Hi, I'm Victor, an independent AWS Infrastructure & Security specialist with 19+ years of hands-on experience (9+ on AWS), architecting, automating, and securing cloud-native and mission-critical workloads. I help organizations modernize their AWS environments through security reviews, modern architecture, DevSecOps coaching, and FinOps tooling. I'm the co-founder of unusd.cloud for AWS cost and waste awareness, and the creator of IAMTrail, the AWS Managed Policy Changes Archive.
Design, review, and optimize your AWS infrastructure for security, scalability, and cost-efficiency.
Identify vulnerabilities, implement best practices, and secure your AWS environment end-to-end.
Automate deployments, security controls, and compliance with Infrastructure as Code and CI/CD pipelines.
Analyze and reduce your AWS spend with actionable recommendations and automation.
Comprehensive security monitoring and alerting solution for AWS accounts. Includes CloudWatch dashboards and automated security controls.
Full version history and diffs for 1,525+ AWS Managed IAM Policies, archived since 2019. Catch every silent policy change AWS makes.
Monitor available IPs in VPC subnets using CloudWatch metrics. Avoid IP shortages with proactive alerts.
Analyze AWS IAM and S3 policies to identify third-party and external access. Detects vendors, unknown accounts, and confused deputy risks in your AWS environment.
The garbage collector for your AWS: identify unused and underutilized resources, reduce costs, and shrink your attack surface.
Scheduled detection across all AWS regions. EC2, RDS, EBS, S3, and 20+ services covered.
Ask questions in plain English, get actionable recommendations based on FinOps best practices.
Get reports via Email, Slack, or Teams with cost breakdown, CLI snippets, and direct AWS Console links.
AWS silently updates Managed IAM policies all the time. IAMTrail catches every single change, with full version history and diffs archived since 2019.
Every version of every AWS Managed IAM policy, with inline diffs showing exactly what changed and when.
Daily or weekly email digests with inline diffs. Track specific policies or subscribe to all changes.
Spot upcoming AWS services before they launch. New v1 policies often signal unreleased features.
I write about AWS security best practices, cloud architecture patterns, DevSecOps workflows, and lessons learned from real-world engagements.
Read on zoph.meAdvanced AWS certifications and deep security expertise.
Extensive experience in enterprise security and cloud architecture.
Successfully secured cloud infrastructure for global clients.
Direct, strategic partnership with continuous support.