Curriculum Vitae

Nicholas Rasmussen

Cloud Architect & Infrastructure Leader — the complete record: eighteen years of roles, the systems built along the way, credentials, and the full technical inventory.

Salt Lake County, Utah nickmrasmussen@gmail.com LinkedIn github.com/ViperVnDm
Last updated August 2026
01 — PROFILE

Professional summary.

Cloud Architect with 18+ years of progressive IT and infrastructure experience, currently the sole cloud architect at a financial services firm — owning the full Azure and AWS footprint end to end: architecture, governance, security, cost, and day-to-day operations.

My work spans all three major clouds. I design and operate enterprise-grade multi-cloud environments across AWS, Azure, and GCP, bridging architecture, DevOps, security, and IT operations. That includes greenfield Azure landing zones built from nothing, production Kubernetes clusters on EKS, AKS, and GKE, and Terraform module frameworks that make deployments repeatable and audit-ready.

The path here ran through the whole stack. I started in technical support, where I learned the Windows, Linux, networking, and database fundamentals that still inform my architecture decisions. From there came infrastructure engineering — thousands of VMs across VMware vCenter and Hyper-V/SCVMM, HPE Synergy composable infrastructure, SAN storage administration, and PowerShell automation that cut VM deployment times by 70%. Then DevOps and platform work, and now architecture.

The through-line: I've been the person paged at 3am for every layer of the stack. That shapes how I design — a bias for simple, boring, reversible systems that don't wake anyone up.

02 — AREAS OF EXPERTISE

Competency domains.

Six areas where I've shipped production systems — not just certifications, but running environments with real users, real budgets, and real 3am pages.

Cloud platforms

Multi-cloud architecture across AWS, Azure, and GCP — landing zones, account and subscription hierarchies, network topology, and managed Kubernetes running production workloads on all three providers.

AWSAzureGCP Landing ZonesEKSAKS GKEEC2 / VPC

Infrastructure as Code

Terraform-first and module-driven, with Pulumi and Kustomize where they fit better. Everything reproducible; nothing clicked into a console. GitOps-style promotion across environments.

TerraformPulumi KustomizeGitOps AnsiblePowerShellBash

CI/CD & DevOps

Pipelines for building, testing, and deploying both infrastructure and applications. GitHub Enterprise administration at the org level — policies, SAML enforcement, branch protections, access governance. Docker and Helm for portable runtime.

GitHub ActionsAzure DevOps GitLab CIGitHub Enterprise DockerHelm

Identity & security

Entra ID, Okta, and Azure Policy for governance. Least-privilege RBAC, secret management via Key Vault, and conditional access rolled out to workforces that had to keep working through the change.

Entra IDOkta RBACAzure Policy Key VaultConditional AccessSAML / SSO

Data-center infrastructure

Thousands of VMs across VMware vCenter and Hyper-V/SCVMM. HPE Synergy composable infrastructure, Nimble all-flash SAN, Commvault backup across multiple sites — the layer under the cloud that still runs the business.

VMware vCenterHyper-V / SCVMM HPE SynergyNimble SAN CommvaultWindows ServerLinux

Networking & data

BGP peering, site-to-site VPN, DNS/DHCP, VLAN segmentation. MSSQL and PostgreSQL administration — including the migrations, the availability groups, and the awkward point-in-time restores.

BGP / VPNDNS / DHCP VLANsMSSQL PostgreSQL
03 — PROFESSIONAL EXPERIENCE

Employment history.

Every role since 2007, at full detail — including the earlier support and infrastructure years that the one-page resume has to compress.

Prestige Financial Services Oct 2025 – Present
Cloud Architect
  • Sole cloud architect owning the full Azure + AWS environment for a financial services firm — architecture, governance, security, cost, and day-to-day operations.
  • Designed a greenfield Azure landing zone from scratch: hub-spoke networking, RBAC, Azure Policy, Key Vault, centralized logging, and security baselines.
  • Built all infrastructure with Terraform — modular IaC frameworks supporting scalable, repeatable, audit-ready deployments across environments.
  • Led cloud migration initiative end-to-end: strategy, architectural reviews, workload transitions, and blocker resolution in collaboration with engineering and security.
  • Established CI/CD pipelines for IaC via Azure DevOps + GitHub Actions; provided mentorship on cloud-native design to cross-functional teams.
  • Stepped into expanded IT leadership as the company wound down — directed the outsourced MSP for all day-to-day IT operations and managed Entra ID / Okta governance.
Prestige Financial Services Sep 2022 – Oct 2025
Cloud Engineer
  • Managed a hybrid AWS + Azure environment supporting containerized, mission-critical financial workloads.
  • Administered Amazon EKS clusters — autoscaling, upgrades, Helm chart management, and cross-environment reliability improvements.
  • Automated infrastructure provisioning with Pulumi (IaC); earned AWS Certified Solutions Architect – Associate within 2 months of joining.
  • Led GitHub Enterprise migration with Okta SSO integration; administered the platform ongoing — managing org policies, SAML enforcement, branch protections, and access governance.
Medici Land Governance Apr 2020 – Sep 2022
DevOps Engineer
  • Sole DevOps engineer for a global SaaS platform — owned all GCP infrastructure, GKE production clusters, and Kustomize-based GitOps pipelines.
  • Managed full corporate separation in 2021: migrated Google Cloud, O365, Okta, Cloudflare, Slack, and Confluence to a new independent entity.
Accela Nov 2019 – Apr 2020
Expert Services Engineer
  • Delivered professional services for a government SaaS platform: custom SQL/Crystal reports, PowerShell automation, GIS integrations, and Azure resource deployments.
Ivanti Oct 2015 – Nov 2019
Senior DevOps Infrastructure Engineer
  • Senior infrastructure engineer for a global engineering org — managed thousands of VMs across VMware vCenter and Hyper-V/SCVMM.
  • Reduced VM deployment times 70% via automated PowerShell provisioning templates and hardware upgrades.
  • Consolidated the engineering footprint from 40+ racks of desktops to under 6 racks through datacenter consolidation and virtualization.
  • Deployed HPE Synergy composable infrastructure and Nimble all-flash SAN; administered Commvault backup across multiple sites.
LANDesk Software 2013 – 2015
Product Support Engineer
  • Tier-3 escalation point for Endpoint Manager (EPM) and Avalanche MDM — the last stop for the issues that got past the earlier tiers.
  • Partnered directly with Engineering on defect prioritization, bringing field evidence into the triage process.
  • Delivered customer-facing product training at trade shows and industry events.
EMC Corporation 2012 – 2013
Technical Support Engineer II
  • Supported EMC NetWorker enterprise backup for large-scale customer environments.
  • Ranked in the top 10% for case resolution across the support organization.
  • Earned the EMC Information Storage & Management (ISM) certification while in role.
Wavelink Corporation 2007 – 2012
Technical Support Engineer III
  • Promoted from Tier 2 to Tier 3 within three years; took on key account management for the company's largest customers.
  • Participated in QA for software releases, validating builds before they reached customers.
  • Ran weekly Tier 2 training sessions, raising first-line resolution rates.
  • Built the foundation in Windows, Linux, networking, and PostgreSQL that everything since has been built on.
04 — TECHNICAL PROJECTS

Things I've built.

Personal and professional projects outside the day job — infrastructure, applications, and systems work, each one running or shipped rather than sketched.

Cloud & Infrastructure as Code

Multi-Site AWS Static Hostingtheutcloudarchitect_aws

The infrastructure serving this site. Four reusable Terraform modules provision two S3 origins (portfolio and resume) behind separate CloudFront distributions with Origin Access Control, a single wildcard ACM certificate with DNS validation, a CloudFront Function for clean-URL rewriting, and Route 53 A/AAAA alias records for apex, www, and subdomain. Deployment runs through GitHub Actions with OIDC federation — no long-lived AWS keys — and path-filtered jobs so only the changed site syncs and invalidates.

TerraformS3CloudFront ACMRoute 53OAC GitHub ActionsOIDC
View source

AWS App Runner Container Serviceai-first-aws-apprunner

A production-flavored example of a containerized FastAPI service on AWS App Runner with least-privilege S3 access. Terraform provisions the ECR repository, a private SSE-S3 encrypted bucket with 30-day lifecycle expiration, and an IAM instance role assumed via tasks.apprunner.amazonaws.com — scoped to exactly one bucket. Includes health checks and environment configuration.

AWS App RunnerECRS3 IAMTerraformFastAPIDocker

AWS Control Tower Bootstrapterraform-setup-AWS-controltower

Terraform skeleton and helper tooling for standing up an AWS Organization with an OU and account layout suitable for bootstrapping Control Tower — the multi-account landing-zone problem, solved from code rather than the console.

TerraformAWS Organizations Control TowerMulti-Account

Cleanabit — Commercial Site & Invoice PWAcleanabit-web

A live commercial cleaning business site (cleanabit.com) plus an installable invoice and proposal PWA on its own subdomain (app.cleanabit.com). The app is a single-page tool with a service worker for offline support, a PWA manifest for Android install, localStorage persistence, the Web Share API for sending documents, and a dedicated print stylesheet. Both properties are static assets on S3 behind CloudFront, provisioned by Terraform.

TerraformS3CloudFront PWAService WorkerJavaScript

Multi-Cloud IaC Lab

An ongoing set of working reference implementations across providers and tools: AKS on Azure and Elastic Beanstalk on AWS in Terraform, WordPress on Azure, EKS and general AWS provisioning in Pulumi across TypeScript, Python, and C#, and Ansible playbooks for home-lab configuration management. Deliberately spread across stacks — the point is comparing how each tool models the same problems.

TerraformPulumiAnsible AKSEKSAzureAWS
Applications & Platforms

Dovecot Web Admin ConsoleDovecot_WebInterface

A browser-based administration interface for Dovecot/Postfix mail servers, built with FastAPI, HTMX, and Tailwind. Handles mail user administration, queue inspection and control (flush, delete, hold, release), multi-service log analysis, IP blocking via UFW with a CIDR allowlist, disk and per-mailbox capacity tracking, and threshold-based alerting with email/webhook delivery and cooldown enforcement. Security-hardened by design: an unprivileged web process communicates with a root-level helper daemon over a Unix socket, with strict input validation and command allowlisting rather than shell interpolation.

PythonFastAPIHTMX TailwindDovecotPostfix UFWLinux
View source

Home Monitoring Dashboardhome-monitoring-dashboard

A self-hosted network monitoring dashboard — FastAPI backend, React frontend, packaged as a single Docker container. Monitors HTTP, HTTPS, and TCP services with live updates, seven-day uptime history, incident tracking, and webhook alerting. A multi-architecture image (linux/amd64 and linux/arm64) is published to the GitHub Container Registry on every push, so it runs unchanged on x86 servers, Raspberry Pi, and Apple Silicon with no build toolchain on the host.

PythonFastAPIReact DockerGHCRMulti-ArchSQLite
View source

HomeBase — Asset & Maintenance Platformai-home-maintanence-and-assett-tracking

A privacy-first, self-hosted platform for managing properties, assets, vehicles, and maintenance schedules. Next.js 15 and React on the front, tRPC for end-to-end type safety, PostgreSQL with PostGIS for spatial data, Redis and BullMQ for the job queue, and MinIO for object storage. Features include an AES-256 encrypted document vault, SVG floor plans and Leaflet yard maps, NWS/OpenWeatherMap freeze alerts, irrigation controller integrations, multi-user households with role-based access, and SMS/Slack/Discord notifications with quiet hours. Runs on Docker Compose behind Traefik with automatic SSL.

Next.jstRPCTypeScript PostgreSQL / PostGISRedis / BullMQ MinIOAuth.jsTraefikDocker Compose

PhotoSync — Family Photo Consolidation Pipelinehome-photo-data-pipeline

A Windows desktop application that consolidates per-user Immich sync shares into a single canonical family archive, deduplicating by content rather than by timestamp. Because Immich rewrites mtimes, sync state is a SQLite content-hash manifest — size prefilter, then SHA-256 — plus a per-user ledger, never a "last copied" watermark. Files are classified as new, duplicate, or conflict (surfaced for human review); placement is driven by EXIF DateTimeOriginal with folder and mtime fallbacks, and Live Photo pairs move as an atomic unit. Every copy runs as temp write → hash verify → atomic rename → journal, so a failed run halts cleanly and resumes, and any run can be undone with per-file hash verification. Source shares are opened read-only. Split into a UI-free core library and a WPF MVVM app, with an xUnit suite including an end-to-end scenario test.

C#.NETWPF / MVVM SQLiteSHA-256EXIFxUnit
AI & Emerging Tech

AI Protocol Playgroundai-protocol-playground

Working implementations of six AI agent protocols — Model Context Protocol (MCP) for tool and data connectivity, Agent-to-Agent (A2A) for discovery and inter-agent communication, AG-UI for SSE streaming of agent events to frontends, and three more — each as a self-contained runnable module. Built as a hands-on study of how the emerging agent interoperability stack actually fits together.

MCPA2AAG-UI PythonSSEAI Agents

Local LLM & AI Tooling Evaluation

Ongoing hands-on evaluation of self-hosted and local-first AI tooling: running Qwen models locally, wiring local inference into VS Code and OpenCode, and deploying and troubleshooting a self-hosted LibreChat stack. The theme is the same as the rest of the home lab — understand the operational reality of a technology by running it yourself.

OllamaQwenLibreChat Local InferenceSelf-Hosting
05 — CERTIFICATIONS

Credentials.

06 — EDUCATION

Education.

07 — TECHNICAL SKILLS

Full inventory.

The complete technology index, by category — everything above, flattened for scanning and keyword search.

Cloud platforms
AWS · Azure · Google Cloud Platform · Landing Zones · AWS Organizations / Control Tower · EC2 · VPC · S3 · CloudFront · Route 53 · ACM · IAM · App Runner · ECR · Lambda
Containers & orchestration
Kubernetes · Amazon EKS · Azure AKS · Google GKE · Docker · Helm · Kustomize · Docker Compose · Traefik
Infrastructure as Code
Terraform · Pulumi (TypeScript, Python, C#) · Ansible · Kustomize · GitOps · CloudFront Functions
CI/CD & source control
GitHub Actions · Azure DevOps · GitLab CI · GitHub Enterprise administration · OIDC federation · Branch protections · Git
Identity & security
Microsoft Entra ID · Okta · SAML / SSO · RBAC · Azure Policy · Azure Key Vault · Conditional Access · Least-privilege IAM · UFW
Virtualization & hardware
VMware vCenter · Hyper-V · SCVMM · HPE Synergy composable infrastructure · Nimble all-flash SAN · Commvault backup
Operating systems
Windows Server · Linux (Debian/Ubuntu, RHEL) · Windows 11
Networking
BGP · Site-to-site VPN · DNS · DHCP · VLAN segmentation · Hub-spoke topology · Cloudflare
Data
Microsoft SQL Server · PostgreSQL · PostGIS · SQLite · Redis · MinIO · Crystal Reports
Languages & frameworks
PowerShell · Bash · Python · FastAPI · C# / .NET · WPF · TypeScript · JavaScript · React · Next.js · tRPC · HTMX · HTML / CSS · Tailwind
Collaboration & SaaS
Microsoft 365 · Google Workspace · Slack · Confluence · Jira
Developer tooling
Claude Code · GitHub Copilot · VS Code · Ollama · LibreChat · xUnit