Cloud & Security Engineering

Sam Tindal

Staff / Senior Cloud Software & Security Engineer

Email GitHub
206-291-0062 samtindal@pm.me Lawton, OK Available immediately

01 Summary

Software engineer with nine years across cloud platforms, six of them at Amazon, with a recurring thread of security- and compliance-sensitive work: ITAR / HIPAA / GDPR compliant design, access governance, threat modeling, and a FIDO2/WebAuthn authentication architecture evaluation for a classified air-gapped environment. Primary language is Python, with production experience in Java and C#. Consistent pattern of fixing the process behind a recurring problem rather than the instance in front of him, including an internal tooling change that cut agent workflow time by up to 50%. Based in Lawton; does not currently hold a security clearance and is prepared to pursue one.

02 Technical Skills Matrix

Security & Compliance

ITAR / HIPAA / GDPR Threat Modeling Security Design Review IAM Least-Privilege RBAC & Access Governance OAuth 2.0 / OIDC / SAML / JWT FIDO2 / WebAuthn TLS KMS Encryption Secrets Management & Rotation CVE & Supply-Chain Remediation Incident Response

Cloud & Systems

AWS Lambda IAM KMS VPC ECS & Fargate S3 CloudFront SageMaker CloudWatch OpenSearch Google Cloud Linux Administration Docker Container Orchestration

Languages

Python Java C# SQL JavaScript Rust (WASM / WebGL2)

Infra & Delivery

AWS CDK CloudFormation Git & PR Change Control CI/CD Staged Promotion Multi-Stage Approval Gates Rollback Procedures

Data & Testing

Apache Spark / PySpark ETL Pipeline Orchestration Elasticsearch / OpenSearch JUnit TestNG Mockito Cypress

Tools & Platforms

JIRA Confluence Bitbucket ServiceNow Cloudflare Pages

03 Professional Experience

Intermediate Technical Consultant

r4 Technologies, Inc.

August 2025 – September 2026 Lawton, OK
  • Supported the configuration baseline for a multi-tenant cloud analytics platform under the platform's senior technical lead, maintaining per-tenant deployment configuration across customer environments on Google Cloud.
  • Authored a reusable dependency supply-chain security workflow for npm and pip covering package name verification, vulnerability triage, and remediation.
  • Reviewed and dispositioned RBAC access requests against documented role definitions and project scope, enforcing least privilege across customer environments.
  • Scoped a cross-customer GDPR right-to-erasure approach covering data handling and deletion across every customer environment rather than per-customer workarounds.
  • Built tenant-generic QA automation that verifies configured customer environments after every deployment, combining deterministic checks with automated failure triage.
  • Authored a pull-request-based change-submission process proposing reviewable, auditable change control in place of ad hoc infrastructure requests.
  • Authored the proof-of-concept intake process defining how candidate work is scoped and evaluated before commitment to a production engagement.

Systems Development Engineer (Contract)

Aditi Consulting, Inc. (Client: Amazon Kuiper)

April 2024 Bellevue, WA
  • Evaluated architecture options for a self-contained FIDO2/WebAuthn authentication server providing hardware-backed multi-factor authentication for users operating inside a classified air-gapped environment, replacing password-based login.
  • Conducted stakeholder requirements elicitation, defining functional and non-functional specifications covering performance, scalability, and security constraints.

Software Engineer

Specialist Staffing Services, Inc. (Client: Whole Foods Market)

March 2023 – March 2024 Seattle, WA
  • Led a team architecting and delivering a low-latency service on the customer checkout path, from container networking through private connectivity to internal dependency services.
  • Designed authentication and authorization covering OAuth 2.0 flows, token validation, and service-to-service auth, scoped IAM roles to least privilege, and moved service credentials into managed secrets storage with rotation.
  • Drove security design review and threat modeling for the service, and remediated vulnerability and dependency findings ahead of release.
  • Modeled infrastructure as code and designed CI/CD delivery with multi-stage approval gates.
  • Mentored 6 engineers on development practice, design patterns, cloud architecture, and networking and security fundamentals.
  • Produced design and control evidence for compliance and internal audit review.

Software Development Engineer

Amazon, Inc.

May 2020 – March 2023 Seattle, WA
  • Owned staged deployment pipelines for big data pipeline services, defining stage promotion, one-box and bake periods, approval gates, and automated rollback on alarm.
  • Authored and operated change-management records for deployments outside the standard pipeline, specifying staging steps, rollback alarms, and failure contingencies, and shepherded each through multi-approver review.
  • Instrumented services with structured and method-level logging, aggregating output into operational dashboards for visibility and on-call debugging.
  • Implemented designs complying with export control, data retention, governance, and deletion regulations including ITAR, HIPAA, and GDPR, applying data classification, access restriction, and encryption across pipeline and storage layers.
  • Maintained an ETL pipeline ingesting, augmenting, and publishing data using Spark, Java, and Python microservices.
  • Integrated machine learning model output into a search index and maintained a React dashboard over it with automated UI testing.
  • Responded to security findings on call and drove remediation across shared services under mandated timelines.

Cloud Support Engineer

Amazon Web Services, Inc. (AWS)

March 2017 – May 2020 Seattle, WA

Cloud Support Engineer (2018–2020) · Technical Customer Support Specialist (2017–2018)

  • Completed formal AWS infrastructure fundamentals training covering compute, storage, and databases, then supported customers on account and billing across the full service catalog.
  • Advanced from the general support tier onto a specialist team focused on domain registration and DNS.
  • Diagnosed customer architecture and service-level failures at volume in premium support, building depth in service internals.
  • Identified and closed workflow gaps in internal agent tooling, submitting and reviewing commits, including a ticket-creation search function that cut agent workflow time by up to 50%.
  • Maintained a development environment and submitted code reviews throughout both support roles, including contributions to an internal Python Flask application and user scripting libraries.

04 Education

M.S., Engineering Leadership and Management

Jan 2025 – Dec 2027 (in progress)

The University of Oklahoma, Gallogly College of Engineering

B.A., Journalism (Advertising)

December 2012

The University of Oklahoma, Gaylord College of Journalism and Mass Communication