AWS Migrations and Security
Modernization Week
View Migrations sessions on demand »Migrate with Confidence to a Secure Cloud
Join AWS experts for a deep-dive learning series designed to take your organization's transformation journey to the next level.
Who should attend?
Security Engineer (SecOps Engineer), Security Architect (IT Security Architect; IT Enterprise Architect; Information Security Architect), CISOs, Heads of/Directors of IT Security, Heads of SecOps, Heads of Security Architecture, Security Directors, IT Risk & Compliance Managers, Directors of GRC, Data Protection Officers, Heads of Identity Management, or anyone interested in or responsible for implementing IT security, identity or compliance/risk strategy.
CIOs, CTOs, VP/Director of IT, VP/Director of Engineering, VP/Director of Infrastructure, Cloud Architect, Solutions Architect, DevOps Engineer or anyone interested in or responsible for migrating and modernizing their existing workloads to the cloud.
Agenda
Click on a Track to view session details.
Monday, April 4
Migrations Track
Day 1 Theme: Microsoft Windows
Session 1: Breaking the Monolith
Level 300
9:00am - 10:00am PT | 12:00pm - 1:00pm ET
Speaker: Stefan Minhas, DA App Modernization Lab - AWS
Large organizations have a tremendous amount of resources invested in existing monolith applications. AWS customers are always looking for a successful way to move to microservices without having to completely rewrite the monolith and build-in a successful approach. AWS offers familiarity and a microservices proving ground. In this session, we will learn how to identify possible failure modes to ensure a successful start to your modernization journey. We then look at ways to ring-fence ideal starting points in your application suitable for breaking as a microservice. Then we will demonstrate the application of the ‘Strangler Fig’ pattern and how it can be leveraged using AWS services.
Session 2: Modernizing Microsoft SQL Server on AWS
Level 300
10:00am - 11:00am PT | 1:00pm - 2:00pm ET
Speaker: Runeet Vashisht, Sr. Solutions Architect, Microsoft Platform on AWS - AWS
Database modernization is the cloud-based approach to modernizing and cost-optimizing Microsoft SQL Server on AWS. In this session you will learn about the benefits of database modernizing and how to get started. We will cover topics such as RDS SQL Server, deploying Microsoft SQL Server on Linux, migrate from Microsoft SQL Server to Amazon Aurora. We will see with Babelfish, Aurora PostgreSQL now understands T-SQL so that your apps that were originally written for SQL Server can work with Aurora with fewer code changes.
Security Track
Day 1 Theme: Threat Detection & Incident Response
Session 1: Demonstration of threat detection operationalization best practices
Level 300
8:00am - 9:00am PT | 11:00am - 12:00pm ET
Speaker:
Himanshu Verma, Principal Security Specialist - AWS
To start the threat detection and incident response training day, this session will review foundational security services for proactive and early detection of security events through demonstrations that show how real-world vulnerabilities and unauthorized behavior are identified, prioritized, and operationalized for fast remediation. Services will be deployed and built upon to create layers of defense include Amazon Macie, Amazon Inspector, Amazon GuardDuty with root cause analysis with Amazon Detective, and centralized cloud security posture assessment with AWS Security Hub.
Session 2: New AWS security services for container threat detection
Level 300
9:00am - 10:00am PT | 12:00pm - 1:00pm ET
Speaker:
Scott Ward - Principal Solutions Architect, AWS
Containers are becoming a cornerstone of many AWS customers' application modernization strategy. With the increased adoption of containers customers also need a way to operationalize and scale threat detection that is specific to their container workloads. To help meet the container security and visibility needs of security and devops teams , new container specific security capabilities have recently been added to Amazon GuardDuty and Amazon Inspector. In this session we will review these new threat detection capabilities, deployment best practices for each service, and how to best operationalize these services for your container workloads running in AWS.
Session 3: Confronting Ransomware: Six Habits of Highly Effective Threat Detection/Incident Response Teams
Level 300
10:00am - 11:00am PT | 1:00pm - 2:00pm ET
Speakers:
Merritt Baer - Principal, Office of the CISO, AWS
Megan O'Neil - Sr. Security Solutions Architect, AWS
Ransomware continues to be a common attack across industries and geographies. In this session, we will highlight ways that you can take advantage of cloud-scale security as you do detection and incident response for threats including ransomware. This session will cover some AWS security services like Amazon GuardDuty and Amazon Detective, and will describe how to leverage infrastructure-as-code to do security as code, leveraging services like AWS CloudTrail, AWS Lambda, and AWS Config. It will highlight some cloud-y capabilities like provable security, and the ability to leverage immutable and ephemeral infrastructure. Finally, we will feature some “lessons learned” from AWS Security as we protect, detect, and remediate threats.
Tuesday, April 5
Migrations Track
Day 2 Theme: SAP
Session 1: Cost Savings Blueprint: How Customers Achieved 103% ROI by Migrating SAP Workloads to AWS
Level 300
8:00am - 9:00am PT | 11:00am - 12:00pm ET
Speaker: Brian Griffin, SAP Practice CTO - AWS
In this session, we will review findings from Forrester Consulting’s Total Economic Impact™ study that shows how actual customers have saved millions while driving new levels of efficiency and innovation by migrating SAP to AWS. The webinar will also provide free resources to help you build a data-driven business case for migrating SAP to AWS so you can realize similar benefits in your organization.
Session 2: Migrate an SAP ERP system to AWS with minimal downtime
Level 300
9:00am - 10:00am PT | 12:00pm - 1:00pm ET
Speakers:
Milind Pathak, Sr. US-West SAP Specialist SA - AWS
Sunil Yadav, SAP Principal Consultant - AWS
In this workshop, learn how to automate lift-and-shift migrations of SAP ERP Central Component (ECC) and SAP S/4HANA using AWS Application Migration Service (AWS MGN). Start by converting source servers to AWS automatically and without time-intensive, error-prone manual processes. Then, perform a series of nondisruptive tests to ensure ERP systems will continue to function seamlessly. Finally, execute the cutover and perform final validation.
Session 3: Marc O’Polo’s journey to direct-to-consumer operations and SAP S/4HANA
Level 300
10:00am - 11:00am PT | 1:00pm - 2:00pm ET
Speakers:
Pavol Masarovic, Sr. DACH SAP Specialist SA - AWS
Steffen Sandner, Director, Digital Intelligence - Marc O'Polo
Marc O´Polo has the ambitious goals to be the most innovative fashion retailer in Germany and to shift to a direct-to-consumer model. To support these changes, Marc O´Polo decided to move from three legacy ERP systems to a unified to SAP S/4HANA implementation on AWS. They are also building a data lake, which will allow them to combine SAP data with other key data sources to greater insight into their customers and operations using AWS services. In this session, we will look at Marc O’Polo’s S/4HANA implementation and lessons learned that other SAP customers can use to support their own journey to a data-driven enterprise.
Security Track
Day 2 Theme: Data Protection
Session 1: Demystifying PKI and certificates on AWS
Level 300
8:00am - 9:00am PT | 11:00am - 12:00pm ET
Speaker:
Chandan Kundapur - Sr. Technical Product Manager, AWS
This session is for developers, public key infrastructure (PKI) administrators, and IT professionals who deploy, manage, and issue public and private certificates on AWS. This session covers AWS services and capabilities for managing and deploying public certificates, private certificates, and certificate authorities on AWS. Learn about common use cases for enabling encryption in transit, including mutual TLS, containers, service meshes, Amazon API Gateway, Elastic Load Balancing, Amazon CloudFront, and Amazon Managed Streaming for Apache Kafka (Amazon MSK).
Session 2: Secrets management best practices
Level 300
9:00am - 10:00am PT | 12:00pm - 1:00pm ET
Speakers:
Avni Rambhia - Senior Technical Product Manager, AWS
Managing and using secrets at scale is a common challenge as you modernize applications – whether you’re creating individual client applications, large-scale multi-tenant SaaS and PaaS offerings, or adapting internal applications for zero-trust architectures. AWS Secrets Manager enables you to manage secrets over their entire lifecycle, and to reliably and securely consume these secrets. In this talk, you’ll learn how advanced users make the most of Secrets Manager features including fine-grained access control, automatic secret rotation, cross-region replication, and centralized monitoring. You’ll also learn techniques to easily and efficiently consume secrets in your applications, while optimizing costs.
Session 3: Best practices for protecting data using encryption
Level 300
10:00am - 11:00am PT | 1:00pm - 2:00pm ET
Speaker:
Jeremy Stieglitz - Principal Product Manager, AWS
Today, AWS offers over 100 services that can encrypt your data or sign/verify data with cryptographic protection. This overview session highlights common AWS KMS encryption and digital signature patterns. It also reviews some recently launched features (e.g., ABAC, Amazon S3 Bucket Keys, and multi-region keys) and improvements to AWS crypto tools (e.g., the AWS Encryption SDK, the Amazon DynamoDB Encryption Client, and the Amazon S3 encryption clients).
Wednesday, April 6
Migrations Track
Day 3 Theme: VMware
Session 1: Migration and Modernization at Scale with VMware Cloud on AWS
Level 200
8:00am - 9:00am PT | 11:00am - 12:00pm ET
Speakers:
Aarthi Raju - Sr. Manager, VMware Solutions Architecture, AWS
Samir Kadoo - VMware AMER SA Lead, AWS
Whether you’re just starting out on your hybrid cloud journey or you’re well established, there’s always something new to explore. For the past 5 years, VMware and AWS have been jointly engineering solutions to support our customers’ evolving hybrid cloud needs. In this session, we’ll focus on best practices for moving your on-premises VMware workloads to AWS with VMware Cloud on AWS. Next, we’ll share options for modernizing these workloads with AWS services. Lastly, we’ll dive into our newest joint offering, VMware Cloud on AWS Outposts, which is designed to support your applications with latency and local data processing requirements
Session 2: Modernizing VMware Cloud on AWS workloads with native AWS services
Level 300
9:00am - 10:00am PT | 12:00pm - 1:00pm ET
Speakers:
Harsha Sanku - Sr. Partner Solutions Architect, AWS
Karthik Varadaraj - Partner Solutions Architect, AWS
Organizations today are looking for ways to extend their on-premises data center to the cloud without having to re-platform or refactor their applications. By leveraging native AWS services, organizations can enhance your security and network performance and reduce your TCO by optimizing storage. In this session we'll focus on integrating VMware Cloud on AWS with Amazon EFS, Amazon FSx, and Amazon S3 to offload storage-heavy workloads. Also we will demonstrate how workloads residing on VMware Cloud on AWS can leverage an AWS Elastic Load Balancer to distribute workloads, AWS WAF to enhance security, and Amazon CloudFront to reduce latency.
Session 3: Building Your Connectivity to Enable Hybrid Cloud with VMware Cloud on AWS
Level 300
10:00am - 11:00am PT | 1:00pm - 2:00pm ET
Speakers:
Paul Cradduck - Sr. Specialist Solutions Architect VMware, AWS
Ric Vazquez - Specialist Solutions Architect VMware, AWS
VMware Cloud on AWS enables our workloads to be mobile. In this hybrid approach we are able to have workload mobility such that we have the freedom to enable functionality on-prem or in VMware Cloud on AWS. This empowers our businesses to scale, modernize or survive disasters. No matter what our use case we need to ensure workload availability. In this session we will learn how to build the connectivity between our workloads running in VMware Cloud on AWS and the people who rely on them. We will explore how we build connectivity for reliability, scale and flexibility.
Security Track
Day 3 Theme: Identity & Access Management
Session 1: Practical guidance to get to least privilege IAM at scale
Level 300
8:00am - 9:00am PT | 11:00am - 12:00pm ET
Speakers:
Cassia Martin - Sr. Technical Product Manager, AWS
Liam Wadman - Sr. Technical Product Manager, AWS
In this talk, we’re going to share a mental model for how to get to least privilege in your AWS environment. We’ll talk about the foundations and security controls that you can implement on your first day in AWS, and then we’ll share techniques for continuously updating access across your environments over time. You’ll learn about creating logical isolation boundaries for your data and applications using AWS accounts, applying guardrails to allow your developers to experiment and innovate safely using identity and access management policies, and right-sizing access permissions using AWS IAM Access Analyzer.
Session 2: Explore, organize, and manage access to your AWS resources
Level 300
9:00am - 10:00am PT | 12:00pm - 1:00pm ET
Speaker:
Fabian Labat - Sr. Solutions Architect, AWS
In this session, learn how AWS is helping enterprises effectively manage their cloud resources. Also, learn how you can use tools like Tag Editor to search for resources and Tag Policy to define rules on how tags can be used. Understand how you can use AWS Resource Groups to organize your resources into logical collections, generate reports, and perform bulk actions. Finally, learn how to use AWS Resource Access Manager to securely share resources with other AWS accounts or within your AWS organization.
Session 3: Managing identities and access across AWS accounts
Level 300
10:00am - 11:00am PT | 1:00pm - 2:00pm ET
Speakers:
Samuel Folkes - Sr. Solutions Architect, SMB, AWS
Chris Mercer - Security Solutions Architect, Identity, AWS
AWS customers from many industries have been adopting AWS SSO to improve their security posture and unblock productivity by providing a central pane of glass for users’ assigned accounts and applications, both in AWS Management Console and AWS CLI. In this session, explore some common patterns that existing customers have used to successfully migrate their existing AWS access solutions to AWS SSO with no interruption to users.
Thursday, April 7
Security Track
Day 4 Theme: Privacy & Compliance
Session 1: Streamline Compliance Reporting with Audit Manager
Level 300
8:00am - 9:00am PT | 11:00am - 12:00pm ET
Speaker:
Kajal Deepak - GM, AWS Audit Manager, AWS
In a rapidly shifting regulatory environment, compliance audits can be a moving target, demanding a heavy IT burden, and introducing technical complexity for the business. Streamline audits and enable continuous compliance with AWS Audit Manager, by offering self-service regulatory reporting and monitoring for Compliance business owners. Learn how Audit Manager’s detailed, pre-built reporting frameworks map 18 standards and regulatory requirements (PCI, HIPAA, SOC2, etc) to the relevant AWS data sources (eg- CloudTrail logs), reducing technical complexity and manual data usage collection, for simplified audit preparation, risk assessments, and ongoing issue monitoring.
Session 2: Designing for data privacy on AWS
Level 300-400
9:00am - 10:00am PT | 12:00pm - 1:00pm ET
Speakers:
Carl Mathis - Sr. Privacy Consultant, AWS
Daniel Nieters - Sr. Privacy Consultant, AWS
In this session, learn how AWS approaches privacy and to leverage AWS services for an architectural approach to enable privacy compliance requirements are met with speed and efficiency. Join us to learn how to build reusable privacy enhancing patterns into your AWS deployments. Quickly address data minization, data-centric design. and cross-border data flows. Also learn how to incorporate data quality and right to erasure into your architectural designs.
Session 3: Cloud compliance, assurance, and auditing
Level 300
10:00am - 11:00am PT | 1:00pm - 2:00pm ET
Speaker:
Andres Silva - Principal CloudOps Specalist Solutions Architect, AWS
Compliance is a key topic for our customers. How do they get started with compliance in the cloud? In this session, you will learn how to continuously assess, manage, and maintain compliance for formalized standards such as those required by Federal Risk and Authorization Management Program (FedRAMP), National Institute of Standards and Technology (NIST), and others. We will also learn about the various auditing options, including auditing privileged access across services like Amazon S3 and Amazon DynamoDB. We will dive deep into how you can achieve governance and compliance using preventative and detective guardrails and other AWS offerings.
Migrations sessions are not available on Thursday, April 7
Featured Speakers

Samir Kadoo
VMware AMER SA Lead
AWS
Samir Kadoo leads the Americas VMware Specialist Solutions Architecture team at Amazon Web Services (AWS). Samir and his team work closely with customers who are looking to utilize VMware Cloud on AWS along with integrations with native AWS services to help meet their business needs throughout their cloud migration journey.

Kajal Deepak
General Manager, AWS Audit Manager
AWS
Kajal Deepak is the General Manager for AWS Audit Manager service. She is responsible for service operations and feature roadmaps. She leads a team of engineers and product managers who are working on reimagining audit and compliance.

Aarthi Raju
Sr. Manager, Partner SA, VMware
AWS
Aarthi Raju leads the VMware Solutions Architecture team at AWS. Aarthi and her team provides technical architectural guidance to customers and partners to help them migrate and modernize applications in the cloud.

Merritt Baer
Principal, Office of the CISO
AWS
Merritt provides technical cloud security guidance to complex, regulated organizations, and advises the leadership of AWS’ customers on security as a bottom line proposition. She also helps build strategic initiatives for how AWS secures itself, running on AWS.

Paul Cradduck
Sr. Specialist SA, VMware
AWS
Paul Cradduck is focused on migrating VMware workloads to AWS. He has led clients towards optimal technology solutions for 15+ years. He has extensive experience with VMware vSphere datacenter strategy, design and implementation.

Chandan Kundapur
Sr. Technical Product Manager
AWS
Chandan is responsible for AWS Certificate Manager (ACM) and focuses on helping AWS customers identify and secure their resources and endpoints with public and private certificates. Chandan has over 15 years of experience in Cyber security and prior to joining AWS, Chandan led Enterprise endpoint and cloud workload protection products used to secure major enterprise and government organizations.
Session Proficiency Levels Explained
Level 200
Intermediate
Sessions are focused on providing best practices, details of service features, and demos with the assumption that attendees have introductory knowledge of the topics.
Level 300
Advanced
Sessions dive deeper into the selected topic. Presenters assume that the audience has some familiarity with the topic, but may or may not have direct experience implementing a similar solution.
Level 400
Expert
Sessions are for attendees who are deeply familiar with the topic, have implemented a solution on their own already, and are comfortable with how the technology works across multiple services, architectures, and implementations.