Christian D Wallace
Profile
I'm a Senior Site Reliability Engineer with 10 years of experience combining deep networking with modern cloud platform engineering. I operate Instructure's multi-region Kubernetes platform, powering Canvas LMS for tens of millions of learners worldwide, and I'm known for owning multi-region migrations end-to-end and building the reusable infrastructure application teams build on.
Work Experience
Senior Site Reliability Engineer
- Built Instructure's internal developer platform ("Trigger") powering Canvas LMS across 40 EKS clusters in 8 AWS regions with 433 active service deployments on Akuity-managed ArgoCD GitOps with Helm/Kustomize and Kyverno policy-as-code, giving every team a self-service path to ship and scale services. Now building Trigger's next-generation deployment API on Node.js/Express and MongoDB with Go and Python tooling, replacing the legacy internal PaaS it runs on
- Architected and built Instructure's AWS Transit Gateway mesh with Terraform and Ruby, migrating off a self-hosted VyOS mesh running iBGP and OSPF with zero customer downtime. The new mesh has held five-nines uptime since cutover and cut the administrative overhead of running our own routing infrastructure. Also led a fleet-wide TGW security-group referencing rollout across 34 TGWs in 9 regions, trimming thousands of CIDR-based rules
- Led company-wide Zero-Trust modernization, migrating to AppGate ZTNA to replace scattered SSH keys, a legacy Teleport VPN, and the GlobalProtect client VPN, eliminating the bottleneck of routing all traffic through HQ. Also rolled out ArgoCD Okta SSO via SCIM and HashiCorp Vault, giving every engineer centrally managed, auditable access
- Designed org-wide security tooling, including CrowdStrike CSPM, Wiz, and AWS Config StackSets. When that tooling caught an active post-compromise incident, used it to trace what changed and tuned AWS WAF rules in real time to contain the attack, then led the migration to Signal Sciences for longer-term WAF coverage
- Owned observability and CI/CD strategy, spanning Datadog/Observe dashboards, GitHub/Gerrit for version control, and Jenkins/GitHub Actions pipelines that gave every team a paved-road way to ship and debug safely
- Architected network/IAM for new AWS LZA accounts end-to-end, replacing one-off account requests with a group-based access model every team now onboards through
Network Engineer
- Engineered Cisco ASA 5508 AnyConnect VPN split-tunneling during the COVID-19 remote-work transition, cutting corporate bandwidth utilization by 60% overnight for a fully remote financial-services workforce
- Built centralized network configuration and change-management automation using NetBrain, RANCID, NetBox, and Cisco ACI, giving engineering teams automated drift detection, nightly config history for faster troubleshooting, a single source of truth for IP allocation, and declarative fabric policy instead of manual CLI changes
Network Engineer I
- Led migration of 30+ customer Site-to-Site IPsec VPN tunnels from Dell SonicWall to Cisco ASA 5525, coordinating cutover windows and policy translation directly with each B2B partner's network team
- Designed and built the entire network for a new company headquarters, including switches, Meraki access points, and Cisco SD-WAN, enabling branch sites to route directly instead of backhauling through a hub-and-spoke WAN, cutting latency and adding resilient failover
Technical Solutions Analyst
- Owned tier-3 production incident response for a 24/7 mission-critical EHR platform serving healthcare providers nationwide, troubleshooting complex outages where every second counted for clinicians making time-sensitive care decisions
- Administered production Linux systems at the OS level and wrote SQL directly against application databases to correct corrupted data and resolve failures that restarts and scripted fixes couldn't touch
Education
Additional