David Digheji

Systems & Cloud Engineer | AWS | Linux | Networking | Security

London, United Kingdom

Visitor Count: Loading...

About

Systems and cloud engineer with a background in business-critical infrastructure, enterprise networking, Linux and Windows administration, and incident troubleshooting. My recent hands-on work focuses on AWS, Terraform, secure identity, cloud networking, monitoring and CI/CD. I enjoy tracing problems across system, network and cloud layers, documenting the root cause, and turning repeatable operational work into reliable automation.

Core Skills

AWS & Cloud Security

IAM, IAM Identity Center, STS, MFA, Access Analyzer, VPC, EC2, S3, CloudFront, Route 53, ECS Fargate, ECR, CloudWatch and CloudTrail.

Systems & Networking

Linux, Windows Server, Active Directory, TCP/IP, DNS, DHCP, HTTP/HTTPS, routing, switching, VPN, Cisco and Fortinet.

Automation & DevOps

Terraform, Bash, GitHub Actions, AWS OIDC, Git, Docker, Docker Compose, PowerShell and Python fundamentals.

Projects

Aegis Cloud Security Platform

In Progress

Building a security-focused AWS platform to demonstrate secure identity, credential hygiene, external-access analysis, cloud hardening, threat detection and operational verification.

  • Implemented IAM Identity Center with MFA, group-based access, permission sets and temporary STS role sessions instead of long-lived administrator credentials
  • Audited and remediated legacy IAM users, access keys, console access and privileged group membership, then verified the final credential posture
  • Hardened S3 public-access controls and secured CloudFront access to S3 using Origin Access Control
  • Reviewed and tightened GitHub OIDC trust, verifying CI/CD access continued to work without static AWS credentials
  • Investigated IAM Access Analyzer findings and completed the current security baseline with zero active findings
  • Maintained stage-by-stage evidence, verification commands and security documentation in the repository

Completed: secure identity foundation and AWS security baseline. Next: threat detection and monitoring.

FuelOps ECS Platform

Built a production-style AWS ECS Fargate platform with Terraform to demonstrate container deployment, secure networking, load balancing, IAM and operational logging.

  • Provisioned VPC networking with public/private subnets, internet gateway, NAT, route tables and security groups
  • Deployed an ECS Fargate service behind an internet-facing Application Load Balancer using IP target groups
  • Configured CloudWatch Logs for application visibility and operational troubleshooting
  • Implemented Terraform remote state with Amazon S3 and state locking
  • Integrated GitHub Actions with AWS OIDC for deployment without long-lived AWS access keys

MeshGate DevOps Platform

Built a containerised full-stack application to demonstrate Docker-based service delivery, CI/CD automation and practical troubleshooting across application and container layers.

  • Built and ran frontend and backend services using Docker and Docker Compose
  • Implemented a GitHub Actions CI pipeline to build Docker images automatically
  • Integrated Docker Hub to publish backend and frontend images from the pipeline
  • Used GitHub Secrets for Docker Hub authentication
  • Diagnosed service-discovery, port-mapping and container-networking issues during deployment

AWS Cloud Resume Challenge

Built and deployed a serverless portfolio application using AWS services with HTTPS delivery, API integration and automated deployment.

  • Hosted the site using Amazon S3 and CloudFront with HTTPS
  • Configured custom domain and DNS using Route 53 and Cloudflare
  • Implemented a serverless visitor counter using Lambda, API Gateway and DynamoDB
  • Automated deployment using GitHub Actions
  • Troubleshot IAM, CORS, Lambda and API integration issues during implementation

Certifications

CompTIA Security+ HashiCorp Terraform Associate AWS Certified Cloud Practitioner Cisco CCNA AWS Solutions Architect - Associate (In Progress)