Summary
Senior DevOps / Cloud Platform Engineer with 15+ years in infrastructure — from carrier networks and BGP to building multi-account AWS landing zones and production platforms on AWS, GCP and Kubernetes. Everything as code with Terraform and Helm, delivered through GitOps (Argo CD) and GitHub Actions, secured with a shift-left DevSecOps toolchain and operated with SRE practices (SLOs, on-call, postmortems). Strong in hybrid networking, FinOps and platform engineering that gives developers self-service, paved-road infrastructure. AWS Solutions Architect, CKA, CKAD and Google Cloud certified.
Certifications
Core skills
- AWS
- Organizations, Control Tower, SCPs, IAM Identity Center · EKS (Karpenter), ECS, ECR, EC2/Spot, Lambda, Step Functions, EventBridge, SQS, SNS · VPC, Transit Gateway, Direct Connect, Route 53, CloudFront, WAF, ALB/NLB · RDS/Aurora, DynamoDB, DocumentDB, ElastiCache, S3 · KMS, Secrets Manager
- AWS security
- GuardDuty, Security Hub, CloudTrail, AWS Config, Inspector, least-privilege IAM
- Google Cloud
- GKE (Standard / Autopilot), Cloud Run, Compute Engine · VPC, Shared VPC, Cloud Interconnect, HA VPN, Cloud NAT, Cloud Load Balancing, Cloud Armor · IAM, Workload Identity · Cloud SQL, Pub/Sub, Cloud Storage, BigQuery · Artifact Registry, Cloud Build · Secret Manager, Cloud KMS
- Kubernetes
- EKS, GKE, on-prem clusters, Helm, Istio, Argo CD / GitOps, Karpenter, Docker; Azure (AKS basics)
- IaC & CI/CD
- Terraform, Terragrunt, GitHub Actions, GitLab CI/CD, Jenkins, Cloud Build
- DevSecOps
- Trivy, Checkov, tfsec, OPA Gatekeeper, Kyverno, SBOM, Sigstore cosign, Renovate, HashiCorp Vault
- SRE & platform
- SLOs/SLIs, incident response, on-call, blameless postmortems, runbooks · Backstage, golden paths, self-service infrastructure
- Observability
- OpenTelemetry, Prometheus, Alertmanager, Grafana, Loki, OpenSearch, Dynatrace, Datadog, CloudWatch, Cloud Monitoring
- FinOps & DR
- Cost Explorer, Savings Plans, Reserved Instances, Compute Optimizer, Spot · AWS Backup, RTO/RPO, multi-AZ, multi-region
- Compliance
- ISO 27001, SOC 2 and GDPR-aligned environments
- Networking
- BGP, OSPF, PIM, VLAN, VPN, DNS/DHCP; Cisco, Juniper, Huawei, MikroTik
- AI engineering
- AI agents, MCP servers, LLM-assisted DevOps automation
- Systems & code
- Linux (expert), Bash, Go, Proxmox, PostgreSQL, Snowflake
Experience
Founder & Principal Cloud / DevOps Consultant · TomalaIT
Dec 2013 – PresentIndependent consultancy — cloud architecture, platform engineering and networking for SMB and fintech clients.
- Built a multi-account AWS landing zone from scratch — Organizations, Control Tower, SCP guardrails, IAM Identity Center (SSO) and a centralised security baseline with GuardDuty, Security Hub, CloudTrail, Config and Inspector.
- Operate EKS with Karpenter (Spot-first) and ECS platforms; run FinOps with Savings Plans, Reserved Instances, Compute Optimizer and Cost Explorer.
- Delivered GCP platforms on GKE (Standard/Autopilot) and Cloud Run with Shared VPC, Cloud Armor, Workload Identity, Cloud SQL and Pub/Sub.
- Designed hybrid networking across AWS, GCP and on-prem — Direct Connect, Transit Gateway, Cloud Interconnect, HA VPN — with secure data exchange between environments.
- Engineered resilience: DR with defined RTO/RPO, multi-AZ / multi-region architectures and AWS Backup policies.
- Built event-driven serverless workloads with Lambda, EventBridge, SQS/SNS and Step Functions.
- Implemented observability with OpenTelemetry, Prometheus, Alertmanager, Grafana and Loki; shipped EKS and AWS logs to an on-prem OpenSearch cluster.
- Introduced SRE practices — SLOs/SLIs, on-call, incident response, blameless postmortems and runbooks.
- Shifted security left: Trivy, Checkov/tfsec, OPA Gatekeeper/Kyverno, SBOM and cosign image signing; Renovate for automated vulnerability patching.
- Work with AI agents and MCP (Model Context Protocol) servers — integrating LLM-driven automation with cloud, Kubernetes and CI/CD tooling.
- Platform engineering with Backstage — golden paths and self-service infrastructure; CI/CD with GitHub Actions, GitLab CI and Jenkins, secrets in Vault.
- Manage RDS/Aurora, DynamoDB and Cloud SQL — provisioning, backups, performance and upgrades; delivered in ISO 27001 / SOC 2 / GDPR-aligned environments.
- Re-platformed a cryptocurrency exchange from EKS to on-prem Kubernetes, significantly reducing infrastructure spend.
- Delivered an IoT sensor-event pipeline on AWS feeding Snowflake and Sigma BI; built HA Proxmox private clouds and WireGuard access layers.
DevOps Engineer · Softkraft
Nov 2021 – Mar 2022- Provisioned dev / stage / prod AWS environments with Terraform + Terragrunt.
- Designed a bastion-host security model isolating all private infrastructure.
- Implemented CI/CD from GitHub to ECR and ECS with automatic task-definition rollout after each build.
stack: AWS ECS · ECR · Terraform · Terragrunt · Ansible · Prometheus · Grafana · Linux
DevOps Engineer · Webanywhere
Dec 2020 – Aug 2021- Migrated workloads to AWS and codified infrastructure in Terraform.
- Implemented monitoring with Zabbix and Grafana; supported developers on infrastructure issues.
Systems & Network Administrator · Polish Mining Group
Dec 2018 – Dec 2020- Redesigned the corporate network with OSPF and VLAN segmentation (Cisco, Juniper, MikroTik).
- Modernised DHCP, DNS and NFS services and planned network capacity growth.
Network Engineer · Orange Poland
Apr 2011 – Dec 2013- Provisioned, configured and maintained DSL / ADSL broadband services in a national carrier network.
- Diagnosed and resolved access-network and connectivity faults, working with field and NOC teams.
- Supported day-to-day operation of access and aggregation network infrastructure.
Network Administrator · Tech-LAN
Jan 2009 – Dec 2013- Designed, built and managed WLAN and LAN networks — from planning and hardware installation to day-to-day operation.
- Administered Linux network services: DHCP, DNS and FTP servers.
Education
- Silesian University of Technology, Gliwice, Poland
- Electronics and Telecommunications · 2016 – 2020
Languages & work
- English — professional working proficiency
- Polish — native
- Work: remote · B2B / contractor or full-time · EU work rights
I hereby consent to the processing of my personal data included in this document for the purposes of the recruitment process, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).