Cloud security engineer with over a decade of clinical healthcare experience across radiology, MRI, CT, and emergency departments, combined with hands-on compliance automation and AWS infrastructure engineering. Built the Compliance Engineering Platform: five production systems covering policy-as-code enforcement, automated audit evidence collection, HIPAA gap remediation, continuous security monitoring, and zero trust credential elimination. Brings a perspective on regulated data protection that is grounded in the clinical environments the controls are built to protect.
Experience
Radiologic Technologist · QA · Epic Super User
Jul 2023 – Present
Memorial Sloan Kettering Cancer Center · New York, NY
Serve as Epic Super User, governing clinical data access controls and improving system adoption across departments
Document and enforce compliance procedures aligned with DOH, HIPAA, and ACR regulatory standards
Maintain audit trails and logs for quality control, supporting regulatory audits and compliance reporting
Coordinate departmental policy updates to ensure adherence to risk and safety requirements
Oversee governance of imaging software, ensuring secure configurations and access controls
Radiologic Technologist
Nov 2016 – May 2022
Englewood Hospital and Medical Center · Englewood, NJ
Supported compliance initiatives in intraoperative environments through policy adherence and technical documentation
Maintained accurate patient data across imaging systems (PACS, RIS) in a regulated clinical environment
End-to-end compliance automation platform across AWS and GCP. Five production systems built from 11 labs covering policy-as-code enforcement, automated evidence collection, HIPAA gap remediation, continuous security monitoring, and zero trust credential elimination. Every system has a live interactive demo.
14 HIPAA control gaps identified and closed before audit. 94% reduction in policy violations reaching production. Audit prep reduced from 3 weeks manual to automated same-day collection. Mean time to detect configuration drift dropped from weeks to under 2 hours.
Compliance guardrails pipeline: OPA/Rego policy gates blocking IaC misconfigurations at pull request time. Every violation mapped to NIST 800-53 control reference.
Full-stack serverless resume deployed on AWS. S3 and CloudFront frontend with ACM certificate and WAF protection. Lambda and DynamoDB visitor counter. Infrastructure defined as code with Terraform and deployed via GitHub Actions CI/CD pipeline.
Production site live at chamb.dev. Zero-downtime deploys with CloudFront cache invalidation on every push to main.