Matt Benedict
Cloud & Network Engineer
matt.benedict1701@gmail.com·github.com/sormin-the-red·linkedin.com/in/matthew-benedict·matt-benedict.cloud·Indianapolis, IN·Remote only

Summary

I design and run production systems on AWS, serverless first, and I am just as at home in the network beneath them: VPC architecture, site to site VPN, routing, and firewall policy. A growing share of my recent work is containerized, packaging services with Docker and orchestrating them on Kubernetes for freelance clients. Backing that is a B.S. in Cloud & Network Engineering and ten certifications, among them the AWS Solutions Architect and CloudOps Associate credentials with CompTIA Network+ and Security+. What I enjoy is owning a system end to end and keeping it secure and cheap to run, with enough logging that I can tell what it is doing when something breaks.

Certifications

AWS Certified Solutions Architect – Associate·AWS Certified CloudOps Engineer – Associate·AWS Certified Cloud Practitioner·HashiCorp Terraform Associate·CompTIA A+·Network+·Security+·Cloud+·LPI Linux Essentials·ITIL Foundation

Technical Skills

AWS
Lambda·API Gateway·EC2·S3·DynamoDB·CloudFront·Cognito·IAM·VPC·Site-to-Site VPN·CloudWatch·WAF·ECS/Fargate·AppSync·Bedrock·Rekognition·IoT Core·SES·EventBridge·Secrets Manager
Networking
Hybrid cloud architecture·route-based IPsec Site-to-Site VPN (IKEv2, NAT-Traversal)·VLANs / 802.1Q trunking·zone-based firewalls·NAT / DNAT·DHCP·routing·subnetting
Containers
Docker·Kubernetes·container orchestration·containerized microservices
IaC & CI/CD
AWS CDK (C#, TypeScript)·Terraform·GitHub Actions·OIDC federation·AWS Amplify
Languages
C#/.NET·TypeScript·Python·C++·PowerShell·SQL
Tools
Linux·Windows Server / Active Directory·VMware / Hyper-V·GNS3·VyOS·Open vSwitch·Wireshark·Git / GitHub·SolidWorks PDM (administration and add-ins)

Experience

Creative Works Indianapolis, IN July 2017 – Present
Cloud & Network Engineer

Projects

Hybrid-Cloud Network Capstonegithub.com/sormin-the-red/BSCNE-AWS-Capstone-Project---E030
On-prem site (GNS3): VyOS router/firewall, three-VLAN segmentation over 802.1Q trunking, screened DMZ, DHCP, and NAT/DNAT—bridged to an AWS VPC over a route-based IPsec Site-to-Site VPN (IKEv2 + NAT-Traversal). Cloud side: tiered public/app/data subnets with Security Groups + NACLs, VGW routing deliberately scoped to one on-prem subnet for least-privilege access—all in Terraform. Validated across eight test cases.
GlazeVault Serverless Backendgithub.com/sormin-the-red/vitrify-backend
Domain-decomposed serverless API: nine bounded-context Lambdas behind one HTTP API, single-table DynamoDB with access-pattern GSIs, Cognito social OAuth and triggers, Bedrock generative-AI integration, Rekognition moderation, CDK infrastructure-as-code.
The Duke Online Real-time multiplayertheduke-online.com·github.com/sormin-the-red/TheDukeOnline
AWS AppSync (GraphQL + WebSocket subscriptions), Cognito, per-time-control Elo ratings, and a WAF + DynamoDB throughput-cap + Budgets guardrail layer. CDK end to end.
mkuntz-site Serverless sitegithub.com/sormin-the-red/mkuntz-site
Keyless GitHub Actions + OIDC continuous deployment of CDK infrastructure; CloudFront edge-cached static reads keep visitor loads off Lambda entirely.

Education

B.S. Cloud & Network Engineering (AWS track) — Western Governors University · coursework complete; conferring 2026