Justin Gorny

Download Resume
About

Summary

Summary

Seasoned infrastructure engineer and technical leader with 8+ years of experience leading large-scale infrastructure initiatives in cloud-native environments. Justin specializes in AWS, Kubernetes, GitOps, infrastructure-as-code, reliability engineering, and cloud governance, with a strong record of improving uptime, reducing spend, and enabling teams with reusable platform patterns.


Based in Pittsburgh, Pennsylvania, Justin currently serves as Senior Infrastructure Engineer at HeroDevs. Public LinkedIn profile data currently shows 900 followers and 500+ connections.


Core Strengths:

  • AWS platform architecture & multi-account governance
  • Kubernetes (EKS) operations, scaling, and security
  • GitOps (Argo CD / Flux CD) and CI/CD automation
  • OpenTofu / Terraform / Terragrunt infrastructure-as-code
  • Reliability engineering, observability, and incident response
  • FinOps and cost optimization (rightsizing, spot, savings plans)
  • Cloud security, policy-as-code, IAM/RBAC, least privilege
  • Technical leadership, mentoring, and stakeholder communication
Experience

Work History

Experience

HeroDevs

- · Remote
Senior Infrastructure Engineer
  • Owned the company Kubernetes ecosystem across multiple EKS clusters using Argo CD, Helm, and GitOps workflows for consistent and reproducible deployments.
  • Provisioned and managed infrastructure with OpenTofu (Terraform), including reusable modules for AWS, GitHub, and Artifactory access governance.
  • Built reusable GitHub Actions and standardized CI/CD patterns for testing, promotion, artifact publishing, and drift detection.
  • Maintained 99.5% uptime for customer-facing applications (including the NES Registry) through SLO-driven monitoring and expanded observability with Prometheus, AlertManager, Blackbox Exporter, and Grafana.
  • Implemented Kyverno policy-as-code guardrails to reduce misconfiguration risk and strengthen baseline cluster security.
  • Improved Kubernetes scheduling efficiency with Karpenter node pools and spot instances across ~35% of workloads.
  • Reduced AWS spend by 65% month-over-month on EC2/EKS and drove an 84% year-over-year reduction through rightsizing, spot adoption, savings plans, and RDS/storage optimizations.
  • Improved reliability and MTTR by designing multi-region disaster recovery for secrets and RDS backups with infrastructure-as-code.
  • Onboarded Terragrunt to enforce DRY IaC patterns and isolate state files, reducing configuration complexity and speeding CI.
  • Operationalized OSS Teleport for secure, short-lived, identity-based access to private EKS/RDS resources with centralized RBAC and audit logs.

UPMC Enterprises

- · Hybrid
Lead Cloud Infrastructure Engineer
  • Managed 80+ AWS accounts and 25+ projects across technical incubation and lifecycle stages.
  • Led a team of 3 cloud engineers designing and deploying cloud solutions to accelerate healthcare IT and AI startups.
  • Implemented an organization-wide data perimeter using SCPs, RCPs, VPCE policies, and supporting documentation.
  • Architected and deployed a de-identification pipeline on Amazon EMR to support commercialization of payer/provider data (Ahavi™).
  • Operationalized AWS SageMaker and MLflow workflows for model development, testing, and lifecycle maintenance.
  • Collaborated with customers on solution requirements, feasibility, cost/value analysis, and risk assessment for moderate-to-complex initiatives.
  • Oversaw patch scheduling and coordinated directly with customers to plan, communicate, and execute updates.
  • Drove infrastructure strategy innovation with cross-functional stakeholders.

UPMC Enterprises

- · Remote
Senior Cloud Infrastructure Engineer
  • Architected and executed migration of on-prem workloads to AWS using a hub-and-spoke design with AWS Transit Gateway and site-to-site VPNs.
  • Served as Terraform SME for enterprise IaC initiatives and knowledge transfer sessions.
  • Re-architected self-hosted GitLab runners into EKS using Argo CD and Karpenter for scaling and job isolation, achieving ~65% YoY cost savings.
  • Achieved HiTrust CSF certification for the MyUPMC application architecture and security posture.
  • Implemented Kubernetes autoscaling with Karpenter and HPAs, resulting in ~20% annual EC2 savings.
  • Adopted Flux CD for Kubernetes manifest management, improving deployment performance by more than 400%.
  • Enhanced Kubernetes security using NSA hardening guidance, including Network Policies, IRSA, and RBAC.
  • Modernized application servers to AWS Bottlerocket for container-focused operations.
  • Built a solution to surface application health details and enable remote dynamic updates via a Slack app.
  • Led sign-on migration from Azure IMS generic roles to AWS SSO scoped roles with least privilege controls.
  • Drove a cost savings initiative using Karpenter, Spot Fleets, and EC2 Savings Plans to reduce spend by 36%, plus CoreDNS adoption over Route53 for an additional $17,000 annual savings.
  • Established a warm disaster recovery solution that reduced RTO by 600% while maintaining an RPO under 15 minutes.

FedEx Services

- · Hybrid
Software Engineer
  • Developed and maintained web-based applications hosted on Android devices for field use using Java, Spring Boot, Maven, and Jenkins CI.
Education

Education

Education

Robert Morris University

-
Master of Science · Organizational Leadership

Pittsburgh, PA

Robert Morris University

Graduate Certificate · Leadership and Organizational Change

Pittsburgh, PA

Pennsylvania State University

Bachelor of Science · Computer Engineering

Erie, PA

Certifications

AWS

AWS Certified Solutions Architect - Professional - Amazon Web Services (AWS) (Issued Sep 2024 · Expires Sep 2027)

AWS Certified Solutions Architect - Associate - Amazon Web Services (AWS) (Issued Jan 2023 · Expires Sep 2027)

AWS Certified SysOps Administrator - Associate - Amazon Web Services (AWS) (Issued Feb 2024 · Expires Feb 2027)

AWS Certified AI Practitioner - Amazon Web Services (AWS) (Issued Aug 2025 · Expires Aug 2028)

AWS Certified Cloud Practitioner - Amazon Web Services (AWS) (Issued Dec 2021 · Expires Sep 2027)

Infrastructure & Kubernetes

HashiCorp Certified: Terraform Associate (002) - HashiCorp (Issued Jan 2023 · Expires Jan 2025)

KCNA: Kubernetes and Cloud Native Associate - The Linux Foundation (Issued Feb 2023 · Expires Feb 2026)

Technical Skills

Cloud & Platform Engineering

AWS, Kubernetes (EKS), Docker, Platform Engineering, Solutions Architecture, Multi-Region Architecture, Disaster Recovery (RPO/RTO), Cloud Networking & VPNs

Infrastructure as Code & Automation

OpenTofu, Terraform, Terragrunt, AWS CDK, Ansible, Bash, Python

GitOps & Deployments

Argo CD, Flux CD, Helm, Kustomize, GitHub Actions, GitLab CI/CD

Observability & Reliability

Prometheus, Grafana, AlertManager, Blackbox Exporter, Monitoring & Alerting, SLA/SLO Design, Incident Response

Security & Governance

IAM, Least Privilege Design, IRSA, Policy-as-Code (Kyverno), Compliance & Governance Controls, Microsoft Entra ID

Data & Persistence

PostgreSQL, MySQL, AWS RDS, Backup & Recovery Strategies

Selected Work

Impact Highlights

Impact
Managing Infrastructure as Code with Terragrunt
Managing Infrastructure as Code with Terragrunt
Medium · Jan 28, 2026
Kubernetes Storage on EKS
Kubernetes Storage on EKS: EBS, EFS, S3 CSI
Medium · Dec 15, 2025
Executive Contact Hub

Let's Connect

Contact

Cloud Platform, Reliability, and Delivery Leadership

If you need help with AWS platform strategy, Kubernetes operations, GitOps delivery, cloud governance, or reliability outcomes, this is the fastest way to reach Justin.

Primary Contact Channels

Availability

  • Timezone: Eastern Time (Pittsburgh, PA)
  • Response Window: Typically within 24 hours
  • Focus Areas: Platform engineering, cloud architecture, reliability, and technical leadership
  • Engagement Types: Full-time opportunities, strategic consulting, technical collaboration, and speaking or podcast invites

Best Reasons To Reach Out

  • AWS multi-account architecture, governance, and policy guardrails
  • EKS platform design, GitOps workflows, and secure Kubernetes operations
  • Infrastructure as code standards with OpenTofu, Terraform, and Terragrunt
  • Reliability, observability, disaster recovery, and FinOps optimization programs
  • Hands-on technical leadership for platform teams and cloud modernization