Michael Burbank

Professional Summary


AWS Certified Solutions Architect - Associate and sole cloud administrator for Arizona State Parks and Trails, transforming an inherited, undocumented AWS environment through architecture redesign, workload migration, identity governance, automation, security remediation, monitoring, and cost optimization.

Re-architected a confidential-data application, completed a production Windows Server migration, reduced eligible EC2 costs by 12%, and cut endpoint compliance remediation from 1-1.5 weeks to 20-30 minutes. Public-sector technologist and Army veteran recognized for practical AWS guidance and cross-agency collaboration.

Certifications


Technical Skills


Experience


  • Serve as the agency's sole cloud administrator, establishing the first reliable baseline for an inherited, undocumented AWS estate; used CloudFormation IaC generator to scan unmanaged resources and produce a consolidated infrastructure template for review and modernization.
  • Resolved a month-long AWS account ownership and administrative-access issue across ADOA, SHI, and AWS Organizations; restored an authorized management path, enforced MFA for every IAM user, and implemented a 90-day IAM password policy.
  • Re-architected a third-party SHPO design into a production-aligned UAT architecture for confidential data, replacing an all-public topology with segmented public/private subnets, private ECS Fargate/RDS/DMS tiers, ALB-controlled ingress, encrypted storage, and VPC endpoints.
  • Completed the ArcGIS production cutover from Windows Server 2019 to Windows Server 2025 using a reusable HashiCorp Packer golden AMI, documented rollback procedures, stakeholder validation, and post-migration monitoring.
  • Reduced eligible production and test EC2 costs by 12% with EventBridge business-hour schedules, cutting monthly runtime from 730 to 239 hours; consolidated resources into us-west-2, standardized tags, and retired obsolete regional, storage, security-group, and backup configurations.
  • Built an Ansible remediation project that reduced Tanium compliance work from 1-1.5 weeks to 20-30 minutes per endpoint while addressing approximately 600-900 findings on each Windows system.
  • Restored patch governance for three Windows EC2 instances after a 23-month update gap, remediated AZDOHS-identified Java risks, and upgraded seven Lambda functions flagged by Trusted Advisor from Python 2.7 to Python 3.12.
  • Implemented AWS Backup plans, CloudWatch alarms for high CPU and EC2 status checks, SNS email notifications, and scheduled-start verification; created an AWS CLI/S3 Sync backup for critical FileMaker Pro incident data and configured 90/180-day S3 storage transitions.
  • Processed approximately 107 onboarding, offboarding, and promotion requests through Active Directory, ServiceNow, and Google Workspace; own iPhone/iPad configuration and deployment while administering Jamf Pro support across roughly 288 mobile devices.
  • Represent the agency in monthly AWS technical account sessions; invited by an AWS Solutions Architect to Arizona Department of Revenue's AWS Immersion Day, where provided hands-on guidance to public-sector participants and received invitations to return.
  • Designed and deployed a production client website on Hostinger with Cloudflare DNS/CDN, SSL/TLS, caching, and performance optimization.
  • Integrated Google Analytics and Search Console, increasing organic reach by 45%.
  • Implemented Git feature branching and environment-based configuration to support secure, maintainable releases.
  • Performed Agile planning, code reviews, QA testing, and deployment documentation.
  • Owned releases end to end, including rollback planning and post-deployment validation.

Project Highlights


  • Completed the end-to-end challenge in approximately 2-3 weeks, deploying the resume frontend to S3 and CloudFront with Route 53 DNS, ACM-managed HTTPS, and CloudFront Origin Access Control.
  • Built a serverless visitor counter with AWS SAM, API Gateway, Python Lambda, DynamoDB, JavaScript integration, and CORS controls.
  • Applied restrictive S3 bucket policies and published a technical implementation article with architecture and deployment diagrams.
  • Migrated the workload from Lightsail to an EC2 Reserved Instance and standardized NGINX on Amazon Linux 2023.
  • Automated EC2 provisioning, IAM instance profiles, security groups, NGINX, systemd, and idempotent deployments with Ansible.
  • Configured CloudFront, ACM-managed TLS, cache behaviors, post-deployment invalidations, health checks, and deployment logging.
  • Implemented Ansible linting and syntax validation in CI and standardized reproducible tooling with isolated Python environments and pinned requirements.

Education


Site Visitors