Resume ↓ Contact me

Bonjour.

Français

I'm Rimon Mikhael — cloud automation & platform engineering.

Here, building means observing, automating and revealing. Platforms that are reliable, living and honest.

Scroll

The engineer

Rimon Mikhael, out in the world

I'm a cloud automation and infrastructure engineer working across research and healthcare IT environments. My strength isn't only operating infrastructure — it's building the software around it.

My background runs from low-level systems work in C and Linux up through Python, Django, Go and cloud SDKs — now steering toward MLOps and AI infrastructure operations.

rimon@phl: ~/career — bash

          

R. Mikhael

Rimon Mikhael

Greater Philadelphia,
Remote

Currently

Children's Hospital of Philadelphia —
Research Institute, Roberts Center for Pediatric Research

Automation & orchestration engineer · mostly remote

At CHOP's Research Institute I develop whole application suites and systems around research infrastructure — working primarily in automation and orchestration, HPC, the VMware vRealize / Aria suite, and the automation and administration of our AWS Control Tower.

Among those suites: the notification system for research infrastructure, the reporting apps, and the Cirrus dashboard — and they are far more than dashboards. Heavily integrated with each other over REST APIs, they plug into our administration core across the whole estate: VMware vCenter, AWS, Azure, Pure Storage, Isilon, Starfish (which the reporting app integrates with directly), HashiCorp Vault, Dell ECS, Microsoft 365, and the HPC clusters. They run workflows directly from VMware Aria Automation and integrate with AWS Lambdas — AWS Config can reach endpoints and trigger webhooks across the stack.

I've also built end-to-end provisioning pipelines — deploying VMware virtual machines, Azure VMs, and EC2 instances on AWS from a single automation flow — and integrated with our Horizon VDI infrastructure.

Right now I'm also integrating a wearable device from our research teams into an MLOps pipeline, with a dashboard for the data it gathers.

I code from assembly to C to Python, work comfortably across the full stack, and carry a strong core background in machine learning. I know it sounds impossible — I just love computers.

Looking ahead

There's one dream I intend to finish: my master's degree. Work comes first — it always has; I'm a hard worker before anything else — and the degree is what I build around the work, never instead of it. The ideal next chapter is a role with a university, where tuition support is part of the deal: I'll gladly relocate, and gladly trade some salary, for the chance to close that loop. Education is the long game — and I play long games.

Fields of work

Manifesto

Every manual process is a platform waiting to happen. I listen to how the infrastructure is really used, transform the routine into software, and reveal the costs, the waste and the truth.

Rimon Mikhael at night beneath the bridge, New York
New York — off duty.

Selected projects

Billing & Chargeback Platform

CategoryBilling & Chargeback

MaterialsDjango, Python, SQL, PDF & email

StatusIn production

Infrastructure billing usually lives in spreadsheets and tribal knowledge. This platform replaced both with Django applications that price and bill fileshares, VMs, physical servers and HPC usage — owner mapping, cost-centre tracking, per-U rack pricing, all in one place.

One click renders owner-specific PDF bills and emails them to owners or entire distribution groups. And every six months, each PI receives an access report of exactly what they hold — the fileshares, AWS accounts and virtual machines under their name — so reviews happen on schedule, not on suspicion.

The dashboards reveal what billing systems usually hide: unattributed costs, expired records, missing CMDB entries. A billing platform that quietly audits the whole estate.

Storage Automation & Isilon Operations

CategoryStorage Operations

MaterialsIsilon/OneFS, SMB/NFS, Starfish, CMDB

StatusIn production

Enterprise storage answers to no one — until you make it. Automated collection and reporting of quotas, shares, ownership and access groups across Isilon/OneFS, cross-checked against CMDB and Starfish until every gap has a name and an owner.

It drives safe decommissioning end to end as well — export removal, AD group cleanup, CMDB updates, controlled filesystem cleanup — the risky manual steps encoded as one repeatable, reviewable workflow.

AWS Control Tower Governance

CategoryCloud Governance

Materialsboto3, STS, Organizations, Lambda

StatusIn production

Cross-account governance as code: role assumption at scale through STS, landing-zone checks, account lifecycle operations and S3 policy automation across the entire organization.

Purpose-built governance Lambdas patrol the fleet, aligned with the latest CIS benchmarks for AWS security — so compliance is continuous rather than an annual scramble.

Drift detection returns clean true/false answers that orchestration can act on directly — with full operational logging kept underneath, for the humans.

VMware vRA / vRO Workflows

CategoryVirtualization Workflows

MaterialsAria Automation, vRO, vCenter, REST

StatusIn production

ServiceNow and Cirrus — our custom front end — drive vRO/vRA as the orchestration backbone for the entire infrastructure request catalog:

01Isilon filesharescreated end to end
02Dell ECSIAM management & S3 buckets
03Vaultnamespaces · secrets in and out
04AWS accountsprovisioned on request
05Kubernetesclusters on AWS & VMware TKG
06Globus · VDI · ElasticsearchCHOP-built request flows
07Virtual machinesprovisioning & Horizon VDI access

One front end, one orchestration backbone, every request auditable — and it survived the Aria upgrades, too.

HPC Usage & Efficiency Reporting

CategoryResearch Computing

MaterialsSlurm, Python, RHEL VDI, Docker, vRO, Workday API

StatusIn production

Raw Slurm job data — CPU and memory efficiency, requested resources, runtime — turned into reports research stakeholders actually read: usage, waste, performance and cost drivers, per job and per group.

Beyond reporting, I've been reshaping how researchers reach the cluster itself: custom RHEL VDIs deployed as user shells, sparing the login nodes, with a purpose-built Docker container for app deployment and a custom wrapper that tames the greedy accounting algorithm behind user quotas.

The VDIs are provisioned through vRO workflows and requested through Cirrus and ServiceNow — with approvals flowing from PI grants via the Workday API. Access to the cluster became a governed request, not a shared bottleneck.

Azure Research Self-Service & Events

CategoryCloud Platform Engineering

MaterialsDjango, React, Terraform, Azure Bastion

StatusWorking proof · governed rollout

The CHOP Azure Research Portal turns VM delivery into a governed product: Platform Administrators, PIs and research users each receive a purpose-built workspace for grants, requests, access, approvals and lifecycle operations.

Terraform plans are immutable and checksum-verified; grant expiry closes unsafe requests; Azure Bastion keeps SSH native to Entra ID; GitHub and future Terraform Enterprise integration are captured as explicit architecture decisions rather than hidden coupling.

Public code

Personal projects — the Daisy suite

Eight self-hosted homelab apps built around local AI: research, voice, media, orchestration, learning, narration, graphs and model operations. Hover for a glimpse; click for the full story.