Skip to content
MKMukesh Kasliwal
AWS Management

Your AWS, owned by one senior engineer.

Monitoring, incident response, cost optimization and security under a defined monthly plan — with a response time you can hold me to.

01What's included

Everything below, at every tier

The higher tiers add scope and shorten the response window. Nothing in this list is an upsell.

Monitoring & alerting

Coverage across your AWS services, tuned so alerts mean something. You find out from me, not from a customer.

Incident response

When something breaks, a senior engineer is on it inside the window your plan guarantees — not queued behind other accounts.

Cost optimization

Continuous, not an annual spring clean. Right-sizing, commitment planning, and killing what nothing is using.

Patching & updates

Operating systems, runtimes and managed-service versions kept current, scheduled so it does not land in the middle of your week.

Backup verification

Backups tested by restoring them. An untested backup is a belief, not a recovery plan.

Infrastructure as code

Changes made in Terraform and version-controlled, so the environment can be rebuilt and every change has a history.

Security review

IAM permissions, exposed endpoints, credential hygiene and stale access reviewed on a schedule rather than after an incident.

Monthly report

What happened, what it cost, what changed, and what I recommend next — in a form you can forward without rewriting it.

Need a bounded, one-off project instead of an ongoing retainer? See project work.

02Pricing

Three tiers, one engineer

Ranges rather than fixed prices — where you land depends on the size of the account and how much of it I take on. Every tier carries a guaranteed response time.

SLA Standard

$300 – $700/month

Stable production workloads that need an owner.

Incident response within 4 hours

  • Monitoring and alerting across your AWS account
  • Incident response when something breaks
  • Monthly cost review with recommendations
  • Routine security checks and patching
  • Backup verification — tested, not assumed
  • A monthly report you can forward to your board
Book a free AWS audit
Most chosen

AWS Operations Partner

$1,500 – $2,500/month

Growing SaaS where AWS cost and reliability have become board-level concerns.

Incident response within 2 hours

  • Everything in SLA Standard
  • Cost management worked against an agreed savings target
  • Quarterly architecture review as the product changes
  • Ownership of the deploy pipeline
  • Bi-weekly cost reviews, not just monthly
  • A direct Slack channel — no ticket queue
Book a free AWS audit

Fractional CTO

$4,000 – $8,000/month

Funded SaaS that needs infrastructure leadership without a full-time hire.

Incident response within 1 hour

  • Everything in AWS Operations Partner
  • Infrastructure roadmap ownership
  • Security posture and compliance readiness
  • Hiring and vendor guidance for your technical team
  • On-call coverage
  • Direct line for architecture decisions as they come up
Book a free AWS audit
03The arithmetic

The retainer usually pays for itself.

A typical AWS account carries 20–40% of avoidable spend: oversized instances, unattached volumes, forgotten environments, storage on the wrong tier, and reserved capacity nobody renewed. On a mid-size AWS bill, recovering that covers the retainer and leaves change.

The saving scales with your bill

The bigger the account, the more there is to recover — and the more the arithmetic favours having someone own it.

It compounds monthly

A right-sized instance is not a one-off refund. It is a lower bill every month thereafter.

The audit is free

You get the findings in writing before you commit to anything. If there is nothing worth recovering, I will say so.

A documented before-and-after with the real numbers is available in the case-study write-up.

04The alternatives

What you are actually choosing between

Every option here is one somebody has picked. This is the honest version of how they compare.

Working with me

Monthly cost
$300 – $8,000
Time to productive
Days
Senior AWS depth
Yes
Owns both the app and the infrastructure
Yes
Guaranteed response time
Yes
Cost optimization as standard
Yes
Continuity when someone leaves
Documented and handed over
Cancel at short notice
Yes

In-house hire

Monthly cost
$10,000+ fully loaded
Time to productive
2–3 months to hire, then ramp-up
Senior AWS depth
Depends who you land
Owns both the app and the infrastructure
Rarely both
Guaranteed response time
Business hours, if not on leave
Cost optimization as standard
Competing priorities
Continuity when someone leaves
Single point of failure
Cancel at short notice
No

Agency

Monthly cost
$5,000+
Time to productive
Weeks
Senior AWS depth
Sold senior, staffed junior
Owns both the app and the infrastructure
No
Guaranteed response time
Ticket queue
Cost optimization as standard
Usually billable extra
Continuity when someone leaves
Account team churn
Cancel at short notice
Annual contract typical

Doing nothing

Monthly cost
Nothing — until an outage
Time to productive
Senior AWS depth
No
Owns both the app and the infrastructure
No
Guaranteed response time
No
Cost optimization as standard
No
Continuity when someone leaves
No
Cancel at short notice
Yes
05Guarantees

What is guaranteed, and what is targeted.

Naming the difference matters. A vendor who guarantees uptime they do not control is telling you something about how the rest of the contract will go.

Guaranteed

  • Incident response times — 4, 2 or 1 hour depending on your plan
  • Monitoring coverage across the agreed services
  • A monthly report, delivered on schedule

Targeted

  • 99.9% uptime — the standard the architecture is built toward
  • 20–40% reduction in avoidable AWS spend

I do not guarantee uptime, because I do not control your application code and I am not going to promise something I cannot underwrite. What I guarantee is that when something breaks, a senior engineer is already looking at it inside the window you are paying for.

06Availability

Working hours, stated up front

I work from IST (UTC+5:30). Here is the honest overlap with the regions I work in most.

UK

1:30pm – 10:30pm IST

Full working-day overlap

US East

6:30pm – 2:30am IST

Afternoon overlap, calls scheduled to suit

Australia

5:30am – 1:30pm IST

Morning overlap

Calls are scheduled to fit your working hours, not mine. Incident response runs to the guaranteed times in your plan regardless of timezone.

07Worked example

The worked example, with the real numbers.

The case study behind the 20–40% figure: what the account looked like before, what changed, and what it cost each month afterwards. Actual figures, not percentages.

I will send it over by email.

08SLA questions

Contract, access and escalation

The questions worth asking before handing anyone your AWS account.

Is there a minimum contract length?

No. Retainers run month to month. I ask for 30 days notice to cancel so there is time to hand over documentation, access and any in-flight work properly — but there is no annual commitment and no exit fee.

What happens if we cancel?

You get a handover: Terraform state and code, runbooks, monitoring configuration, and a written summary of outstanding risks. Access I hold is revoked by you. Everything I built for you was in your account and in your repository the whole time, so nothing is held hostage.

What access do you need, exactly?

An IAM role you create, scoped to the services in your plan, with permissions I can enumerate for you before you create it. Read-only to begin the audit. No root credentials, ever, and no shared user accounts — everything I do is attributable to that role in CloudTrail.

How does escalation work during an incident?

You have a direct channel — Slack on the higher tiers, email otherwise — and the response clock starts when you raise it, not when I next check. Incidents get an acknowledgement, a running update while I work, and a written summary afterwards covering cause and what changed to prevent a repeat.

What if the problem is in our application code, not the infrastructure?

Then I fix it, if it is within the scope we agreed, or I tell your team exactly where it is and why. That is the point of hiring someone who has spent 13+ years writing production PHP rather than a pure infrastructure specialist — the diagnosis does not stop at the boundary.

Do you work with teams outside your timezone?

Yes, and the overlap is published above rather than glossed over. Response-time guarantees hold regardless of timezone; scheduled calls are set in your working hours.

Stop firefighting your AWS.

Book a free AWS audit