kyle@potter — zsh

  

[ currently @ Coalfire Systems ]

Kyle Potter Technical Site Reliability
Engineering Manager

Engineer with 8+ years architecting secure, scalable cloud infrastructure for enterprise and government clients. Deep expertise in FedRAMP & GovCloud environments, AWS, Linux systems administration, security tooling, vulnerability management, and Kubernetes-based microservices. Currently focused on the secure adoption of AI and agentic workflows to improve developer velocity without compromising compliance posture.

Portrait of Kyle Potter

About

I lead technical strategy and delivery for large-scale, highly audited cloud environments — spanning AWS GovCloud, FedRAMP Moderate, and DoD IL5. My work sits at the intersection of infrastructure automation, security compliance, and platform reliability: building the Infrastructure-as-Code, CI/CD pipelines, and Kubernetes platforms that let engineering teams move fast inside heavily regulated environments — and lately, exploring how agentic AI tooling like Claude Code fits into that world without breaking the compliance model.

8+ Years in Cloud & Infra
40k+ Locations Supported
70+ AWS Accounts Connected
7 Cloud Certifications

Experience

Jul 2025 — Present

Technical Manager, Site Reliability Engineering

Coalfire Systems Inc · Chicago, IL (Remote)

  • Serve as technical lead for a large enterprise organization in AWS GovCloud, triaging incoming work and assigning duties based on expertise and capacity.
  • Drive technical strategy and project delivery for FedRAMP and DoD IL5 GovCloud environments; play a lead role in audits, providing evidence and NSS controls for management-plane security tooling.
  • Created and optimized GitLab CI/CD pipelines for continuous deployment of containerized workloads to EKS clusters, automating Splunk, Trend Micro, and Nessus agent rollout.
Aug 2023 — Jul 2025

Senior Engineer, Cloud Services / Senior Site Reliability Engineer

Coalfire Systems Inc · Chicago, IL (Remote)

  • Led client workshops evaluating application architecture for FedRAMP Moderate and IL5 High environments; developed Lucid Charts diagrams for data flow, access controls, and network protocols.
  • Collaborated with architects on scalable, secure systems meeting FedRAMP requirements; helped build company-wide Terraform modules incorporating FIPS endpoints and security best practices.
  • Ensured continuous NIST compliance via automated monitoring and remediation with Ansible; enforced STIGs using DISA playbooks and Packer-built AMIs.
Feb 2022 — Aug 2023

Senior Cloud Engineer

2nd Watch · Liberty Lake, WA

  • Built and managed AWS cloud infrastructure for McDonald's Managed Services, supporting environments across 40,000+ locations worldwide.
  • Architected AWS Transit Gateway to securely connect 70+ accounts, replacing legacy VPC peering; implemented AWS Identity Center with role-based access for 1,000+ users.
  • Established cloud adoption standards with the architecture team, building a company-wide patching solution on AWS patch baselines and Systems Manager maintenance windows.
Dec 2020 — Feb 2022

Linux Systems Engineer

Two Barrels · Spokane, WA

  • Built and maintained open source infrastructure for 500+ employees across Two Barrels, Registered Agents, and Corporate Tools with full autonomy over tooling decisions.
  • Deployed scalable systems across AWS and on-premises data centers, including email servers, ticketing systems, and Kubernetes clusters.
  • Automated configuration management for 100+ Linux servers via Bash and Ansible; built a real-time VPN monitoring dashboard with Python/Django.
Apr 2018 — Dec 2020

CloudOps Engineer

2nd Watch · Liberty Lake, WA

  • Drove Infrastructure-as-Code adoption using Terraform and CloudFormation; deployed Cloud Custodian, New Relic, Qualys, and SentinelOne for compliance, monitoring, and endpoint security.
  • Developed Python scripts and Lambda functions for multi-region resource automation, plus Bash/Ansible for consistent Linux configuration management.

Projects

Homelab · GitOps GitHub ↗

Talos + Flux GitOps Cluster

Architected and self-host a 3-node bare-metal Kubernetes cluster on Talos Linux — an immutable, API-only OS with no SSH and a minimal attack surface — driven end-to-end by Flux CD with zero manual kubectl apply. Built a progressive delivery pipeline that auto-promotes changes through dev → staging → production via Kustomize overlays, with cert-manager issuing Let's Encrypt TLS automatically, Sealed Secrets for encrypted-at-rest credentials, and MetalLB/NGINX handling bare-metal ingress.

Talos LinuxKubernetesFlux CDCilium KustomizeHelmcert-managerMetalLB Sealed SecretsGitHub Actions

Skills

Cloud Services

AWSGovCloudEKSECS FargateLambdaIAMVPC AWS Identity CenterCloudFormationSystems Manager Transit GatewayAzureAzure Entra IDSSO

DevSecOps & IaC

LinuxBashPythonContainers KubernetesWindowsTerraformAnsible GitLab CI/CDPackerJenkinsTerragrunt GitHub ActionsFluxArgoCDClaude Code Agentic AILucid ChartsDraw.io

Security Tooling

TenableTrend MicroSplunkBurpSuite AquasecAnchorePrisma CloudSentinelOne New RelicQualys

Certifications

  • Google Professional Cloud Security Engineer
  • Certified Kubernetes Administrator (CKA)
  • HashiCorp Terraform Associate
  • AWS Solutions Architect Associate
  • AWS Developer Associate
  • AWS SysOps Administrator Associate
  • AWS Cloud Practitioner

Contact

Open to conversations about cloud security, FedRAMP/GovCloud architecture, and agentic AI in regulated environments.