Senior DevOps Engineer | Cloud Engineer | Platform Engineer
Kubernetes · GCP · AWS · Azure · DevSecOps
I build secure, scalable, observable and automated cloud platforms.
Senior DevOps / Platform Engineer with 4.5+ years of hands-on production ownership of cloud-native infrastructure. GCP is my primary platform, with additional production experience on AWS and Azure.
I design and operate the layers between application code and the cloud: multi-cluster Kubernetes (GKE, EKS, AKS), Istio and Managed Cloud Service Mesh, global HTTP(S) load balancing with Cloud Armor / WAF at the edge, and the CI/CD and infrastructure-as-code that make all of it reproducible and reviewable.
Areas of focus:
| Area | What I do |
|---|---|
| Cloud infrastructure | Landing zones, VPC design, private connectivity, IAM boundaries, managed data services on GCP, AWS and Azure |
| Kubernetes platforms | Cluster lifecycle, node pool strategy, autoscaling, hardened workloads, network policies, multi-cluster migrations |
| Infrastructure as Code | Terraform modules with environment separation and remote state; Ansible for configuration management |
| CI/CD automation | GitHub Actions and Jenkins pipelines with build, test, scan, approval and rollback stages |
| DevSecOps | SonarCloud and Trivy as blocking gates, hardened multi-stage images, governed base images in Artifact Registry |
| Cloud security | Cloud Armor / WAF rule design, least-privilege IAM, network segmentation, encryption, audit logging, PCI DSS-aligned baselines |
| Observability | Prometheus, Grafana, ELK, Cloud Monitoring; SLO-backed dashboards and actionable alerting |
| Production reliability | Incident response, root-cause analysis across Kubernetes, networking, DNS, TLS and databases; runbooks and change management |
| Cost optimization | Rightsizing node pools, sidecars and Redis capacity; autoscaling tuning; consolidation and legacy decommissioning |
| Category | Technologies |
|---|---|
| Cloud | Google Cloud Platform (primary), AWS, Microsoft Azure |
| Containers | Docker, Kubernetes, GKE, EKS, AKS, Anthos, Cloud Run, Helm, Kustomize |
| Service Mesh | Istio, Managed Cloud Service Mesh, Envoy, mTLS, traffic splitting, circuit breaking |
| Infrastructure as Code | Terraform, Ansible |
| CI/CD | GitHub Actions, Jenkins, GitLab CI, Azure DevOps, Cloud Build, GitOps workflows |
| Security | Cloud Armor, WAF, DDoS mitigation, Trivy, SonarCloud, IAM hardening, VPC Service Controls, Secret Manager, PCI DSS baselines, DevSecOps |
| Observability | Prometheus, Grafana, Alertmanager, ELK Stack, Nagios, Cloud Monitoring, Cloud Logging, distributed tracing, SLOs |
| Databases & Data | Cloud SQL / MySQL, PostgreSQL, MongoDB, BigQuery, Redis Enterprise, Memorystore, RabbitMQ, Pub/Sub |
| Data Engineering | Datastream (CDC), Airbyte, Data Fusion, Dataflow, Cloud Functions, Cloud Storage |
| Networking | Global HTTP(S) Load Balancer, NEGs, URL Maps, Internal/External LB, Cloud CDN, Cloud DNS, Cloud NAT, Cloud VPN, Serverless VPC, Nginx, Envoy, SSL/TLS |
| Languages & OS | Python, Bash, Groovy, YAML, Linux (RHEL, Ubuntu) |
Each repository is a personal reference implementation of a pattern I use professionally. They are built and documented to production standards, but they are demonstration architectures, not the production code of any employer.
| Repository | Domain | What it demonstrates |
|---|---|---|
| terraform-gcp-platform | Cloud Architecture / IaC | Modular Terraform landing zone: VPC, private GKE, Artifact Registry, Cloud SQL, GCS, Global HTTPS LB, Cloud Armor, WIF for CI, remote state, dev / uat / prod separation |
| kubernetes-production-platform | Kubernetes | Hardened workload baseline: probes, requests/limits, HPA, PDB, Pod Security Admission, NetworkPolicies, RBAC, Kustomize overlays and a Helm chart |
| github-actions-devsecops | CI/CD / DevSecOps | Tests, SonarCloud, Trivy, distroless multi-stage image, OIDC push to Artifact Registry, gated UAT and production GKE deploys, rollback workflow |
| gke-istio-platform | Service Mesh | Istio / Managed Cloud Service Mesh behind a Global LB with NEGs, strict mTLS, AuthorizationPolicy, canary and blue/green routing, egress control |
| gcp-cloud-armor-security | Edge Security | Cloud Armor / WAF policies as code: OWASP preconfigured rules, rate limiting, IP and geo controls, rule optimization within policy limits, security logging |
| kubernetes-observability-stack | Observability / SRE | kube-prometheus-stack, SLO recording rules with multi-window burn-rate alerts, Grafana dashboards, ELK log pipeline, alert runbooks |
| devsecops-vulnerability-platform | Vulnerability Management | Trivy image / fs / IaC scanning, CVE classification and policy gates, SBOM and cosign signing, aggregated dashboard from synthetic data, remediation workflow |
| cloud-cost-optimization | FinOps | Billing-export SQL, idle resource detectors, Kubernetes rightsizing from Prometheus data, BigQuery and storage optimization, Redis capacity planning, safe cleanup automation |
| cloud-data-platform | Data Platform | MySQL and MongoDB to BigQuery via Datastream CDC and Airbyte, GCS landing, dedupe and SCD2 SQL, reconciliation tooling, backfill and cutover runbook |
Reading order for a quick review: terraform-gcp-platform for how I structure infrastructure, github-actions-devsecops for how I ship, gke-istio-platform and gcp-cloud-armor-security for how I handle traffic and security, and kubernetes-observability-stack for how I keep it running.
Senior DevOps Engineer — CheQ, Bangalore (Feb 2025 – Present)
Architected and own the production GCP platform spanning multi-cluster GKE, Cloud Run, Cloud SQL, BigQuery, Memorystore, VPC and Artifact Registry for PCI, lending and core application workloads serving 500K+ users. Led cross-cluster workload migrations with zero data loss and no customer-facing downtime, designed the Global HTTP(S) Load Balancer topology using NEGs and URL maps, operate Istio / Managed Cloud Service Mesh in production, own Cloud Armor / WAF policy design and DDoS mitigation, and run the GitHub Actions and Jenkins DevSecOps pipelines with SonarCloud and Trivy as blocking gates. Administer Cloud SQL / MySQL and Redis Enterprise HA, maintain a PCI DSS-compliant security baseline, and act as technical lead for reliability, observability, security and compliance initiatives.
DevOps Engineer — MoreYeahs IT Technologies, Indore (Oct 2020 – Jan 2025)
Built fintech cloud infrastructure from scratch on GCP with a multi-cluster GKE, multi-project topology, and operated GCP and Azure estates for fintech, healthcare, e-commerce and B2B SaaS workloads. Managed production GKE, AKS and EKS clusters with Anthos and Istio (mTLS, canary and blue/green releases), consolidated fragmented Azure DevOps pipelines into a unified multi-tenant delivery pipeline, and built CI/CD with GitHub Actions, Jenkins and Cloud Build. Orchestrated TB-scale MySQL and MongoDB to BigQuery migration and CDC synchronization using Datastream, Data Fusion, Dataflow, Airbyte and Cloud Storage, and implemented observability with Prometheus, Grafana, ELK and Nagios. Grew the cloud engineering team from 2 to 15 engineers, led a DevOps squad of 3, and introduced organization-wide standards for pipelines, IaC, branching and change management.
- Google Cloud Certified — Professional Cloud Architect
- Google Cloud Certified — Professional Cloud Security Engineer
- Microsoft Certified — Azure Administrator Associate (AZ-104)
- Microsoft Certified — Azure Fundamentals (AZ-900)
- Master of Computer Applications (MCA) — Rajiv Gandhi Proudyogiki Vishwavidyalaya, Indore (2019 – 2021)
- Bachelor of Computer Applications (BCA) — Devi Ahilya Vishwavidyalaya, Indore (2015 – 2018)
- Infrastructure is code. Every environment is reproducible from a versioned, peer-reviewed repository. No console changes in production.
- Secure by default. Least-privilege IAM, private networking, encryption in transit and at rest, and security scanning as a blocking gate rather than a report.
- Observability before scale. SLOs, dashboards and actionable alerts ship with the service, not after the first incident.
- Rollback is a feature. Every deployment path has a tested, documented way back.
- Cost is an engineering metric. Rightsizing, autoscaling and consolidation are part of platform ownership.
Professional experience above reflects my actual career. Repositories are personal reference implementations and labs; none contain employer code, credentials or infrastructure details.