Distinguished Engineer | Platform, Reliability & Security Systems
San Antonio, TX • joe@kordish.rs • github.com/jkordish • linkedin.com/in/jkordish
Distinguished engineer with 20+ years in infrastructure and security, including 13+ years across Mandiant, FireEye, and Trellix. Built secure, reliable cloud platforms for security products with deep experience in AWS, Kubernetes (EKS), infrastructure as code, GitOps, observability, resilience engineering, and cloud governance. Strongest where reliability, security, scale, and operational clarity all matter at once.
- Cloud & Platform: AWS, Kubernetes (EKS), Lambda, EC2, S3, RDS Serverless, multi-region architecture, IPv6
- Infrastructure & Delivery: Terraform, Helm, Ansible, Packer, GitHub Actions, GitOps, CI/CD automation
- Reliability & Observability: SLO/SLI, incident response, postmortems, capacity planning, Prometheus, Grafana, CloudWatch, Fluent Bit, New Relic
- Languages & Security: Rust, Python, Go, Shell, FedRAMP, PCI DSS, SOC 2, vulnerability assessments, cloud governance
Continuous progression across Mandiant, FireEye, and Trellix through acquisition and operating-model changes.
Jan 2026 - Present
- Defined reference architectures and operating standards for a multi-region AWS EKS platform supporting multiple product teams.
- Established SLO/SLI design, alert-quality review, incident-review loops, and automated verification across delivery pipelines.
- Partnered with security and compliance stakeholders to strengthen cloud governance and FedRAMP-aligned infrastructure controls.
- Served as a technical escalation point and mentor for senior engineers, raising the bar for architecture review and operational discipline.
Jan 2022 - Dec 2025
- Led multi-region AWS EKS platform design using Karpenter and spot-aware capacity strategies to improve scale, resilience, and cost efficiency.
- Built a multi-cluster regional strategy, including IPv6 support, to improve deployment flexibility and service resilience.
- Modernized delivery with infrastructure as code and GitOps using Terraform, Helm, and GitHub Actions for repeatable, lower-risk releases.
- Expanded autoscaling and serverless patterns with HPA/VPA, Lambda, and RDS Serverless to reduce toil and overprovisioning.
- Improved operational visibility with Prometheus, Grafana, CloudWatch, Fluent Bit, and New Relic.
- Built Rust-based CLI and Lambda tooling to automate common SRE workflows.
Jan 2021 - Dec 2021
- Owned reliability for AWS production systems spanning container platforms, CI/CD automation, and data pipelines.
- Reduced incident load through capacity tuning, safer retry behavior, and operational simplification across multi-tier services.
Jan 2018 - Jan 2021
- Migrated legacy services to Kubernetes (EKS) and improved release safety with immutable deployments and health-based rollout gates.
- Managed multiple EKS clusters supporting mission-critical services with a strong security and compliance posture.
- Expanded serverless patterns to reduce operational toil and shrink blast radius for batch and ETL workflows.
Jan 2014 - Jan 2018
- Rebuilt CI/CD with Ansible, Terraform, Packer, and Consul to make releases consistent and repeatable.
- Built big-data analytics platforms using EMR, AWS Data Pipeline, and Lambda for large-scale ETL workloads.
- Authored runbooks, SOPs, and operational documentation to standardize deployment and response.
Jul 2013 - Dec 2013
- Built CI/CD with TeamCity and replaced brittle Bash deployments with Ansible-based workflows.
Apr 2012 - Jul 2013
- Led PCI assessments and built repeatable compliance processes across varied client environments.
Sep 2010 - Mar 2012
- Managed 1,000+ VMware virtual machines for USAMITC, automated routine operations with PowerCLI, and improved platform uptime and throughput.
Sep 2007 - Sep 2010
- Designed VMware solutions for the U.S. Air Force, supported early large-scale virtualization, and conducted enterprise vulnerability assessments.
Nov 2006 - Sep 2007
- Performed real-time monitoring and incident response for the Air Force GIG and partnered with AFCERT on critical incidents.
Oct 2000 - Oct 2006
- Led a team of eight delivering boundary protection, vulnerability assessment, and intrusion detection for the largest Air Force communications squadron.
- M.S., Information Assurance & Security (Network Defense), Capella University, 2016, Summa Cum Laude
- B.S., Psychology, Capella University, 2015, Summa Cum Laude
CISSP • RHCSA • Security+
Rust Language Release Team volunteer (2018 - 2020): testing, documentation, and community support.