Halil Oeztoprak
Principal Cloud & DevSecOps Architect (AWS / Azure / Terraform / Kubernetes / CI-CD)
Experience
Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD)
KfW Bankengruppe
Regulated environment of a German banking group (approx. 8,500 employees, hybrid cloud strategy).
Responsible for operating, provisioning, and continuously securing business-critical platforms – including a GenAI chat application, a big-data/AI platform, and data science workstations based on Azure Virtual Desktops and VMs. Ownership of Azure DevOps projects such as ShaiHulud and React2Shell and BSI warnings - security operations improvements across the SDLC.
Deployment responsibility for the GenAI chat application, big-data/AI platform (BDAI), and data science workstations (AVD/VM-based) in the respective landing zones.
Deployment & release management: end-to-end responsibility for deployments of portal and service applications in multiple Azure landing zones, including technical approvals, approvals according to development teams' deployment guidelines, and ensuring ITIL-based change and release processes in ongoing operations via ServiceNow.
Azure landing zones & network architecture: building, provisioning, and operating Azure landing zones for 3-tier web applications with enhanced network segmentation, VNet peering, hub-and-spoke architectures, private endpoints, and firewall integration in separate subscriptions and tenants.
Azure DevOps governance & operations: ownership of the Azure DevOps organization including projects, repositories, and CI/CD pipelines; implementation of governance requirements such as branch policies, approval gates, permission models, and auditing-capable operating structures.
Infrastructure as Code (Terraform): design, implementation, and operation of a modular Terraform architecture for standardized cloud infrastructure provisioning, including state management, provider versioning, reusability, and policy-as-code approaches.
CI/CD pipeline engineering: designing, operating, and optimizing complex YAML-based CI/CD pipelines with multi-stage deployments, template standardization, self-hosted agents, integrated secret management, and automated quality and security checks.
Git migration & platform consolidation: planning and executing migration of repositories and pipelines from Azure DevOps to GitLab CI/CD, including automated scripts, Git history migration, pipeline porting, and consolidation of development platforms.
Container & platform operations (AKS): running and conducting security assessments of container-based workloads on Azure Kubernetes Service, centralizing on-premises container registry for ACR. OpenShift (OCP) security reviews: security assessment of code baselines, build pipelines, and deployment processes for on-premises OpenShift clusters running critical applications, and deriving concrete hardening recommendations.
Shift-left security & DevSecOps transformation: implementing a company-wide shift-left approach to integrate security early into development and deployment processes, enabling developers to conduct security checks independently, and sustainably reducing vulnerabilities before production (IDE integrations, pre-commit hooks, local scanners).
Software supply chain security: analyzing and mitigating supply chain risks in NPM- and Yarn-based applications through dependency audits, securing CI/CD pipelines, token rotation, and restricting risky build and lifecycle mechanisms.
Frontend & framework security (React/Next.js): security assessment and coordination of remediation for critical vulnerabilities in all platform applications and web frameworks, including alignment and additional technical mitigations with all teams following BSI warnings.
Software composition analysis (SCA): implementing and operating automated vulnerability scans for container images, pipelines/artifacts, and third-party dependencies, including SBOM exports within CI/CD pipelines.
SAST/DAST integration: designing and piloting static and dynamic application security tests in close cooperation with security architecture and development teams to continuously improve code and runtime security, and establishing operational acceptance tests (BATs).
Artifact & registry consolidation: analyzing and consolidating all package and container repositories for service applications and AKS workloads with the goal of a centralized, secured registry strategy, including centralized vulnerability scanning and governance.
Dependency Track & SBOM strategy: advising the compliance board on implementing a central SBOM and vulnerability management platform to increase enterprise-wide dependency transparency and accelerate CVE response times.
CI/CD pipeline hardening: security analysis and cleanup of the existing pipeline landscape by removing unused pipelines, improving secrets hygiene, enforcing the least privilege principle, and isolating build agent environments.
Azure Web Application Firewall (WAF) optimization: analyzing and optimizing existing Azure WAF rule sets (OWASP Top 10 Core Rule Set, DSR/SDC, custom rules) to defend against known vulnerabilities and exploit patterns, including reducing false positives and improving threat detection.
Documentation & stakeholder communication: creating and maintaining technical documentation, runbooks, and architecture diagrams in Jira and Confluence, as well as actively transferring knowledge between operations, development, security, and compliance stakeholders.
Principal Cloud Solutions Architect & Senior DevSecOps Engineer
risiq GmbH
Banking risk management platform.
Startup in finance, 42 cloud services, 50+ employees, multi-account AWS landing zone, multi-stage Kubernetes cluster provisioning with EKS and ECS, and front-end web interface via AWS Amplify. GDPR, C5, BaFin, and DORA compliant CI/CD deployment pipelines via GitHub Enterprise.
Implemented a multi-account strategy with AWS Control Tower and Account Factory for Terraform (AFT) for secure separation of dev, test, and production environments, plus centralized governance and compliance monitoring in a fully automated GitOps model.
Established data residency in EU regions, implemented encryption at rest and in transit, and built audit trails and logging mechanisms for full traceability of personal and critical business data.
Deployed highly available EKS clusters with auto-scaling, pod security standards, network policies, and integration of AWS Fargate for serverless container workloads, as well as ECS for a hybrid container strategy.
Developed automated deployment pipelines with GitHub Enterprise Actions that measure and optimize change failure rate, lead time, mean time to recovery, and deployment frequency, including automated rollback mechanisms, OWASP, SAST, and DAST integration with SonarQube and Burp Suite Enterprise.
Integrated AWS Security Hub, GuardDuty, Config Rules, and Inspector for continuous security and compliance monitoring, and implemented IAM roles with least privilege and MFA enforcement.
Onboarded additional AWS accounts into the customer's CSPM/CNAPP portal based on Wiz Security.
High-performance backend API development: building a scalable microservices architecture with AWS Lambda, API Gateway, and RDS/DynamoDB for risk data processing, including CDN integration.
AWS Amplify front-end deployment and infrastructure co-development of a responsive web application with React/Angular, automated build and deployment pipelines for banking clients, and integration of Auth0 for secure user authentication and authorization.
Implemented comprehensive monitoring and custom metrics for business KPIs and SLA monitoring of risk management functions.
Established a multi-region strategy with automated backups, cross-region replication, RTO/RPO-optimized recovery processes, and regular disaster recovery tests.
Developed automated compliance checks, policy-as-code implementation via OPA, continuous vulnerability scans via Dependency-Track, and integration of AWS Config for configuration drift detection with audit-ready documentation.
Enterprise Cloud Solutions Architect / Senior DevOps Engineer
Bilfinger SE
2,500 workloads for over 17,000 employees worldwide.
Multi-account AWS landing zone, deployment of multi-stage Kubernetes clusters with Amazon EKS and ECS, as well as AWS Fargate; hybrid networking with global IP address management (IPAM) and WAN; use of transit gateways and Palo Alto firewalls (Pan-OS) across six operational cloud regions.
Service ownership of AWS cloud landing zones, including operation, further development, and ensuring compliance with corporate standards and governance policies for all subsidiaries.
Conducted security and compliance analyses (DevSecOps) and mapped findings to common frameworks like NIST, ISO 27001, and PCI DSS.
Performed AWS Well-Architected Reviews to assess and optimize existing multi-account landing zone architectures.
Centralized and consolidated multiple AWS landing zones and built a global network architecture to the Azure Prisma Hub.
Managed and optimized incident, change, and problem management processes via ServiceNow for AWS Global Networking / Azure Global WAN.
Analyzed, optimized, and migrated DaaS workloads (Desktop-as-a-Service), including comparing and transitioning from Nutanix Frame and AWS WorkSpaces Classic to AWS WorkSpaces Pools.
Tuned storage performance and throughput for Amazon FSx for Windows File Server.
Introduced and operated a centralized firewall and traffic inspection setup with Palo Alto Networks (PAN-OS).
Designed and implemented a fully automated AWS landing zone solution with built-in security and compliance mechanisms.
Built and maintained infrastructure-as-code (IaC) pipelines using Azure DevOps for repeatable, secure deployments including security gates.
Rolled out global AWS WorkSpaces Pools for over 500 CAD/engineering end users, including enablement and architecture optimization.
Implemented staging environments for Kubernetes workloads, including separation of dev/test/prod and access control.
Integrated Dependency-Track for SBOM analysis and implemented additional security services like AWS Inspector, GuardDuty, and Security Hub.
Connected the AWS environment to external SOC providers, including SIEM integration.
Onboarded the new landing zone into the CSPM tool (SentinelOne Singularity Cloud Platform), including continuous security posture management.
Documentation, quality assurance, and knowledge transfer to internal engineering and security teams.
Enterprise Cloud Solutions Architect / Senior DevOps Engineer
Concordia Versicherungsgesellschaft auf Gegenseitigkeit a.G.
450 workloads, multiple data centers and branch offices.
AWS cloud pilot, multi-account AWS landing zone, multi-stage Kubernetes cluster deployment with EKS and ECS, hybrid networking with Direct Connect, Transit Gateway, and site-to-site VPN.
Configured a well-architected AWS multi-account landing zone, including workload accounts and organizational units (OUs) for multi-stage Kubernetes clusters.
Advised the client on multi-account and multi-stage strategies in AWS.
Implemented Account Factory for Terraform (AFT) to scale the AWS landing zone and automate security and compliance across the organization.
Applied security and compliance policies according to BSI, VAIT, C5, BaFin, and DORA.
Implemented service control policies (SCPs) and guardrails in AWS Control Tower and AWS Organizations.
Enabled security standards and implemented and configured AWS native security services like SecurityHub, GuardDuty, and IAM Access Analyzer based on best practices.
Configured and enabled compliance standards for resources with AWS Config and AWS Trusted Advisor.
Created decision templates for service strategies, especially for implementing and managing key management services for compliance and data encryption in AWS.
Planned and configured hybrid connectivity, including connecting customer data centers and implementing dynamic routing strategies via BGP VPN/failover and network segmentation.
Developed and deployed secure, compliance-compliant EC2 images according to CIS framework and STIG.
Automated infrastructure provisioning with Terraform across multiple AWS accounts via Azure DevOps YAML pipelines.
Built IaC and CI/CD deployment pipelines including security gates with SAST and DAST integration via Trivy and tfsec for Kubernetes deployments via ArgoCD.
Implemented role-based access control (RBAC) and attribute-based access control (ABAC) in AWS IAM and integrated AWS Identity Center for comprehensive identity management.
Set up comprehensive CloudWatch monitoring, including log aggregation and real-time analytics.
Established centralized backup management and business continuity and disaster recovery planning with AWS Backup services.
Comprehensive documentation including runbooks and operations manuals.
Conducted quality and performance reviews.
Senior Cloud Consultant / Senior Cloud Solutions Architect
Allgeier Group SE / Naggaro SE
Various clients from different industries, over 1,500 users in the EUC context, five main applications including infrastructure migrations.
AWS Cloud MSP, multi-account AWS landing zone, multi-tenant AppStream 2.0 fleets, and Amazon WorkSpaces Classic provisioning using Terraform and AFT.
Configured multiple AWS multi-account landing zones, including workload accounts and organizational units (OUs).
Implemented and managed SCPs and guardrails in AWS Control Tower and AWS Organizations, including regional usage restrictions and establishing an account security and compliance concept according to AWS best practices.
Planned, configured, and automated provisioning of multiple VPCs and infrastructures for AWS VDI technologies, focusing on Amazon AppStream 2.0 and Amazon WorkSpaces.
Developed, automated, and deployed images for Amazon AppStream 2.0 and AWS WorkSpaces services using Terraform and image pipelines.
Designed migrations and planned and executed strategic migration of client applications and application servers to AWS cloud through rehosting/lift-and-shift.
Fully automated provisioning of client infrastructures and applications in multi-stages and multi-accounts via Terraform and CI/CD pipelines.
End-to-end configuration and testing for multiple user streaming via AppStream 2.0, including autoscaling and fleet management.
Created and deployed standardized Amazon WorkSpaces, including Active Directory domain join and standard GPOs.
Connected AWS WorkSpaces services to Microsoft Active Directory workloads and integrated with identity provider services for user synchronization including single sign-on (via SCIM).
Implemented Azure Active Directory synchronization for Microsoft 365 and Entra ID with Entra ID Connect.
Configured CloudWatch monitoring and enabled application monitoring for applications.
Set up centralized backup management with AWS Backup service for the respective client organizations.
Lead IT Consultant and Team Lead of the dedicated 3rd-Level Global IT Operations team
Atotech Deutschland GmbH & Co. KG
1,250+ workloads and over 5,500 users spread across globally connected data centers and offices in regions such as Asia/Pacific, EMEA and the USA.
Active Directory Security Assessment: Conduct detailed analyses of security settings, identify existing vulnerabilities, and assess the current security level.
Microsoft Services Hub Log Analytics Workspace configuration: Set up a central monitoring management system to collect and analyze security-relevant log data.
Advanced Group Policy Management 4.0: Implement advanced group policy management with granular security controls for Group Policy Objects (GPOs).
Tier-0 security concept: Develop and implement a Tier-0 concept for organization-wide segmentation of security levels in Active Directory and the GPO structure, including logical optimizations.
Hardening service accounts: Review and harden service accounts with a focus on password policies, removal of weak accounts, and migration to gMSA accounts (Group Managed Service Accounts).
Hardening user account policies: Tighten user account settings and password requirements according to current best practices.
General AD hardening: Apply extensive hardening measures based on CIS benchmarks and BSI security guidelines.
Entra ID Connect update and redesign: Update and redesign the Entra Connect implementation to optimize user synchronization between on-premises and cloud identities.
Log4Shell response: Implement additional security measures to fix Log4Shell vulnerabilities and enable automated patch management using RedHat Satellite and WSUS.
Cloud Consultant
IVG Immobilien GmbH
Advised on the planning, architecture, and full implementation of a scalable Windows Virtual Desktop environment for 500+ users.
Built and configured host pools (pooled & personal) with automated user assignment and load balancing according to the Azure Well-Architected Framework.
Developed and operated a fully automated image pipeline (golden image build & deployment) using Azure Image Builder – including regular updates, security hardening, and CAD application integration.
Implemented MSIX/App Attach for dynamic application delivery: packaging, storage integration (Azure Files), assignment, and lifecycle management for different user groups from Entra ID.
Integrated FSLogix for user profile management (Azure Files) to ensure high-performance, persistent user profiles with GPO enforcement.
Implemented monitoring & logging (Azure Monitor, Log Analytics Workspace) for proactive troubleshooting and capacity planning.
Automated scaling and maintenance processes for session hosts (start VM on connect, scheduled agent updates, autoscaling).
Implemented Conditional Access policies and multi-factor authentication for secure remote access to AVD desktops.
Created operational documentation, runbooks, and handed over to IT operations.
Lead IT Consultant | Team Lead of the dedicated 3rd-Level Global IT Operations team
Atotech Deutschland GmbH & Co. KG
1,250+ workloads and over 5,500 users across globally connected data centers and offices worldwide.
Strategic support for the AWS cloud migration to ensure a seamless transformation of the IT infrastructure.
Led the 3rd-Level global IT operations team responsible for the uninterrupted operation of the global IT landscape.
Ensured global 3rd-Level support for all data centers and sites worldwide, including DMZs and global secure platforms.
Managed IT processes: carried out and controlled consulting, monitoring, incident, change, and problem management processes.
Operated a hybrid, heterogeneous IT infrastructure on-premises and in the cloud at a 3rd-Level support level.
Responsible for Microsoft backend services in a single-forest, multi-domain Active Directory setup.
Managed Microsoft 365 services, Exchange Online (hybrid), Microsoft Endpoint Manager (SCCM/EPM), Intune MDM, MDT, and Windows 10/11 client rollouts.
Ran the SCCM backend globally, software distribution, and management of distribution points.
Implemented and operated monitoring solutions like SCOM & Zabbix.
Ensured operations including VMware virtualization, Riverbed systems, storage and network services, Citrix VDI infrastructure, and RedHat Linux & Satellite.
Migration and transformation: planned and executed migrations, rehosting, redeployments, and rearchitecting of services into the AWS cloud.
Security and vulnerability management in the global IT landscape.
Coordinated external service providers, partners, and strategic provider management in an international enterprise context.
Senior IT Consultant
Atotech Deutschland GmbH & Co. KG
1,250+ workloads and over 5,500 users worldwide.
Provided comprehensive consulting and support to the client during the AWS cloud migration preparation phase.
Performed detailed assessments for around 250+ Linux servers and over 50 Linux applications.
Introduced RedHat Satellite for efficient patch management of RedHat and CentOS servers.
Modernized Linux servers with minor and major release changes in preparation for cloud requirements.
Conducted AWS Migration Readiness Assessments (MRA) for resources, tools, and workforce skills.
Installed AWS discovery and inventory tools to analyze application dependencies.
Created comprehensive documentation of the Linux system landscape as a basis for cloud rehosting.
Team Lead & Lead IT Consultant | Senior Modern Digital Workplace Consultant
Allgeier Group SE
Various industries (energy, healthcare), team leadership and setup for Microsoft 365 onboardings including resource and deployment planning.
Planned, managed, and executed complex Microsoft 365 onboarding projects for clients like CENTOGENE, Powerlines Group GmbH, and Onyx Germany GmbH.
Managed heterogeneous platforms including Windows 10/11, macOS, Android, and iOS.
Migrated email services, calendars, and mailboxes to Exchange Online.
Configured and deployed Microsoft Teams including integration of B2B scenarios.
Managed devices, configuration, and automation using Microsoft Intune.
Developed automated policies in PowerShell and GitHub to increase efficiency.
Implemented device compliance and security policies based on CIS benchmarks and BSI standards.
Designed and implemented a secure corporate app store including black- and whitelisting through Entra ID groups.
Extended management strategies to macOS and implemented fully automated deployments using Windows Autopilot and JAMF.
Created detailed runbooks and process documentation.
IT Consultant & Technical Migration Lead
gkv informatik GbR
Healthcare insurance environment, Citrix infrastructure backend services, IGEL thin clients for BARMER.
Initiation and planning of the migration project for Citrix infrastructure outsourcing.
Design and technical implementation of migration paths for the existing Citrix infrastructure.
Development of a new Citrix backend for future operations.
Identification and implementation of migration strategies for user profiles and software packages.
Design and creation of a new Active Directory group structure including naming conventions.
Securing the migration process by identifying critical configurations such as Citrix UPM and GPOs.
Coordination and management of external service providers during the transition.
IT Consultant, Team and Transition Manager
IT Dienstleistungszenrum Berlin (ITDZ)
750+ workloads, HP enclosure cluster with 64 server systems, 4,500 Citrix users.
Knowledge transfer and delivery of operations manuals and concepts to specialist departments.
Setup, operation, and management of the Citrix Hypervisor (XenServer) virtualization environment.
Optimization of the Citrix XenApp/XenDesktop infrastructure as well as the Citrix Hypervisor.
Hardening of the Citrix desktop design using Group Policies according to the CIS framework and BSI standards.
Performance optimization in the area of Citrix Hypervisor virtualization and Provisioning Services.
Monitoring of infrastructure services using SCOM and CheckMK.
Design and implementation of a FollowMe/Pull Printing solution according to BSI standards, including full encryption.
IT Consultant
BAM Deutschland AG
2nd and 3rd level support for Citrix remote workspaces.
Implementation and rollout of Windows 10 clients using Baramundi.
Interim administration of the Exchange server.
Software packaging and endpoint management.
Mobile device management via MobileIron/MobilePASS.
Quality management and documentation creation.
IT Consultant
Telefónica Germany GmbH & Co. OHG
Over 750 server workloads, virtual RedHat server farms in two data centers.
Responsibility for VMware vCenter administration in a global context.
ITIL-compliant incident management and change request handling with BMC Remedy.
Release and deployment management for RedHat application platforms.
Coordination of international resources for minor and major RedHat 6 to RedHat 7 release transitions.
Development of a patch management concept for RedHat server systems in compliance with ISO standards.
Implementation and commissioning of the RedHat Satellite platform 6.2.
Migration of RedHat licenses to RHSM and inventory assessment including CMDB transfer.
Analysis of the global IT infrastructure and creation of a monitoring concept including SLAs.
BASH and PowerShell scripting to automate IT processes.
IT Consultant
Landeshauptstadt München
Over 500 workloads, virtualization of physical and virtual servers.
Execution of P2V (physical to virtual) virtualization of physical servers with VMware.
V2V (virtual to virtual) conversion of KVM/QEMU server systems into VMware vCenter.
Coordination and scheduling of virtualization processes.
Virtualization of RedHat, SLES, and Microsoft Windows servers.
Integration of virtualized systems into the central data center.
Implementation of service and process monitoring as well as quality assurance of migration processes.
IT Consultant
World Hotels GmbH
Azure cloud infrastructure, SharePoint Server, MS-SQL Server 2012, Reporting Services.
Developed a cloud migration concept using a lift-and-shift approach.
Migrated databases from MS-SQL Server 2008 to MS-SQL Server 2012.
Set up and deployed SharePoint and database servers in Azure Cloud.
Executed lift-and-shift migration for Microsoft servers with testing phases.
Customized and created SQL Server reports, including trend analyses.
Performed quality control and wrote operating manuals.
Junior Identity & Access Management (IAM) Consultant
IT Baden-Württemberg (BITBW)
Designed and implemented an IAM environment using Microsoft Identity Manager (MIM).
Developed attribute flows and synchronization rules for Active Directory user objects.
Built and secured the perimeter network (DMZ), including a reverse proxy.
Integrated and tested IAM tools for single sign-on (SSO) applications.
Set up the SSO identity provider and integrated it with Active Directory Federation Services (ADFS).
IT System Administrator / Project Administrator
Med 360° SE
275 workstations, 50 server systems, 6 locations.
Designed and built a new standards-compliant server room.
Executed Active Directory migration projects (Windows Server 2003 to 2012/R2).
Replaced Microsoft Exchange servers with Zarafa groupware on a Linux platform.
Automated Windows 7 rollout and replaced Windows XP clients using OPSI.
Connected multiple sites via site-to-site VPN.
Introduced a cross-site Citrix terminal server system for KIS applications.
Implemented Nagios monitoring with CheckMK.
Set up a new ticketing system (OTRS) and a Linux-based CRM system (vTiger).
Managed and coordinated external service providers.
System Programmer / Main Project during Fixed-Term Assignment
rku.it GmbH
Two data centers, over 2000 server systems, various network components.
Developed a monitoring system architecture based on Nagios.
Implemented the Nagios master server and configured the platform.
Successfully migrated Nagios to Check_MK OMD (Open Monitoring Distribution).
Integrated AIX, Linux, and Windows servers into the monitoring system.
Mapped service dependencies and prioritized business-critical applications.
Monitored systems via SNMP and WMI, including alert configuration.
Integrated monitoring results into the ticketing system (Omnitracker).
Trainee - IT Specialist / System Integration
rku.it GmbH
Successfully replaced physical HP ProLiant file servers and HP EVA 6000 SAN systems.
Implemented a highly available Microsoft failover cluster on VMware.
Connected the new cluster to a NetApp storage system.
Performed data migration, ensuring NTFS permissions were maintained.
Configured and managed backups to guarantee data security.
IT Support Intern
R.iT GmbH
Provided 1st and 2nd level support for end users.
Administered and maintained Microsoft Small Business Server for multiple clients.
Diagnosed and resolved issues in real time to ensure smooth operations.
Coordinated support tasks while meeting SLAs and KPIs.
Summary
My focus is on migrating and transforming complex enterprise infrastructures in hybrid and multi-cloud environments – especially in designing, building, and operating automated AWS multi-account landing zones, conducting Well-Architected Reviews, as well as migrating and integrating demanding End User Computing (EUC) workloads like AppStream 2.0, WorkSpaces, Azure Virtual Desktop, and Nutanix Frame.
I bring deep expertise in identity and access management (IAM) integration, zero-trust architectures, Kubernetes, infrastructure as code (IaC), CI/CD pipelines, and comprehensive automation.
In cloud security and compliance, I can point to extensive project experience with frameworks like BSI, ISO 27001, VAIT, DORA, C5, and NIS-2, and I have successfully implemented CSPM/CNAPP, SIEM, and DevSecOps processes and sustainably established operational security measures.
I rely on secure IT and cloud architecture, automated infrastructure, and the reliable, compliant operation of distributed cloud and End User Computing services with VDI technologies.
Skills
- Aws Multi-account Architecture And Governance: Concept Development, Building, And Consolidated Operations Of Scalable Landing Zones With Aws Control Tower, Organizations, Transit Gateway, Direct Connect, And Account Factory For Terraform (Aft). Development And Implementation Of Automated Governance Policies For Secure And Compliant Management Of Complex Multi-account Environments, As Well As Automation Of Recurring Operational Tasks.
- Cloud Security And Compliance: Implementation And Continuous Optimization Of Security And Compliance Frameworks By Integrating Securityhub, Guardduty, Aws Inspector, As Well As Cspm Solutions Such As Tenable, Sentinelone, Singularity Platform, And Wiz. Execution Of Measures In Line With Bsi, Bait, Vait, And Pci Requirements, Building Siem Integrations For Monitoring And Analyzing Security Events, And Establishing Best Practices In Cloud Security Management.
- Infrastructure Automation And Devops: Development And Operation Of Terraform-based Infrastructure Workflows, Implementation Of Iac Pipelines Using Azure Devops, Github Enterprise, And Gitlab, As Well As Integration Of Automated Security And Quality Checks (Sast/dast Via Trivy, Tfscan, Tflint, Snyk Security, Etc.). Building And Optimizing Ci/cd Processes For Efficient, Consistent Deployments, And Maintaining Automated Server Image Pipelines For Reproducible Environments.
- Kubernetes And Container Operations: Running And Managing Containerized Workloads With Eks/ecs, Including Governance And Separation Of Dev, Test, And Prod Environments. Implementing Monitoring, Staging, And Observability Solutions For Stable And Productive Container Environments, As Well As Automations For Deployment And Scaling.
- End User Computing & Identity: Planning, Implementing, And Securing Microsoft 365 Tenants Including Entra Id, Active Directory Security, Microsoft 365 Tenant Management, And Intune Integration. Executing Complex Migration Projects For End User Computing Platforms Such As Workspaces, Appstream, And Azure Virtual Desktop And Nutanix Frame To Modernize And Secure Digital Work Environments.
- Shift-left Security & Devsecops Transformation: Implementing A Company-wide Shift-left Approach To Integrate Security Early Into Development And Deployment Processes, Enabling Developers To Conduct Security Checks Independently, And Sustainably Reducing Vulnerabilities Before Production (Ide Integrations, Pre-commit Hooks, Local Scanners).
- Software Supply Chain Security: Analyzing And Mitigating Supply Chain Risks In Npm- And Yarn-based Applications Through Dependency Audits, Securing Ci/cd Pipelines, Token Rotation, And Restricting Risky Build And Lifecycle Mechanisms.
- Frontend & Framework Security (React/next.js): Security Assessment And Coordination Of Remediation For Critical Vulnerabilities In All Platform Applications And Web Frameworks, Including Alignment And Additional Technical Mitigations With All Teams Following Bsi Warnings.
- Software Composition Analysis (Sca): Implementing And Operating Automated Vulnerability Scans For Container Images, Pipelines/artifacts, And Third-party Dependencies, Including Sbom Exports Within Ci/cd Pipelines.
- Sast/dast Integration: Designing And Piloting Static And Dynamic Application Security Tests In Close Cooperation With Security Architecture And Development Teams To Continuously Improve Code And Runtime Security, And Establishing Operational Acceptance Tests (Bats).
- Artifact & Registry Consolidation: Analyzing And Consolidating All Package And Container Repositories For Service Applications And Aks Workloads With The Goal Of A Centralized, Secured Registry Strategy, Including Centralized Vulnerability Scanning And Governance.
- Dependency Track & Sbom Strategy: Advising The Compliance Board On Implementing A Central Sbom And Vulnerability Management Platform To Increase Enterprise-wide Dependency Transparency And Accelerate Cve Response Times.
- Ci/cd Pipeline Hardening: Security Analysis And Cleanup Of The Existing Pipeline Landscape By Removing Unused Pipelines, Improving Secrets Hygiene, Enforcing The Least Privilege Principle, And Isolating Build Agent Environments.
- Openshift (Ocp) Security Reviews: Security Assessment Of Code Baselines, Build Pipelines, And Deployment Processes For On-premises Openshift Clusters Running Critical Applications, As Well As Deriving Concrete Hardening Recommendations.
- Azure Web Application Firewall (Waf) Optimization: Analyzing And Optimizing Existing Azure Waf Rule Sets (Owasp Top 10 Core Rule Set, Dsr/sdc, Custom Rules) To Defend Against Known Vulnerabilities And Exploit Patterns, Including Reducing False Positives And Improving Threat Detection.
- Documentation & Stakeholder Communication: Creating And Maintaining Technical Documentation, Runbooks, And Architecture Diagrams In Jira And Confluence, As Well As Actively Transferring Knowledge Between Operations, Development, Security, And Compliance Stakeholders.
- Aws Multi-account Landing Zones/azure Landing Zones
- It & Cloud Security | Compliance And Governance
- Terraform And Devops Automation
- Devsecops Automation And Developer Experience (Dx)
- Kubernetes And Microservice Architectures And Ci/cd Processes
- Identity And Access Management In Hybrid And Multi-cloud Contexts
- Modern Digital Workplace In Euc Contexts With Vdi Technologies
- Leading It Operations And Carrying Out Large-scale Cloud Migrations
Languages
Education
IHK Bochum / rku.IT GmbH
IT Specialist – System Integration · 2
IT Specialist - System Integration
Certifications & licenses
AWS Certified AI Practitioner
AWS Certified Machine Learning Engineer – Associate
AWS Certified Advanced Networking – Specialty
AWS Certified DevOps Engineer – Professional
AWS Certified Developer – Associate
AWS Certified Security – Specialty
AWS Certified Solutions Architect – Professional
HashiCorp Certified: Terraform Associate
Microsoft Certified: Azure AI Fundamentals
Microsoft Certified: Azure Solutions Architect Expert
AWS Certified Cloud Practitioner
AWS Certified Solutions Architect Associate
AWS Certified SysOps Administrator – Associate
LaceWork Shield Certified - Associate CSPM/CNAPP
Microsoft Certified: Azure Administrator Associate
Microsoft Certified: Azure Developer Associate
Microsoft Certified: Azure Virtual Desktop Specialty
Microsoft Certified: CyberSecurity Architect Expert
Microsoft Certified: Identity And Access Administrator Associate
Microsoft 365 Certified: Modern Desktop Administrator Associate
Microsoft Certified: Azure Fundamentals
ITIL® V4 Foundation Certificate
Microsoft Certified Professional (MCP)
Microsoft Certified Solutions Associate: (MCSA) Windows Server
Citrix Certified Associate - Virtualization (CCA-V)
Microsoft Certified Technology Specialist (MCTS)
Similar Freelancers
Discover other experts with similar qualifications and experience