Case Study
Atlas Air — Building the AWS Landing Zone, CCoE Guardrails, and Bedrock-Ready Platform for a 1,000-Server Migration

Atlas Air
Role
AWS Solutions Architect & AI Integration Lead
Period
September 2025 – Present
Duration
Ongoing
Reporting Line
VP of IT and Director of IT
Industry
Air Cargo / Aviation
The Situation
Atlas Air — one of the world's largest air cargo operators — had been acquired, and the new owner mandated a full migration of all on-premises infrastructure to AWS on a hard deadline. Data center leases were expiring; there was no flexibility on the timeline.
Atlas had no internal cloud personnel. Accenture had managed their on-prem infrastructure for years. Rackspace had been brought in to execute the migration. After almost a year, the program was still spinning its wheels — even standing up a Landing Zone had taken longer than expected.
They needed a senior AWS architect who would personally design the target platform, write the guardrails that controlled what engineers could access and deploy, and establish Bedrock-ready patterns so generative AI could follow without rework.
Why Bring Me In
A 1,000+ server migration on a fixed deadline, across Accenture, Rackspace, and internal IT/security — with simultaneous CCoE and AI readiness work — needed hands-on cloud architecture and platform engineering immediately. Not a permanent VP search. Not a deck. Someone who would build the landing zone, the guardrails, and the migration path in code.
What I Built
- •
Architected the multi-account AWS landing zone. Designed the complete target environment — multi-account strategy, VPC topology, Cloud WAN, Direct Connect, hybrid connectivity (Cisco DMVPN, Palo Alto VM-Series), and core platform services — then deployed it with CDK and Terraform.
- •
Stood up the Cloud Center of Excellence (CCoE) and wrote the guardrails. Defined CCoE scope for IAM, networking, environment strategy, and deployment standards. Built Python-based guardrails that controlled what engineers could access and deploy — so every workload onboarded through the lift-and-shift (and future cloud-native work) stayed inside consistent, enforceable boundaries.
- •
Designed Bedrock-ready AI governance. Multi-account Bedrock model with least-privilege IAM, model invocation logging, and cost controls — plus architecture patterns for future RAG pipelines integrating enterprise data sources with Bedrock Knowledge Bases.
- •
Hardened security and privileged access. RBAC integrated with CyberArk, WAF and centralized inspection VPCs, identity/network/logging patterns aligned to Atlas requirements and AWS-native services.
- •
Built serverless data and integration patterns. Lambda, Step Functions, and EventBridge pipelines for operational data. Designed future-state high-availability SFTP (Globalscape EFT) across regions, plus migration strategies for Oracle RAC, AIMS, and related airline workloads.
- •
Drove cost and DR architecture. FSx for NetApp ONTAP storage modernization with $30K+ projected annual savings. Multi-region disaster recovery with automated failover. Sequenced migration waves for 1,000+ servers across vendor and internal teams.
Business Outcomes
- •
1,000+ servers on a structured path into a production-ready multi-account AWS footprint
- •
CCoE guardrails in place — Python-enforced controls on what engineers can access and deploy
- •
Bedrock-ready AI governance before generative AI scale
- •
$30K+ projected annual savings through storage modernization
- •
Multi-region DR posture with automated failover designed into the platform
What I Left Behind
- •
A production-ready, multi-account AWS landing zone deployed via CDK and Terraform
- •
CCoE standards and Python guardrails for IAM, networking, environments, and deployments
- •
A documented AI/Bedrock governance framework ready for RAG adoption
- •
Architecture artifacts, diagrams, and patterns guiding vendors and internal teams through the remaining migration waves
