← tomalait.com PDF · Letter PDF · Letter (photo) PDF · A4 PDF · EU (photo)

Open to remote roles · US · Canada · EU · B2B or full-time

Arkadiusz Tomala

Senior DevOps Engineer · Cloud Platform Engineer · AWS · Kubernetes · GCP · Terraform

Arkadiusz Tomala

Summary

Senior DevOps / Cloud Platform Engineer with 15+ years in infrastructure — from carrier networks and BGP to building multi-account AWS landing zones and production platforms on AWS, GCP and Kubernetes. Everything as code with Terraform and Helm, delivered through GitOps (Argo CD) and GitHub Actions, secured with a shift-left DevSecOps toolchain and operated with SRE practices (SLOs, on-call, postmortems). Strong in hybrid networking, FinOps and platform engineering that gives developers self-service, paved-road infrastructure. AWS Solutions Architect, CKA, CKAD and Google Cloud certified.

Certifications

AWS Certified Solutions Architect – AssociateAmazon Web Services
Certified Kubernetes Administrator (CKA)CNCF / Linux Foundation
Certified Kubernetes Application Developer (CKAD)CNCF / Linux Foundation
Google Cloud CertifiedGoogle Cloud

Core skills

AWS
Organizations, Control Tower, SCPs, IAM Identity Center · EKS (Karpenter), ECS, ECR, EC2/Spot, Lambda, Step Functions, EventBridge, SQS, SNS · VPC, Transit Gateway, Direct Connect, Route 53, CloudFront, WAF, ALB/NLB · RDS/Aurora, DynamoDB, DocumentDB, ElastiCache, S3 · KMS, Secrets Manager
AWS security
GuardDuty, Security Hub, CloudTrail, AWS Config, Inspector, least-privilege IAM
Google Cloud
GKE (Standard / Autopilot), Cloud Run, Compute Engine · VPC, Shared VPC, Cloud Interconnect, HA VPN, Cloud NAT, Cloud Load Balancing, Cloud Armor · IAM, Workload Identity · Cloud SQL, Pub/Sub, Cloud Storage, BigQuery · Artifact Registry, Cloud Build · Secret Manager, Cloud KMS
Kubernetes
EKS, GKE, on-prem clusters, Helm, Istio, Argo CD / GitOps, Karpenter, Docker; Azure (AKS basics)
IaC & CI/CD
Terraform, Terragrunt, GitHub Actions, GitLab CI/CD, Jenkins, Cloud Build
DevSecOps
Trivy, Checkov, tfsec, OPA Gatekeeper, Kyverno, SBOM, Sigstore cosign, Renovate, HashiCorp Vault
SRE & platform
SLOs/SLIs, incident response, on-call, blameless postmortems, runbooks · Backstage, golden paths, self-service infrastructure
Observability
OpenTelemetry, Prometheus, Alertmanager, Grafana, Loki, OpenSearch, Dynatrace, Datadog, CloudWatch, Cloud Monitoring
FinOps & DR
Cost Explorer, Savings Plans, Reserved Instances, Compute Optimizer, Spot · AWS Backup, RTO/RPO, multi-AZ, multi-region
Compliance
ISO 27001, SOC 2 and GDPR-aligned environments
Networking
BGP, OSPF, PIM, VLAN, VPN, DNS/DHCP; Cisco, Juniper, Huawei, MikroTik
AI engineering
AI agents, MCP servers, LLM-assisted DevOps automation
Systems & code
Linux (expert), Bash, Go, Proxmox, PostgreSQL, Snowflake

Experience

Founder & Principal Cloud / DevOps Consultant · TomalaIT

Dec 2013 – Present

Independent consultancy — cloud architecture, platform engineering and networking for SMB and fintech clients.

  • Built a multi-account AWS landing zone from scratch — Organizations, Control Tower, SCP guardrails, IAM Identity Center (SSO) and a centralised security baseline with GuardDuty, Security Hub, CloudTrail, Config and Inspector.
  • Operate EKS with Karpenter (Spot-first) and ECS platforms; run FinOps with Savings Plans, Reserved Instances, Compute Optimizer and Cost Explorer.
  • Delivered GCP platforms on GKE (Standard/Autopilot) and Cloud Run with Shared VPC, Cloud Armor, Workload Identity, Cloud SQL and Pub/Sub.
  • Designed hybrid networking across AWS, GCP and on-prem — Direct Connect, Transit Gateway, Cloud Interconnect, HA VPN — with secure data exchange between environments.
  • Engineered resilience: DR with defined RTO/RPO, multi-AZ / multi-region architectures and AWS Backup policies.
  • Built event-driven serverless workloads with Lambda, EventBridge, SQS/SNS and Step Functions.
  • Implemented observability with OpenTelemetry, Prometheus, Alertmanager, Grafana and Loki; shipped EKS and AWS logs to an on-prem OpenSearch cluster.
  • Introduced SRE practices — SLOs/SLIs, on-call, incident response, blameless postmortems and runbooks.
  • Shifted security left: Trivy, Checkov/tfsec, OPA Gatekeeper/Kyverno, SBOM and cosign image signing; Renovate for automated vulnerability patching.
  • Work with AI agents and MCP (Model Context Protocol) servers — integrating LLM-driven automation with cloud, Kubernetes and CI/CD tooling.
  • Platform engineering with Backstage — golden paths and self-service infrastructure; CI/CD with GitHub Actions, GitLab CI and Jenkins, secrets in Vault.
  • Manage RDS/Aurora, DynamoDB and Cloud SQL — provisioning, backups, performance and upgrades; delivered in ISO 27001 / SOC 2 / GDPR-aligned environments.
  • Re-platformed a cryptocurrency exchange from EKS to on-prem Kubernetes, significantly reducing infrastructure spend.
  • Delivered an IoT sensor-event pipeline on AWS feeding Snowflake and Sigma BI; built HA Proxmox private clouds and WireGuard access layers.

DevOps Engineer · Softkraft

Nov 2021 – Mar 2022
  • Provisioned dev / stage / prod AWS environments with Terraform + Terragrunt.
  • Designed a bastion-host security model isolating all private infrastructure.
  • Implemented CI/CD from GitHub to ECR and ECS with automatic task-definition rollout after each build.

stack: AWS ECS · ECR · Terraform · Terragrunt · Ansible · Prometheus · Grafana · Linux

DevOps Engineer · Webanywhere

Dec 2020 – Aug 2021
  • Migrated workloads to AWS and codified infrastructure in Terraform.
  • Implemented monitoring with Zabbix and Grafana; supported developers on infrastructure issues.

Systems & Network Administrator · Polish Mining Group

Dec 2018 – Dec 2020
  • Redesigned the corporate network with OSPF and VLAN segmentation (Cisco, Juniper, MikroTik).
  • Modernised DHCP, DNS and NFS services and planned network capacity growth.

Network Engineer · Orange Poland

Apr 2011 – Dec 2013
  • Provisioned, configured and maintained DSL / ADSL broadband services in a national carrier network.
  • Diagnosed and resolved access-network and connectivity faults, working with field and NOC teams.
  • Supported day-to-day operation of access and aggregation network infrastructure.

Network Administrator · Tech-LAN

Jan 2009 – Dec 2013
  • Designed, built and managed WLAN and LAN networks — from planning and hardware installation to day-to-day operation.
  • Administered Linux network services: DHCP, DNS and FTP servers.

Education

  • Silesian University of Technology, Gliwice, Poland
  • Electronics and Telecommunications · 2016 – 2020

Languages & work

  • English — professional working proficiency
  • Polish — native
  • Work: remote · B2B / contractor or full-time · EU work rights

I hereby consent to the processing of my personal data included in this document for the purposes of the recruitment process, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).