Christian Kappen
Senior AWS Cloud Engineer
Experience
Senior AWS Cloud Engineer
Sopra Financial Technology GmbH
- Setup and operation of a multi-cluster AWS EKS platform for banking workloads with a unified network and security architecture across 45 AWS accounts.
- Developed and standardized a unified AWS network and security architecture for 45 AWS accounts, enabling consistent governance, connectivity, and compliance for enterprise customer environments.
- Developed and operated a multi-cluster AWS EKS platform to support production workloads, significantly improving scalability, availability, and operational reliability.
- Implemented a GitOps deployment model using ArgoCD and Helm, enabling fully automated, auditable deployments and reducing manual release errors.
- Automated infrastructure provisioning using Terraform and Terragrunt at scale, reducing environment setup time by up to 70% and eliminating configuration drift.
- Established enterprise-grade backup and disaster recovery strategies using Velero and AWS Backup, ensuring reliable multi-cluster recovery and business continuity.
- Introduced Rancher as a self-service Kubernetes platform, accelerating developer onboarding while maintaining centralized security and governance.
- Designed and implemented detailed AWS IAM concepts (roles, policies, trust relationships) to enforce the principle of least privilege for access to accounts, workloads, and CI/CD pipelines.
- Developed AWS Lambda-based pre-provisioning workflows for databases, automating initialization, configuration, and access setup to support secure and consistent application integration.
- Delivered consistent, high-quality results as part of a 5-person AWS Solutions Architecture team, resulting in three consecutive contract renewals.
Lead Cloud Architect (AWS)
aconso AG
- Design and operate a secure, highly available AWS infrastructure with isolated customer environments for an enterprise HR platform.
- Design and deployment of a secure, highly available AWS-based cloud infrastructure for enterprise customers with isolated, customer-specific environments.
- Development and standardization of a centralized AWS network and security infrastructure for more than 10 AWS accounts to ensure consistent governance, reliable connectivity, and compliance across enterprise customer environments.
- Served as a technical coach and trainer to educate engineering teams on cloud architecture, security best practices, and operational excellence.
- Worked directly with senior management and the CTO to support enterprise customers, clearly explaining and defending advanced security architectures and implementation decisions.
- Defined and implemented enterprise-level security controls, including SIEM, encryption, and access logging, to meet strict customer and compliance requirements.
- Built and operated a containerized platform using AWS ECS with EC2 and Fargate, balancing cost efficiency, scalability, and operational flexibility.
- Led the migration from CloudFormation to Terraform with Terragrunt, significantly improving the scalability, reusability, and long-term maintainability of the infrastructure.
- Implemented blue-green deployment strategies via GitLab CI, enabling zero-downtime releases and more secure production deployments.
- Defined and enforced scalable AWS IAM and access management patterns, integrating role-based access control and cross-account permissions to securely manage users, services, and automation.
- Implemented serverless database pre-provisioning with AWS Lambda, enabling automated setup of schemas, users, and configuration parameters prior to application deployment.
- Improved application scalability and availability using AWS Load Balancers, ensuring consistent performance across varying workloads.
- Established comprehensive monitoring and observability with Datadog, enabling proactive incident detection and performance optimization.
- Delivered a highly reliable and secure platform that became a core component of the company's digital and enterprise offerings.
- Achieved four consecutive contract renewals, reflecting ongoing delivery quality and strong stakeholder confidence.
Lead Cloud Architect (AWS)
Cura4You GmbH
- Leading the end-to-end design and implementation of a secure cloud infrastructure from the ground up to support a healthcare platform that processes highly sensitive medical data.
- Design and implementation of a secure, segmented AWS network topology using networks, subnets, routing, and security controls to isolate environments, protect critical services, and meet regulatory requirements.
- Implementation of robust AWS IAM architectures with clear separation of duties, least privilege access, and service-to-service authentication for the secure operation of workloads processing sensitive healthcare data.
- Designed and operated multiple AWS ECS and AWS EKS clusters hosting a large-scale microservices architecture, ensuring scalability, reliability, and operational consistency.
- Standardized Docker-based development and runtime environments, aligning local, staging, and production environments to reduce integration issues and friction during deployment.
- Deployed a high-performance frontend architecture using Amazon CloudFront and S3, optimizing global content delivery, scalability, and user experience.
- Implemented blue-green deployment pipelines using GitHub Actions and integrated automated testing to enable zero-downtime releases and significantly improve application stability.
- designed and enforced advanced encryption strategies with AWS KMS, strengthening data protection beyond standard cloud-managed encryption.
- Established comprehensive monitoring and observability with Datadog, enabling proactive detection of issues across the entire application and infrastructure stack.
- Built and managed highly available data tiers using multiple AWS Aurora MySQL 8.0 clusters and AWS ElastiCache Redis clusters.
- Planned and automated the entire infrastructure lifecycle with Terraform and Terragrunt to ensure reproducibility, scalability, and compliance-ready environments.
- Ensured ongoing compliance with GDPR, BSI, PCI, and ISO 27001 by directly embedding security and regulatory requirements into infrastructure and deployment processes.
- Provided fully isolated development, staging, and local environments for developers and product managers, accelerating development speed and improving cross-team collaboration.
Lead Cloud Architect (AWS)
PlanA.Earth GmbH
- Led the migration of an organically grown AWS environment to a highly available, production-grade cloud architecture, significantly improving reliability, scalability, and operational stability.
- assumed full responsibility for stabilizing and modernizing the AWS infrastructure in a fast-growing start-up company (with over 40 million euros in funding) despite frequent team changes and limited previous infrastructure management experience.
- designed and enforced scalable AWS IAM structures with clearly defined roles, policies, and trust relationships, enabling secure access management across teams, services, and CI/CD workflows.
- refactored and standardized the AWS VPC foundation (network design, subnet segmentation, routing, and security controls) to improve isolation, availability, and operational robustness across all environments.
- implemented AWS Lambda-based automation for database provisioning and ETL pipelines to enable serverless initialization, data transformation, and integration workflows, supporting reliable and scalable data processing.
- designed and operated highly available data tiers using multiple AWS RDS MySQL 8.0 clusters and AWS ElastiCache Redis clusters, improving performance and data consistency.
- designed and implemented blue-green deployment pipelines using GitHub Actions, enabling zero-downtime releases and more secure production rollouts.
- built and supported local development environments and CI/CD pipelines, increasing developer productivity and reducing friction in deployment.
- played a key role in the company's ISO 27001 and SOC 2 certification initiatives, contributing to security controls, asset monitoring, and audit readiness.
- implemented continuous asset and compliance monitoring with Vanta, improving infrastructure security visibility.
- delivered a scalable container platform using AWS ECS with EC2 and Fargate, balancing cost efficiency, scalability, and ease of use.
- improved application availability and traffic management using AWS Load Balancers, ensuring consistent performance under load.
- strengthened data protection and security controls using AWS KMS, aligning the infrastructure with the company's security and compliance requirements.
- achieved four consecutive contract renewals, reflecting strong performance impact and stakeholder confidence.
Lead Cloud Architect (AWS)
Schuettflix GmbH
- Led a complete migration from DigitalOcean to AWS, significantly improving the scalability, reliability, and long-term robustness of the cloud infrastructure.
- Designed and implemented a robust AWS network architecture (network layout, subnet segmentation, routing, and security controls) that ensures secure connectivity, high availability, and a strong foundation for the migrated platform.
- Defined and enforced a structured AWS IAM model with role-based access, service identities, and cross-account trust for the secure operation of business-critical back-office workloads.
- Modernized the application platform by replacing an outdated Rancher configuration, stabilizing and optimizing web, front-end, and back-end service operations.
- Designed and implemented Golden AMIs that enable ultra-fast, repeatable deployments and support highly agile release cycles.
- Migrated multi-terabyte object storage from DigitalOcean's S3-compatible storage to AWS S3, improving durability, performance, and operational readiness.
- Established secure remote access via VPN, enabling secure and controlled infrastructure access for distributed engineering teams.
- Introduced advanced monitoring and alerting with AWS CloudWatch and New Relic, enabling proactive detection and faster response to incidents.
- Designed and implemented blue-green deployment strategies to minimize downtime and reduce risk during production releases.
- Built CI/CD pipelines to support efficient development workflows, including automated pipelines for iOS and Android application builds.
- Implemented comprehensive backup and recovery strategies to improve data protection and operational resilience.
- Ensured a smooth operational handover to a dedicated Site Reliability Engineer, ensuring continuity and long-term platform stability.
- Achieved four consecutive contract renewals, reflecting strong performance impact and continued stakeholder confidence.
Lead Cloud Architect (AWS)
Silvertours GmbH
- Led the complete migration of a business-critical back-office fulfillment system from a local installation to AWS, creating a modern, scalable, and highly available cloud platform.
- Defined and enforced a structured AWS IAM model with role-based access, service identities, and cross-account trust for the secure operation of business-critical back-office workloads.
- Developed AWS Lambda-driven automation to support database-related workflows and integration tasks, enabling event-driven processing and reducing manual operational overhead.
- Designed and implemented a comprehensive AWS security and network architecture that ensures secure connectivity, isolation, and compliance for production workloads.
- Migrated tens of terabytes of MySQL data to AWS, performing reliable, low-risk data transfer for business-critical systems.
- Migrated tens of terabytes of NFS data to AWS EFS, enabling scalable, highly available shared storage in the cloud.
- Automated provisioning and configuration of all servers using Terraform and Ansible, eliminating manual configuration and improving infrastructure consistency.
- Introduced CI/CD pipelines with auto scaling groups, load balancers, and blue-green deployments, enabling zero-downtime releases and improved release security.
- Implementation of centralized log management, significantly improving system monitorability and troubleshooting during operation.
- Design and documentation of concepts for backup, maintenance, monitoring, and operation, strengthening long-term reliability and operational readiness.
- Training of development teams in DevOps practices, AWS, and Terraform, increasing internal cloud maturity and reducing operational dependencies.
- Achieved four consecutive contract renewals, reflecting consistent delivery quality and strong stakeholder confidence.
Lead Cloud Architect (AWS)
TrustedShops GmbH
- Led the migration of legacy monolithic applications to AWS using Terraform, Packer, Ansible, Consul, and Vault to build a secure, automated, and reproducible infrastructure.
- Migrated CI/CD workflows from Jenkins to CircleCI, significantly improving the reliability, execution speed, and maintainability of the pipeline.
- Coordinated the company-wide migration from GitLab to GitHub, standardizing version control and improving collaboration and code review workflows.
- Migrated all production databases to AWS-managed services, increasing availability, scalability, and operational stability.
- Implemented ProxySQL for database load balancing and traffic management, improving the performance and resilience of database workloads.
- Automated provisioning, rolling deployments, and in-place upgrades of all servers using Ansible, enabling updates without downtime.
- Established engineering and development standards across teams, improving code quality, consistency, and long-term maintainability.
- Introduced modern development tools and workflows, increasing overall development productivity and delivery quality.
- Designed and implemented an enterprise-wide testing strategy, significantly improving test coverage, release reliability, and defect detection.
- Conducted technical workshops and training sessions on agile testing, clean code practices, and technical debt management, strengthening the development culture and sustainability.
Engineering Manager & Agile Transformation Lead
Chefkoch GmbH
- Introduction and scaling of Scrum and Kanban practices in 6 development teams, enabling predictable deliveries, transparency, and continuous improvement.
- Setting up, coaching, and managing 15 developers in agile working methods, significantly improving collaboration, personal responsibility, and delivery speed.
- Designed and implemented CI/CD pipelines and automated testing frameworks, increasing release frequency while reducing regression risk.
- Led the migration from PHP 5.0 to PHP 7, improving application performance, security, and long-term maintainability.
- Migrated the caching infrastructure from Memcache to Redis, improving reliability, performance, and operational flexibility.
- Performed a complete migration of the codebase and database character set from Latin1 to UTF-8, ensuring proper internationalization and data consistency.
- Introduced and standardized Atlassian Jira, Confluence, and Bamboo, improving project tracking, documentation, and CI/CD integration.
- Established continuous integration and unit testing procedures from the ground up, increasing code quality and reducing production errors.
- Led the architecture migration from a monolithic to a microservices-based system, enabling independent deployments and improved scalability.
- Overall responsibility for 15 developers, coordinating technical implementation with business and delivery goals.
Lead Software Engineer
werkenntwen GmbH
- Led and coordinated more than 10 developers in scaling platform systems to support 9.3 million registered users.
- Managed the scaling and optimization of core systems to ensure stability and performance amid rapidly growing user demand.
- Driving the development of new features for end users and internal staff, aligning technical implementation with business requirements.
- Designed and implemented an internal advertising server that processes more than 5 billion ad impressions per month, providing high throughput and reliability at scale.
- Created regular technical and performance reports for senior management, supporting data-driven decision-making.
- Continued development and optimization of the internal PHP framework, improving maintainability, performance, and developer productivity.
Software Engineer
werkenntwen GmbH
- Built and operated one of Germany's largest social media platforms with up to 250,000 concurrent users and 5+ billion page views per month.
- Participation in a variety of client projects in a fast-paced agency environment, providing customized web solutions for various industries.
- Design, implementation, and maintenance of small to medium-sized websites for multiple clients with varying requirements.
- Development and customization of multilingual websites to support international audiences and localization requirements.
- Building and customizing small e-commerce and shop systems for global target markets.
- Working directly with clients to translate business requirements into technical solutions.
- Achieving results in rapidly changing projects with short implementation cycles, demonstrating flexibility and reliability.
- Creating a solid foundation for clean web development, best practices, and customer-focused delivery.
Software Engineer
Michel Development & Consulting GmbH & Co. KG
- Implemented customer projects with customized web solutions for various industries.
- Designed, implemented, and maintained small to medium-sized websites.
- Developed multilingual websites for international target groups.
- Built e-commerce and shop systems for global markets.
- Worked directly with clients to implement requirements.
Industries Experience
See where this freelancer has spent most of their professional time. Longer bars indicate deeper hands-on experience, while shorter ones reflect targeted or project-based work.
Experienced in Information Technology (17 years), Media and Entertainment (5.5 years), Banking and Finance (1.5 years), Healthcare (1 year), Construction (1 year), and Transportation (1 year).
Business Areas Experience
The graph below provides a cumulative view of the freelancer's experience across multiple business areas, calculated from completed and active engagements. It highlights the areas where the freelancer has most frequently contributed to planning, execution, and delivery of business outcomes.
Experienced in Information Technology (21.5 years), Project Management (6.5 years), Product Development (6 years), and Operations (4.5 years).
Summary
Senior Cloud & Platform Engineer with a focus on AWS infrastructure, Kubernetes, and Infrastructure as Code. Advises CTOs on cloud strategy and architecture, leads platform and DevOps teams, designs and automates scalable enterprise AWS environments.
Skills
Ai & Machine Learning
- Llm Integration
- Prompt Engineering
- Claude
- Openai
- Ai Workflows
Cloud & Container Platforms
- Kubernetes
- Openshift
- Eks
- Rke2
- Aws Lambda
- Ecs
- Fargate
- Docker
Infrastructure As Code & Automation
- Terraform
- Opentofu
- Terragrunt
- Ansible
- Packer
- Helm
- Helmfile
- Cloudformation
Devops & Ci/cd
- Gitops
- Argocd
- Github Actions
- Gitlab Ci
- Blue-green Deployment
- Semantic Release
- Renovate Bot
- Ci/cd
Monitoring & Security
- Datadog
- New Relic
- Cloudwatch
- Grafana
- Prometheus
- Monitoring
- Observability
- Security
- Devsecops
- Siem
Linux & Operating Systems
- Amazon Linux
- Ubuntu
- Debian
- Alpine Linux
- Red Hat Enterprise Linux
- Rocky Linux
Programming & Scripting
- Php
- Bash
- Python
- Go
Methodology & Leadership
- Cloud Architecture
- Technical Leadership
- Technical Training
- Devops Mentoring
- Scrum
- Kanban
- Workshops
Languages
Education
Michel Development & Consulting GmbH & Co. KG
IT Specialist for Application Development (IHK) · Application Development · Sinzig, Germany
BBS Bad Neuenahr-Ahrweiler
Qualified Secondary School Diploma I, specializing in economics · Economics · Bad Neuenahr-Ahrweiler, Germany
Certifications & licenses
Management 3.0
Certified Scrum Master (CSM)
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Christian based?
What languages does Christian speak?
How many years of experience does Christian have?
What roles would Christian be best suited for?
What is Christian's latest experience?
What companies has Christian worked for in recent years?
Which industries is Christian most experienced in?
Which business areas is Christian most experienced in?
Which industries has Christian worked in recently?
Which business areas has Christian worked in recently?
What is Christian's education?
Does Christian have any certificates?
What is the availability of Christian?
What is the rate of Christian?
How to hire Christian?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Senior AWS Cloud Engineer
Nearby freelancers
Professionals working in or nearby Wachtberg, Germany