James Flattery

Senior Platform Engineer

US Navy veteran building large-scale infrastructure as code on AWS. Terraform platform architecture, CI/CD automation, and cloud reliability across multi-environment AWS estates.

LinkedInlinkedin.com/in/jamesflattery email me

Summary

US Navy veteran and platform engineer with a decade spanning defense systems administration, cybersecurity, and cloud infrastructure. Architect of a three-layer modular Terraform platform (Core, Stack, Deploy) spanning 70+ repositories across AWS environments. Security-minded by background and instinct, with a bias toward simple, reusable, single-source solutions: reducing duplication and attack surface so infrastructure is easier to secure, reason about, and maintain.

Experience

Senior Automation & Process Improvement Manager — Maryland Benefits (DoIT)
Jun 2025 – Jun 2026
Remote · Platform Engineering Lead, Enterprise Terraform (ETER)
  • Led the Automation & QA team owning the Enterprise Terraform platform, a three-layer modular IaC ecosystem (Core, Stack, Deploy) spanning 70+ repositories across AWS environments.
  • Transformed a single-purpose chatbot stack into a generic, reusable IaC framework on Amazon Bedrock, OpenSearch Serverless RAG, and AWS Lex, enabling rapid provisioning of AI-powered chatbots across multiple use cases.
  • Re-architected the Jenkins shared pipeline library, consolidating duplicated per-module pipelines into a single base pipeline with centralized tooling, static analysis, automated versioning, and fleet-wide validation — including diagnosing and resolving a critical pipeline-blocking failure that had broken every job using the shared library.
  • Refactored core Terraform modules and stack configurations to be region-agnostic, enabling multi-region deployment capability, and diagnosed and resolved 67 destructive resource-replacement issues via targeted state migration with zero downtime.
  • Designed a grandfather-clause passthrough pattern preventing destructive recreation during major module upgrades, and decomposed a monolithic VPC into eight single-responsibility modules.
  • Built fleet management and audit tooling against the Bitbucket REST API to detect and remediate configuration drift across the module fleet; integrated security scanning (Trivy, TFSec, Gitleaks, TFLint).
  • Coordinated weekly technical syncs with HashiCorp/IBM partner engineers on Terraform Enterprise administration and module hardening, and migrated developer tooling dependencies from public GitHub to an internal Nexus artifact repository, hardening the software supply chain across the developer fleet.
Senior Systems Analyst — GovSec LLC (contractor at Maryland Benefits)
Nov 2022 – May 2025
Remote · Continuous engagement on the same program, later converted to direct state employment
  • Drove early infrastructure-as-code adoption, developing a custom Docker image with Terraform and Jenkins to replace outdated static images and remediate associated security risks.
  • Led a Salesforce-based software procurement application that improved license inventory management and eliminated outages caused by expiring licenses.
  • Directed consolidation of fragmented infrastructure documentation into a centralized platform with approval workflows, and operationalized a formal change and release management framework.
  • Contributed to the launch of the Maryland Benefits One Application, streamlining access to benefits services for hundreds of thousands of residents.
Cyber Security Engineer — Leidos
Aug 2017 – Mar 2018
Reston, VA
  • Conducted security architecture reviews, compliance assessments, and gap analyses aligned with NIST SP 800-53, FedRAMP, and healthcare regulatory requirements.
  • Led cross-functional teams designing and implementing security architectures, driving identified gaps to remediation.
Systems Administrator — Leidos
Aug 2016 – Aug 2017
Herndon, VA · GeoAxis enterprise SSO / identity platform
  • Administered Oracle identity and access management infrastructure in AWS GovCloud supporting 24/7 operations for a federal enterprise SSO platform.
  • Monitored system health with Zabbix, SoapUI, and Linux tooling, and managed the full incident lifecycle through BMC Remedy ITSM.

Technical Skills

Infrastructure as Code: Terraform (modular Core/Stack/Deploy architecture), HCL, Terraform Enterprise, grandfather-clause migration patterns
AWS: VPC, IAM, RDS, Aurora, DocumentDB, S3, KMS, DynamoDB, Lambda, API Gateway, Bedrock, OpenSearch, Lex, ECS
CI/CD & Automation: Jenkins administration, Shared Library, Jenkinsfile, Groovy, Ansible, Nexus, Docker, pre-commit frameworks
Quality & Security: Trivy, TFSec, TFLint, Gitleaks, four-phase peer review methodology, least-privilege access governance
Languages & Tooling: Python, Bash, Groovy, HCL, Git/Bitbucket, WSL 2, Jira, Google Workspace
AI-Assisted Development: Claude, Gemini, Amazon Bedrock RAG workflows

Education

Bachelor of Science, Computer Science — George Mason University, Fairfax, VA · Graduated with Honors (2021)

Certifications

CompTIA CySA+ (Cybersecurity Analyst)