RAFFAELE SOLLECITO · RÉSUMÉ
Full profile

Raffaele Sollecito

Principal Cloud Solutions Architect  ·  AWS Subject Matter Expert

Tavira, Portugal  ·  Remote / EU-wide engagements  ·  Italian citizen

Profile

Cloud architect with 10+ years across AWS platform engineering, security and DevOps, and six AWS certifications including Solutions Architect Professional and Security Specialty. I design and deliver multi-account landing zones, zero-trust identity and network perimeters, production container platforms and agentic AI developer platforms for regulated and enterprise clients — a European institution, Volkswagen, global mobile gaming, fintech, public-sector utilities and IoT. Independent since 2025 through Aspect Solutions.

Experience

Principal Cloud Solutions Architect & Founder

Jan 2025 – present
Remote

Aspect Solutions, Unipessoal Lda · Independent consultancy

  • Enterprise AWS and Azure architecture, security and DevOps for international clients in gaming, fintech, automotive, cybersecurity and IoT — see Selected Engagements below.
  • Lead architect for an IoT semiconductor client's AI-native developer platform on Bedrock AgentCore and multi-account GitLab OIDC delivery.

Cloud Architect

Sep 2023 – Jan 2024
Remote

PwC Luxembourg · Contractor for a European Institution

  • Designed the institution-wide centralised backup strategy on AWS Backup, aligned to the AWS Data Protection Reference Architecture.
  • Rolled out automated EC2 patching and org-wide CloudFormation StackSets.
  • Built S3-triggered automation keeping AWS Network Firewall rules current against malicious domains and IPs.
  • Led remediation of publicly exposed EC2 and RDS resources from Security Hub and Config findings; advised account owners on re-architecture.

Stack: AWS Backup · Network Firewall · Security Hub · Config · CloudFormation StackSets · Systems Manager

Cloud Solutions Architect

Feb 2023 – Jun 2023
Lisbon, Portugal

Volkswagen Digital Solutions

  • Delivered secure AWS accounts inside the MAN-compliant Group landing zone; automated provisioning with Step Functions.
  • Event-driven architecture with CDK and StackSets; cross-account roles and trust policies; Route 53 hybrid resolver shared via RAM.
  • Operated multi-account security tooling — DevOps Guru, Security Hub, custom Config rules — over Direct Connect and Transit Gateway.
  • Ran tech talks for engineering and management.

Stack: AWS CDK · Step Functions · Transit Gateway · Direct Connect · GitLab CI · Python

Solutions Architect

Oct 2021 – Feb 2023
Assago, Italy

ITnet Srl

  • Guided mid-market and enterprise clients through cloud adoption and hybrid operations; designed Control Tower landing zones with IAM integration.
  • Led post-disaster-recovery infrastructure redesign.
  • Integrated ServiceNow ITSM, CMDB and ITOM with AWS Service Catalog.
  • Assessed Azure SAP estate for AWS migration; migrated Jira Server to Jira Cloud.

Stack: Control Tower · Service Catalog · ServiceNow · Azure · Active Directory · Docker

AWS DevOps Engineer

Jun 2019 – Oct 2021
Milan, Italy

Tantosvago Società Benefit

  • Introduced Git Flow; built CI/CD for ECS workloads and CloudFront + S3 static sites.
  • Integrated partner REST APIs with mTLS via API Gateway Lambda proxy; custom SSO with Lambda authorizer, ElastiCache and DynamoDB.
  • Containerised Laravel applications on ECS Fargate behind NGINX with CloudWatch monitoring.

Stack: ECS Fargate · API Gateway · Lambda · DynamoDB · ElastiCache · PHP · Node.js · React

Full Stack Engineer

Apr 2018 – Dec 2018
Milan, Italy

Key Partner Digital

  • Led a multi-platform chatbot framework on AWS Lex and Claudia.js; Angular 2+ front-ends.

CEO & Lead Engineer

Jun 2015 – Mar 2018
Giovinazzo, Italy

Memories IT Company

  • Delivered web platforms for marketplace, booking, hospitality check-in, insurance and car-rental clients; Stripe and Google Maps / what3words integrations.

Stack: Angular 2+ · Vue.js · Yii2 · Magento · WordPress · Joomla · D3.js

Full Stack Engineer

Jan 2015 – Jun 2015
Remote

Francesco Lombardo

  • Forex web platform in PHP / CodeIgniter, MySQL and JavaScript.

Selected Engagements

AWS Platform Engineering & Edge Migration — Global Mobile Gaming

Mar 2026 – present

Conclusion — end client: a globally known mobile & web gaming publisher

Principal architect on the Conclusion team owning the Terraform platform that provisions production AWS infrastructure for three live game titles across multiple accounts, six EKS clusters and eleven Aurora clusters. Led the migration of seven production zones from Cloudflare to an AWS-native edge on CloudFront, WAFv2 and Shield Advanced — delivered on budget, with custom WAF rule sets and Origin Shield tuning. Designed the multi-region DR strategy for EKS, Aurora, ElastiCache/Valkey and CI/CD infrastructure as a single parameter-driven orchestration workflow, validated in a live failover drill. Delivered Amazon MQ (RabbitMQ) 3.13→4.2 engine and instance-class upgrades, AWS Backup with point-in-time restore across all production Aurora clusters, an EKS 1.35 upgrade with node auto-repair and Karpenter, Security Hub FSBP enablement and centralised Secrets Manager reconciliation. Defined ownership boundaries and least-privilege cross-account access for accounts co-managed with the client's platform teams. All changes shipped through ServiceNow change management with peer-reviewed, plan-gated CI and design docs versioned with the code; authored and ran a hands-on CloudFront/WAF workshop for 12 engineers across two practice teams.

AI-Native Internal Developer Platform & Engineering Modernisation

Jul 2025 – present

Global IoT positioning & wireless semiconductor company (via InterEx)

Principal architect of the "0 Code AI" programme: an agentic internal developer platform (AppCommandCenter) on Amazon Bedrock AgentCore, Lambda, EventBridge and DynamoDB, with a React dashboard behind a same-origin BFF and central Cognito / Entra ID SSO. Delivered repo-discovery, architecture-compliance and RAG chat agents that gate GitLab merge requests and answer engineering questions with cited sources; shipped to dev, staging and production through GitLab OIDC credential-less CI with tagged releases. Designed and rolled out cross-account GitLab OIDC deploy roles (AWS CDK) across eleven client AWS accounts, enforcing environment separation and least privilege. Remediated all AWS Security Agent High/Medium findings with fail-closed allowlists, TDD and independent review. Architected the HA self-managed GitLab on AWS (CloudFormation, 500+ users, Entra ID SSO), migrated repositories from GitHub and legacy SVN with full history (119k-commit pilot), and, in a five-person team, re-platformed the company wiki on AWS serverless.

Cloud Platform, Compliance Archive & Security Operations — Regulated Fintech

Aug 2023 – present

UCapital24 — FCA-regulated fintech group

Long-standing cloud architect and de-facto head of IT security. Built the AWS foundation: Control Tower landing zone with Security Hub, Google Workspace SAML SSO into IAM Identity Center and GitLab OIDC credential-less CI/CD; ECS microservices (CloudFormation + Copilot) streaming real-time market data over WebSockets, AppSync GraphQL, Managed Grafana and a SharedServices account with cross-account least privilege. In 2026 delivered an immutable email-compliance archive — Gmail journaling into S3 Object Lock (compliance mode, 7-year retention, KMS, Lambda-indexed manifest) — and exported 218k messages from 97 dormant identities to Deep Archive, cutting the Workspace licence bill by ~$12k/year (≈51%). Led the response to a P1 brand-impersonation BEC attack on an advisory client: forensic timeline, tenant-wide containment, registrar takedown packages and the FCA disclosure assessment; then hardened SPF, DKIM and DMARC across ten domains. Delivered a Microsoft 365 → Google Workspace migration with an atomic Route 53 MX cutover and no mail loss. Provisioned a governed AI-Services account with organisation-wide Bedrock access (redesigned Control Tower region guardrails, reconciled in Terraform), designed the multi-region HA replication of the production backend to the US, and decommissioned 73 legacy resources across two accounts.

Landing Zone & Multi-Tenant Kubernetes Platform — Public-Sector Gas Distribution

Jan 2024 – Dec 2025

ReeVo Cloud & Cyber Security — public-sector gas distribution end client

Control Tower + Security Hub + IAM Identity Center federated with Entra ID; hub-and-spoke Transit Gateway with Direct Connect and VPN failover; Network Firewall with Suricata rule sets. Multi-tenant EKS with namespace isolation, ArgoCD GitOps, Karpenter and NGINX ingress. Terraform observability modules across RDS, DocumentDB, ECS/EKS, CloudFront, WAFv2 and ALB/NLB. Private NLB → API Gateway → CloudFront delivery with WAF, Cognito OAuth 2.0 and KMS; CI/CD on CodeCatalyst.

AWS Infrastructure Modernisation — Connected Vehicle Platform

Jan 2025 – Feb 2025

AWAKE Mobility — automotive IoT

Prod/Dev/QA multi-account architecture aligned to the Well-Architected Framework; Entra ID SSO with least-privilege permission sets; VPC segmentation and Network Firewall; Bitbucket ↔ IAM Identity Center credential-free CI/CD; AWS Backup with cross-region replication; CloudWatch, Uptime Kuma and Sentry monitoring; CloudFormation and Terraform IaC; SNS/SQS/Lambda event-driven guidance.

References