Senior IT Engineer, OneLearn Global
to present
Cyprus, remote. Enterprise e-learning for the maritime industry: an AWS-hosted platform plus integrations with external HR systems and simulator vendors.
- Migrated live AWS production infrastructure (VPC, subnets, EC2, RDS MySQL, Lightsail) to Terraform with remote S3 state using import blocks. Zero downtime, 60% faster deployments, and version-controlled IaC in place of undocumented manual provisioning.
- Codified the production Moodle/IOMAD stack in Terraform: VPC across two availability zones, EC2 with IMDSv2 enforced, RDS MySQL in private subnets with deletion protection, and security groups. Added a bootstrap root (GitHub OIDC, CI role, SSM parameters), a disposable dev environment built from the golden AMI, and a reusable Lightsail module for the Node.js and AI apps.
- Own the CI/CD platform end to end across Jenkins and GitHub Actions: build, test, image push and automated deployment with rollback-ready pipelines.
- Built and operate a Python/FastAPI integration hub connecting the enterprise platform to a third-party RDP-based simulator: LTI 1.3 OIDC launch (RS256 JWT, JWKS, AGS grade passback), an HMAC-signed legacy launch flow, and xAPI score reporting that is idempotent against re-grades. Every external call has exponential-backoff retries and dead-letter handling, so the workflow keeps running through vendor outages.
- Built and run in production an AI course assistant on Amazon Bedrock (Titan embeddings, Cohere Rerank, Claude). It answers learners only from course content, cites the source slides and declines out-of-scope questions. Hosted on Terraform-provisioned Lightsail with a Bedrock-only IAM user and per-answer cost logging.
- Architected a two-tier, offline-first platform for maritime environments: a cloud instance serving 10,000+ users plus Docker-based edge instances running fully offline on vessels with periodic sync. Built the Python sync agent (5-minute cycle, offline queue, exponential backoff, FK-safe ID mapping) and the FastAPI cloud sync API with API-key auth.
- Led the Moodle 3.10 to 4.5 LTS (IOMAD) upgrade: rehearsed the cutover in Docker on production data, fixed a collation mismatch that would have aborted it, and wrote the cutover and UAT runbooks. Upgraded RDS MySQL 8.0 to 8.4 via Blue/Green.
- Own the full image lifecycle for 500+ Linux hosts at remote sites: LUKS-encrypted data partitions, local RPM repository, anti-tampering checks, automated TLS renewal and provisioning bootstrap. Unattended hosts stay patched, encrypted and trusted with no engineer on site.
- Maintain golden Windows and Linux AMIs with Packer (preinstalled applications, drivers, GPOs). The production Moodle AMI is baked from GitHub Actions with OIDC role assumption, so no AWS keys are stored in CI.
- Built a Node.js tool (Prisma, AdminJS, S3) that prepares the course catalogue for import into Adobe Learning Manager: content upload, S3 reconciliation and import-ready CSVs.
- Automated recurring operational work in Python and Bash: course packaging into GPG2-signed encrypted artifacts pushed to S3, bulk user import and log analysis.
- Handle 2nd/3rd-line incident response across infrastructure and applications, including root-cause analysis and the follow-up work that prevents repeats. Maintain the team's technical documentation.
- Own the LMS application lifecycle: version upgrades, performance tuning, security hardening, proctoring, and custom auth, reporting and user-sync APIs.