- Built and operationalized the gateway across dev, test, and production — API Gateway, a Node.js Lambda reverse proxy, Cognito as the OAuth 2.0 / OIDC authorization server with custom SMART scopes, and WAF, deployed with AWS SAM through CI.
- Designed the group-to-scope mapping that enforces limited-access behavior, separating a restricted test user from the full-access group so scope enforcement was provable to the auditor.
- Diagnosed production failures across a four-vendor boundary — access errors on production patient records, cross-vendor client authentication, and compression handling for large clinical payloads — driving vendor-side remediation.
- Authored the disaster-recovery control response for the client's system security plan, documenting the gap in native backup capability and specifying the export approach. A compliance artifact, not just an engineering one.
- Wrote and delivered the troubleshooting runbook and both client-facing runbooks, then led knowledge transfer across the client and vendor teams.
On the role. A colleague was technical lead; I was the implementation arm.
The compliance artifact, the runbooks, and the knowledge transfer are mine — and the standard
was new to the whole team at kickoff, which is rather the point.
SMART on FHIRHL7 FHIR R4OAuth 2.0 / OIDC / PKCEAmazon Cognito
API GatewayLambda (Node.js)AWS SAMAWS WAF