Colin Sanders

Senior engineer at AWS building the software that qualifies every server entering EC2's fleet. Shipping products on the side.

Featured Project

Shuolio

An AI-powered Mandarin learning app. I'm building it while learning the language myself, using it to work through the gaps that existing tools leave open.

The first release focuses on conversation practice: real-time voice conversations with an AI tutor. Next is a full curriculum system with structured lessons and spaced repetition.

AI has handed us tools that can orchestrate learning, adapt to individual levels, and surface information instantly. Most of the assumptions behind how we teach and learn haven't caught up. I'm interested in what happens when you rebuild from those new primitives.

React NativeFastAPIClaude APIElevenLabs
Conversation practiceExercise selectionExercise details

Experience

Senior engineer at Amazon, currently in AWS Hardware Engineering. I build the automated testing that gates every server on its way into EC2's fleet.

Datacenter fleet qualification

I work in AWS Hardware Engineering on the software that qualifies server hardware for EC2's global fleet — automated testing that gates every host through the landing lifecycle, from the manufacturing line to the datacenter to sellable capacity, including AI/hyperscaler platforms.

Recent work: compute-test optimizations returning 2,000+ host-hours/month to sellable capacity, continuous machine-health monitoring across the fleet, and AI-powered observability tracing any code change to the hardware running it across a multi-million-server fleet. I also author and review company-wide AI agent skills for hardware debugging, deployment tracking, and ODM host flashing.

Previously: Amazon Security

Sept 2024 – Feb 2026, in the vulnerability management org. I built systems that routed security vulnerabilities to the right owners with enough context to act on them.

High-throughput data infrastructure

Security signals come from everywhere: host agents, network scanners, container monitoring, cloud configuration, network telemetry, access management changes. The systems I built ingested millions of these signals per second, enabled security engineers to precisely assess risk in real time, and routed it to the teams responsible.

Developer tooling and rule engines

Engineers needed to define rules for how findings got classified and routed, and test those rules before they went live. I built interpreters and execution engines for custom rule languages and scanning platforms, and preview systems that simulated rule changes against petabyte-scale production data.

AI-assisted operations

When a vulnerability showed up, it was critical to figure out who owned the affected system and whether it was exploitable in context. I built MCP tools that augmented and enhanced this research, searching internal documentation and ticket history to find ownership and assess exploitability. Human processes that took weeks converged on seconds.

Past work

Centralized congestion control infrastructure that restored scanning across millions of AWS accounts after emergency throttling. Detection authoring tooling and interfaces for cloud compliance scanning systems. Integration platform for Amazon Business external partners.

About

Based in Seattle. At Amazon, I author and review company-wide AI agent skills and run workshops on AI-accelerated development. I also serve on Seattle's Community Technology Advisory Board, advising the Mayor and City Council on digital equity, privacy, and municipal cybersecurity policy.

Outside of work: published author, currently learning Mandarin, and increasingly interested in knowledge and intelligence as subjects in themselves.

Education

MS Computer Science, University of Alabama

BS Computer Science, University of Alabama