AWS Cost Optimisation
Your AWS bill is 20-50% higher
than it needs to be
I find where the money leaks — and fix it with your team. No slide decks, no rebranded reports. Just savings on your next invoice.
Sound familiar?
Where AWS budgets quietly die
NAT Gateway eating $/GB on every request
One of the top surprise line items. Private subnets pay $0.045/GB just to reach the internet — even for traffic that could stay inside AWS.
No Savings Plans or Reserved Instances
On-demand pricing for workloads that never stop. 30-60% discount left on the table because nobody owns FinOps.
Oversized EC2/RDS/EKS running 24/7
Instance type picked during a spike and never revisited. CloudWatch CPU sits at 8%. Dev runs Multi-AZ.
Zombie resources on every invoice
Idle load balancers, unattached EBS volumes, snapshots from 2022. They never show up in product — only on the bill.
How I work
From AWS bill chaos to clear savings in three steps
1. Scan — free 30-min call
Screen-share Cost Explorer + a quick walkthrough of your architecture. Within 30 minutes I name the top 3 leaks and rough savings range. No commitment.
2. Audit — 1-2 weeks
Read-only access to your AWS account. I produce a prioritised waste report: NAT/data transfer, right-sizing candidates, Savings Plan/Spot strategy, lifecycle policies, zombie resources. Each finding ranked by $/month impact and effort.
3. Fix — alongside your team
Optional follow-up sprint. I ship the high-impact fixes with your engineers — Terraform/IaC PRs, not hand-waving. Savings land on the next invoice.
Deliverables
What you walk away with
Every finding ranked by $/month saved and engineering effort. PDF + spreadsheet.
1-year vs 3-year, compute vs EC2, coverage targets. Concrete buy recommendations.
EC2, RDS, EKS, ElastiCache. Specific instance type swaps including Graviton migration paths.
VPC endpoints, cross-AZ routing, S3 lifecycle policies, log retention. IaC examples included.
AWS Budgets, anomaly detection, cost allocation tags. So the next spike pings you, not the invoice.
Pair with your team to ship the top fixes. Terraform PRs, runbooks, knowledge transfer.
Case study
$60K → $20K/month — same workload, sharper architecture
Context
SaaS platform on AWS. Mid-size engineering team. Cloud bill ballooned to $60K/month — leadership demanded a cut without slowing the product.
Findings
Oversized RDS (Multi-AZ on staging), 40% NAT Gateway egress avoidable via VPC endpoints, no Savings Plans, K8s nodes at 25% utilisation, S3 buckets without lifecycle policies.
Outcome
Monthly AWS spend cut from $60K to $20K. Zero downtime. Three weeks of focused work. Savings landed on the very next invoice.
Engagement options
Three ways to work together
Fixed scope
Audit sprint
1-2 weeks
- ✓ Full audit + prioritised report
- ✓ Savings Plan / RI strategy
- ✓ Right-sizing list with IaC examples
- ✓ Budgets & alerts configured
- ✓ 30-day Slack follow-up
Ongoing
Fix sprint + retainer
From 4 weeks
long-term if needed
- ✓ Pair with your team on fixes
- ✓ Terraform PRs, runbooks
- ✓ Monthly cost review
- ✓ Architecture & FinOps coaching
Common questions
How much access do you need?
Read-only IAM role is enough for the audit (Cost Explorer, ReadOnlyAccess, Trusted Advisor). For fixes, write access is scoped per task — usually via your existing Terraform/CI pipeline, not direct console.
Will you slow my team down?
No. The audit runs in parallel — I work from read-only access. The fix sprint pairs with your engineers a few hours a week, not full-time. Your roadmap keeps moving.
What if we already use Savings Plans?
Coverage is usually 30-60% in cost-conscious teams. The audit checks coverage rate, commitment term mix, and waste from over-committing. Plenty of optimisation usually remains.
Do you work with GCP or Azure?
Yes, though AWS is my deepest stack. Cross-cloud patterns (NAT, egress, right-sizing) transfer well. Mention your provider in the call and I will tell you honestly if I am the right fit.
How fast do savings land?
Quick wins (zombie resources, Savings Plans, lifecycle policies) hit the next invoice. Right-sizing and architecture fixes land within 1-2 billing cycles depending on rollout pace.
What about data security?
Read-only role, no data egress, no third-party tools. All work happens in your AWS account. NDA on request.
Stop overpaying AWS this month
30 minutes, screen-share, top 3 leaks named. No slide deck, no obligation.