Recommended expert

Christian Kappen

Senior AWS Cloud Engineer

Christian Kappen
Wachtberg, Germany

Experience

Aug 2024 - Dec 2025
1 year 5 months

Senior AWS Cloud Engineer

Sopra Financial Technology GmbH

  • Setup and operation of a multi-cluster AWS EKS platform for banking workloads with a unified network and security architecture across 45 AWS accounts.
  • Developed and standardized a unified AWS network and security architecture for 45 AWS accounts, enabling consistent governance, connectivity, and compliance for enterprise customer environments.
  • Developed and operated a multi-cluster AWS EKS platform to support production workloads, significantly improving scalability, availability, and operational reliability.
  • Implemented a GitOps deployment model using ArgoCD and Helm, enabling fully automated, auditable deployments and reducing manual release errors.
  • Automated infrastructure provisioning using Terraform and Terragrunt at scale, reducing environment setup time by up to 70% and eliminating configuration drift.
  • Established enterprise-grade backup and disaster recovery strategies using Velero and AWS Backup, ensuring reliable multi-cluster recovery and business continuity.
  • Introduced Rancher as a self-service Kubernetes platform, accelerating developer onboarding while maintaining centralized security and governance.
  • Designed and implemented detailed AWS IAM concepts (roles, policies, trust relationships) to enforce the principle of least privilege for access to accounts, workloads, and CI/CD pipelines.
  • Developed AWS Lambda-based pre-provisioning workflows for databases, automating initialization, configuration, and access setup to support secure and consistent application integration.
  • Delivered consistent, high-quality results as part of a 5-person AWS Solutions Architecture team, resulting in three consecutive contract renewals.
Aug 2023 - Jul 2024
1 year

Lead Cloud Architect (AWS)

aconso AG

  • Design and operate a secure, highly available AWS infrastructure with isolated customer environments for an enterprise HR platform.
  • Design and deployment of a secure, highly available AWS-based cloud infrastructure for enterprise customers with isolated, customer-specific environments.
  • Development and standardization of a centralized AWS network and security infrastructure for more than 10 AWS accounts to ensure consistent governance, reliable connectivity, and compliance across enterprise customer environments.
  • Served as a technical coach and trainer to educate engineering teams on cloud architecture, security best practices, and operational excellence.
  • Worked directly with senior management and the CTO to support enterprise customers, clearly explaining and defending advanced security architectures and implementation decisions.
  • Defined and implemented enterprise-level security controls, including SIEM, encryption, and access logging, to meet strict customer and compliance requirements.
  • Built and operated a containerized platform using AWS ECS with EC2 and Fargate, balancing cost efficiency, scalability, and operational flexibility.
  • Led the migration from CloudFormation to Terraform with Terragrunt, significantly improving the scalability, reusability, and long-term maintainability of the infrastructure.
  • Implemented blue-green deployment strategies via GitLab CI, enabling zero-downtime releases and more secure production deployments.
  • Defined and enforced scalable AWS IAM and access management patterns, integrating role-based access control and cross-account permissions to securely manage users, services, and automation.
  • Implemented serverless database pre-provisioning with AWS Lambda, enabling automated setup of schemas, users, and configuration parameters prior to application deployment.
  • Improved application scalability and availability using AWS Load Balancers, ensuring consistent performance across varying workloads.
  • Established comprehensive monitoring and observability with Datadog, enabling proactive incident detection and performance optimization.
  • Delivered a highly reliable and secure platform that became a core component of the company's digital and enterprise offerings.
  • Achieved four consecutive contract renewals, reflecting ongoing delivery quality and strong stakeholder confidence.
Oct 2022 - Jul 2023
10 months

Lead Cloud Architect (AWS)

Cura4You GmbH

  • Leading the end-to-end design and implementation of a secure cloud infrastructure from the ground up to support a healthcare platform that processes highly sensitive medical data.
  • Design and implementation of a secure, segmented AWS network topology using networks, subnets, routing, and security controls to isolate environments, protect critical services, and meet regulatory requirements.
  • Implementation of robust AWS IAM architectures with clear separation of duties, least privilege access, and service-to-service authentication for the secure operation of workloads processing sensitive healthcare data.
  • Designed and operated multiple AWS ECS and AWS EKS clusters hosting a large-scale microservices architecture, ensuring scalability, reliability, and operational consistency.
  • Standardized Docker-based development and runtime environments, aligning local, staging, and production environments to reduce integration issues and friction during deployment.
  • Deployed a high-performance frontend architecture using Amazon CloudFront and S3, optimizing global content delivery, scalability, and user experience.
  • Implemented blue-green deployment pipelines using GitHub Actions and integrated automated testing to enable zero-downtime releases and significantly improve application stability.
  • designed and enforced advanced encryption strategies with AWS KMS, strengthening data protection beyond standard cloud-managed encryption.
  • Established comprehensive monitoring and observability with Datadog, enabling proactive detection of issues across the entire application and infrastructure stack.
  • Built and managed highly available data tiers using multiple AWS Aurora MySQL 8.0 clusters and AWS ElastiCache Redis clusters.
  • Planned and automated the entire infrastructure lifecycle with Terraform and Terragrunt to ensure reproducibility, scalability, and compliance-ready environments.
  • Ensured ongoing compliance with GDPR, BSI, PCI, and ISO 27001 by directly embedding security and regulatory requirements into infrastructure and deployment processes.
  • Provided fully isolated development, staging, and local environments for developers and product managers, accelerating development speed and improving cross-team collaboration.
Nov 2021 - Oct 2022
1 year

Lead Cloud Architect (AWS)

PlanA.Earth GmbH

  • Led the migration of an organically grown AWS environment to a highly available, production-grade cloud architecture, significantly improving reliability, scalability, and operational stability.
  • assumed full responsibility for stabilizing and modernizing the AWS infrastructure in a fast-growing start-up company (with over 40 million euros in funding) despite frequent team changes and limited previous infrastructure management experience.
  • designed and enforced scalable AWS IAM structures with clearly defined roles, policies, and trust relationships, enabling secure access management across teams, services, and CI/CD workflows.
  • refactored and standardized the AWS VPC foundation (network design, subnet segmentation, routing, and security controls) to improve isolation, availability, and operational robustness across all environments.
  • implemented AWS Lambda-based automation for database provisioning and ETL pipelines to enable serverless initialization, data transformation, and integration workflows, supporting reliable and scalable data processing.
  • designed and operated highly available data tiers using multiple AWS RDS MySQL 8.0 clusters and AWS ElastiCache Redis clusters, improving performance and data consistency.
  • designed and implemented blue-green deployment pipelines using GitHub Actions, enabling zero-downtime releases and more secure production rollouts.
  • built and supported local development environments and CI/CD pipelines, increasing developer productivity and reducing friction in deployment.
  • played a key role in the company's ISO 27001 and SOC 2 certification initiatives, contributing to security controls, asset monitoring, and audit readiness.
  • implemented continuous asset and compliance monitoring with Vanta, improving infrastructure security visibility.
  • delivered a scalable container platform using AWS ECS with EC2 and Fargate, balancing cost efficiency, scalability, and ease of use.
  • improved application availability and traffic management using AWS Load Balancers, ensuring consistent performance under load.
  • strengthened data protection and security controls using AWS KMS, aligning the infrastructure with the company's security and compliance requirements.
  • achieved four consecutive contract renewals, reflecting strong performance impact and stakeholder confidence.
Oct 2020 - Sep 2021
1 year

Lead Cloud Architect (AWS)

Schuettflix GmbH

  • Led a complete migration from DigitalOcean to AWS, significantly improving the scalability, reliability, and long-term robustness of the cloud infrastructure.
  • Designed and implemented a robust AWS network architecture (network layout, subnet segmentation, routing, and security controls) that ensures secure connectivity, high availability, and a strong foundation for the migrated platform.
  • Defined and enforced a structured AWS IAM model with role-based access, service identities, and cross-account trust for the secure operation of business-critical back-office workloads.
  • Modernized the application platform by replacing an outdated Rancher configuration, stabilizing and optimizing web, front-end, and back-end service operations.
  • Designed and implemented Golden AMIs that enable ultra-fast, repeatable deployments and support highly agile release cycles.
  • Migrated multi-terabyte object storage from DigitalOcean's S3-compatible storage to AWS S3, improving durability, performance, and operational readiness.
  • Established secure remote access via VPN, enabling secure and controlled infrastructure access for distributed engineering teams.
  • Introduced advanced monitoring and alerting with AWS CloudWatch and New Relic, enabling proactive detection and faster response to incidents.
  • Designed and implemented blue-green deployment strategies to minimize downtime and reduce risk during production releases.
  • Built CI/CD pipelines to support efficient development workflows, including automated pipelines for iOS and Android application builds.
  • Implemented comprehensive backup and recovery strategies to improve data protection and operational resilience.
  • Ensured a smooth operational handover to a dedicated Site Reliability Engineer, ensuring continuity and long-term platform stability.
  • Achieved four consecutive contract renewals, reflecting strong performance impact and continued stakeholder confidence.
Apr 2019 - May 2020
1 year 2 months

Lead Cloud Architect (AWS)

Silvertours GmbH

  • Led the complete migration of a business-critical back-office fulfillment system from a local installation to AWS, creating a modern, scalable, and highly available cloud platform.
  • Defined and enforced a structured AWS IAM model with role-based access, service identities, and cross-account trust for the secure operation of business-critical back-office workloads.
  • Developed AWS Lambda-driven automation to support database-related workflows and integration tasks, enabling event-driven processing and reducing manual operational overhead.
  • Designed and implemented a comprehensive AWS security and network architecture that ensures secure connectivity, isolation, and compliance for production workloads.
  • Migrated tens of terabytes of MySQL data to AWS, performing reliable, low-risk data transfer for business-critical systems.
  • Migrated tens of terabytes of NFS data to AWS EFS, enabling scalable, highly available shared storage in the cloud.
  • Automated provisioning and configuration of all servers using Terraform and Ansible, eliminating manual configuration and improving infrastructure consistency.
  • Introduced CI/CD pipelines with auto scaling groups, load balancers, and blue-green deployments, enabling zero-downtime releases and improved release security.
  • Implementation of centralized log management, significantly improving system monitorability and troubleshooting during operation.
  • Design and documentation of concepts for backup, maintenance, monitoring, and operation, strengthening long-term reliability and operational readiness.
  • Training of development teams in DevOps practices, AWS, and Terraform, increasing internal cloud maturity and reducing operational dependencies.
  • Achieved four consecutive contract renewals, reflecting consistent delivery quality and strong stakeholder confidence.
Aug 2017 - Mar 2019
1 year 8 months

Lead Cloud Architect (AWS)

TrustedShops GmbH

  • Led the migration of legacy monolithic applications to AWS using Terraform, Packer, Ansible, Consul, and Vault to build a secure, automated, and reproducible infrastructure.
  • Migrated CI/CD workflows from Jenkins to CircleCI, significantly improving the reliability, execution speed, and maintainability of the pipeline.
  • Coordinated the company-wide migration from GitLab to GitHub, standardizing version control and improving collaboration and code review workflows.
  • Migrated all production databases to AWS-managed services, increasing availability, scalability, and operational stability.
  • Implemented ProxySQL for database load balancing and traffic management, improving the performance and resilience of database workloads.
  • Automated provisioning, rolling deployments, and in-place upgrades of all servers using Ansible, enabling updates without downtime.
  • Established engineering and development standards across teams, improving code quality, consistency, and long-term maintainability.
  • Introduced modern development tools and workflows, increasing overall development productivity and delivery quality.
  • Designed and implemented an enterprise-wide testing strategy, significantly improving test coverage, release reliability, and defect detection.
  • Conducted technical workshops and training sessions on agile testing, clean code practices, and technical debt management, strengthening the development culture and sustainability.
Mar 2012 - Jul 2017
5 years 5 months

Engineering Manager & Agile Transformation Lead

Chefkoch GmbH

  • Introduction and scaling of Scrum and Kanban practices in 6 development teams, enabling predictable deliveries, transparency, and continuous improvement.
  • Setting up, coaching, and managing 15 developers in agile working methods, significantly improving collaboration, personal responsibility, and delivery speed.
  • Designed and implemented CI/CD pipelines and automated testing frameworks, increasing release frequency while reducing regression risk.
  • Led the migration from PHP 5.0 to PHP 7, improving application performance, security, and long-term maintainability.
  • Migrated the caching infrastructure from Memcache to Redis, improving reliability, performance, and operational flexibility.
  • Performed a complete migration of the codebase and database character set from Latin1 to UTF-8, ensuring proper internationalization and data consistency.
  • Introduced and standardized Atlassian Jira, Confluence, and Bamboo, improving project tracking, documentation, and CI/CD integration.
  • Established continuous integration and unit testing procedures from the ground up, increasing code quality and reducing production errors.
  • Led the architecture migration from a monolithic to a microservices-based system, enabling independent deployments and improved scalability.
  • Overall responsibility for 15 developers, coordinating technical implementation with business and delivery goals.
Mar 2011 - Feb 2012
1 year

Lead Software Engineer

werkenntwen GmbH

  • Led and coordinated more than 10 developers in scaling platform systems to support 9.3 million registered users.
  • Managed the scaling and optimization of core systems to ensure stability and performance amid rapidly growing user demand.
  • Driving the development of new features for end users and internal staff, aligning technical implementation with business requirements.
  • Designed and implemented an internal advertising server that processes more than 5 billion ad impressions per month, providing high throughput and reliability at scale.
  • Created regular technical and performance reports for senior management, supporting data-driven decision-making.
  • Continued development and optimization of the internal PHP framework, improving maintainability, performance, and developer productivity.
Feb 2008 - Feb 2011
3 years 1 month

Software Engineer

werkenntwen GmbH

  • Built and operated one of Germany's largest social media platforms with up to 250,000 concurrent users and 5+ billion page views per month.
  • Participation in a variety of client projects in a fast-paced agency environment, providing customized web solutions for various industries.
  • Design, implementation, and maintenance of small to medium-sized websites for multiple clients with varying requirements.
  • Development and customization of multilingual websites to support international audiences and localization requirements.
  • Building and customizing small e-commerce and shop systems for global target markets.
  • Working directly with clients to translate business requirements into technical solutions.
  • Achieving results in rapidly changing projects with short implementation cycles, demonstrating flexibility and reliability.
  • Creating a solid foundation for clean web development, best practices, and customer-focused delivery.
Feb 2004 - Jan 2008
4 years

Software Engineer

Michel Development & Consulting GmbH & Co. KG

  • Implemented customer projects with customized web solutions for various industries.
  • Designed, implemented, and maintained small to medium-sized websites.
  • Developed multilingual websites for international target groups.
  • Built e-commerce and shop systems for global markets.
  • Worked directly with clients to implement requirements.

Industries Experience

See where this freelancer has spent most of their professional time. Longer bars indicate deeper hands-on experience, while shorter ones reflect targeted or project-based work.

Experienced in Information Technology (17 years), Media and Entertainment (5.5 years), Banking and Finance (1.5 years), Healthcare (1 year), Construction (1 year), and Transportation (1 year).

Information Technology
Media and Entertainment
Banking and Finance
Healthcare
Construction
Transportation

Business Areas Experience

The graph below provides a cumulative view of the freelancer's experience across multiple business areas, calculated from completed and active engagements. It highlights the areas where the freelancer has most frequently contributed to planning, execution, and delivery of business outcomes.

Experienced in Information Technology (21.5 years), Project Management (6.5 years), Product Development (6 years), and Operations (4.5 years).

Information Technology
Project Management
Product Development
Operations

Summary

Senior Cloud & Platform Engineer with a focus on AWS infrastructure, Kubernetes, and Infrastructure as Code. Advises CTOs on cloud strategy and architecture, leads platform and DevOps teams, designs and automates scalable enterprise AWS environments.

Skills

Ai & Machine Learning

  • Llm Integration
  • Prompt Engineering
  • Claude
  • Openai
  • Ai Workflows

Cloud & Container Platforms

  • Kubernetes
  • Openshift
  • Eks
  • Rke2
  • Aws Lambda
  • Ecs
  • Fargate
  • Docker

Infrastructure As Code & Automation

  • Terraform
  • Opentofu
  • Terragrunt
  • Ansible
  • Packer
  • Helm
  • Helmfile
  • Cloudformation

Devops & Ci/cd

  • Gitops
  • Argocd
  • Github Actions
  • Gitlab Ci
  • Blue-green Deployment
  • Semantic Release
  • Renovate Bot
  • Ci/cd

Monitoring & Security

  • Datadog
  • New Relic
  • Cloudwatch
  • Grafana
  • Prometheus
  • Monitoring
  • Observability
  • Security
  • Devsecops
  • Siem

Linux & Operating Systems

  • Amazon Linux
  • Ubuntu
  • Debian
  • Alpine Linux
  • Red Hat Enterprise Linux
  • Rocky Linux

Programming & Scripting

  • Php
  • Bash
  • Python
  • Go

Methodology & Leadership

  • Cloud Architecture
  • Technical Leadership
  • Technical Training
  • Devops Mentoring
  • Scrum
  • Kanban
  • Workshops

Languages

German
Native
English
Advanced

Education

Michel Development & Consulting GmbH & Co. KG

IT Specialist for Application Development (IHK) · Application Development · Sinzig, Germany

BBS Bad Neuenahr-Ahrweiler

Qualified Secondary School Diploma I, specializing in economics · Economics · Bad Neuenahr-Ahrweiler, Germany

Certifications & licenses

Management 3.0

Certified Scrum Master (CSM)

Profile

Created
Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Frequently asked questions

Do you have questions? Here you can find further information.

Where is Christian based?

Christian is based in Wachtberg, Germany.

What languages does Christian speak?

Christian speaks the following languages: German (Native), English (Advanced).

How many years of experience does Christian have?

Christian has at least 21 years of experience. During this time, Christian has worked in at least 5 different roles and for 10 different companies. The average length of individual experience is 2 years and 11 months. Note that Christian may not have shared all experience and actually has more experience.

What roles would Christian be best suited for?

Based on recent experience, Christian would be well-suited for roles such as: Senior AWS Cloud Engineer, Lead Cloud Architect (AWS), Engineering Manager & Agile Transformation Lead.

What is Christian's latest experience?

Christian's most recent position is Senior AWS Cloud Engineer at Sopra Financial Technology GmbH.

What companies has Christian worked for in recent years?

In recent years, Christian has worked for Sopra Financial Technology GmbH, aconso AG, Cura4You GmbH, PlanA.Earth GmbH, and Schuettflix GmbH.

Which industries is Christian most experienced in?

Christian is most experienced in industries like Information Technology (IT), Media, Entertainment and Publishing, and Banking and Finance. Christian also has some experience in Tourism and Hospitality, Construction, and Transportation and Logistics.

Which business areas is Christian most experienced in?

Christian is most experienced in business areas like Information Technology (IT), Project Management, and Product Development. Christian also has some experience in Operations.

Which industries has Christian worked in recently?

Christian has recently worked in industries like Information Technology (IT), Banking and Finance, and Construction.

Which business areas has Christian worked in recently?

Christian has recently worked in business areas like Information Technology (IT), Operations, and Product Development.

What is Christian's education?

Christian holds a Bachelor in Application Development from Michel Development & Consulting GmbH & Co. KG.

Does Christian have any certificates?

Christian has 2 certificates. These include: Management 3.0 and Certified Scrum Master (CSM).

What is the availability of Christian?

Christian is immediately available for suitable projects.

What is the rate of Christian?

Christian's rate depends on the specific project requirements. Please use the Meet button on the profile to schedule a meeting and discuss the details.

How to hire Christian?

To hire Christian, click the Meet button on the profile to request a meeting and discuss your project needs.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1200
900
600
300
Market avg: 980-1140 €
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.