Skip to content
~/chingyung

cat ./resume --format full

Ching Yung

AWS Cloud & Security Engineer · London, United Kingdom

Download PDF

Ching YUNG is an AWS Cloud & Security Engineer executing high-availability infrastructure automation and zero-trust engineering at scale. With 5+ years of managing high-stress production environments, Ching treats infrastructure as deterministic code and security as an immutable pipeline constraint.Specializing in defensive platform engineering, Ching designs multi-account AWS enterprise topologies using declarative IaC i.e. Terraform or CloudFormation. Every system is architected to fail silently and self-heal automatically. By programmatically injecting strict compliance guardrails and vulnerability scanning directly into GitOps CI/CD workflows, human error is systematically eliminated from the deployment equation.To ensure production telemetry matches runtime reality, Ching constructs high-fidelity observability ecosystems via Datadog, Prometheus, and CloudWatch—shifting operations from reactive incident response to predictive mitigation. This engineering execution is validated by dual AWS Professional credentials and the Certified Kubernetes Administrator (CKA) title.

cat ./key-metrics

Key Impact

99.99% Availability

Production incident ownership with SLI/SLO monitoring and automated failover.

8× Faster Deployments

120 → 15 min via reusable Terraform modules and CI/CD pipelines with compliance gates.

Zero Critical Findings

GuardDuty + Security Hub + CloudTrail + IaC scanning enforced across 200+ resources.

200+ IaC Resources

Reusable Terraform modules across compute, storage, database, and networking.

history --career

Experience

  1. May 2026present

    AWS Security Engineer · Evri

    The UK's largest dedicated parcel delivery network — securing a massive multi-account AWS estate and automated logistics platforms

    • Assumed ownership of the AWS cloud security posture management (CSPM), proactively monitoring alerts across GuardDuty, Security Hub, and CloudTrail to maintain the platform's security baseline.
    • Contributed to the governance of multi-account Landing Zone environments by reviewing identity perms (IAM, least privilege) and refining Service Control Policies (SCPs) to enforce guardrails.
    • Integrated with the cross-functional platform infrastructure team to ensure secure-by-default practices are embedded into deployment pipelines and infrastructure-as-code (Terraform) modules.
  2. 20252026

    Career Development & Upskilling · Self-directed

    • Earned CKA certification — deepened Linux systems and Kubernetes operations knowledge across namespaces, network policies, and node-level troubleshooting.
    • Open-sourced a serverless AWS platform on GitHub — API Gateway + Lambda backbone with CloudFormation IaC, automated deployment pipelines, and security defaults baked into reusable templates.
    • Bridged theoretical expertise from AWS Professional certifications with hands-on labs to build data pipelines using MSK, EMR (Spark), and Apache Iceberg, aligning with Common Data Fabric (CDF) architectural patterns.
  3. 20222024

    Senior Cloud Engineer · Toluna Corporate

    Mission-critical SaaS platform — millions of users globally, real-time analytics workloads

    • Deployed reusable Terraform modules for all core AWS components — VPC, EKS, IAM, KMS, RDS, S3, DynamoDB — across 200+ resources, cutting deployment lead time from 120 → 15 min.
    • Implemented CI/CD pipelines (GitLab CI, Jenkins) with automated rollbacks, compliance checks, and deployment safety gates across multiple environments.
    • Supported security practices — IAM permission boundaries, AWS Inspector automation, infrastructure code scanning (tfsec/Checkov) — ensuring compliance and eliminating critical vulnerabilities.
    • Built production observability using CloudWatch metrics/logs/alarms, Datadog APM with distributed tracing, and SLI/SLO dashboards that caught regressions before customer impact.
    • Maintained operational runbooks and incident triage workflows — led blameless post-mortems and cross-team resolution, holding 99.99% uptime.
  4. 20212022

    Software Engineer · Further

    Research SaaS platform — greenfield AWS migration, serverless-first architecture

    • Led the greenfield AWS platform design, delivering a resilient multi-layer architecture handling 700K+ daily requests with sub-second latency.
    • Architected serverless workloads using Lambda, API Gateway, and event-driven patterns with CloudFront caching, reducing database load by 65%.
    • Established deployment governance with canary rollouts, automated rollback, and compliance gates coordinated across platform and product teams.
    • Centralised secrets management via AWS Secrets Manager with automated rotation, eliminating hardcoded credentials across 15+ services.
    • Built internal automation tooling in Python and Go for infrastructure provisioning, monitoring integration, and operational runbooks.
  5. 20192021

    Software Engineer · ESD Services Limited

    High-volume e-commerce platform — 700K+ daily transactions, global distribution

    • Managed production AWS infrastructure (EC2, RDS, ElastiCache, S3, CloudFront) with auto-scaling and disaster recovery for peak traffic events.
    • Introduced Docker containerisation with CI/CD automation, improving deployment reliability and environment consistency across global regions.
    • Wrote automation scripts in Python and Bash for infrastructure provisioning, CloudWatch monitoring integration, and operational runbooks.

cat ./skills-matrix

Skills

AWS Services
EC2 / VPCLambdaAPI GatewayEKS / ECSS3DynamoDBRDS / AuroraCloudFrontIAM / SCP
Infrastructure as Code
TerraformCloudFormationReusable ModulesKubernetes / HelmDocker
CI/CD & Deployment
GitLab CIJenkinsGitHub ActionsAutomated RollbacksCompliance Gates
AWS Security & Governance
GuardDutySecurity HubCloudTrailAWS ConfigKMSSecrets Managertfsec / CheckovPolicy-as-Code
Observability
CloudWatchDatadog APMPrometheus / GrafanaDistributed TracingSLI / SLO
Networking
VPC / SubnetsNAT / RoutingEndpoint PoliciesSecurity Groups
Languages & Scripting
PythonBash / LinuxAWS CLIGoNode.js
Operations
Runbooks / PlaybooksIncident ResponseRCA / Post-MortemsDR & FailoverChange Management

ls ./certifications

Certifications

  • Certified Kubernetes AdministratorCKAVerify ↗
    Linux Foundation / CNCF · 2 Feb 2026
  • AWS Certified DevOps Engineer – ProfessionalPROFESSIONALVerify ↗
    Amazon Web Services · 13 Jul 2025
  • AWS Certified Solutions Architect – ProfessionalPROFESSIONALVerify ↗
    Amazon Web Services · 24 Sept 2022
  • AWS Certified Solutions Architect – AssociateASSOCIATEVerify ↗
    Amazon Web Services · 20 Mar 2021
  • AWS Certified Cloud PractitionerFOUNDATIONALVerify ↗
    Amazon Web Services · 16 Jan 2021

ls ./education

Education

  • BEng Computer Science & EngineeringHong Kong University of Science and Technology