CNCF Kubestronaut. Souveräne, sichere Kubernetes-Plattformen ? Plattform-Engineering und DevSecOps.
Aktualisiert am 11.06.2026
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 11.06.2026
Verfügbar zu: 100%
davon vor Ort: 100%
Kubernetes
DevSecOps
Cloud Architect
Sovereign Cloud
Cloud Native
Cloud Engineer
Linux
Helm
Terraform
GitOps
GitLab
CI/CD
DevOps
Keycloak
AWS
Prometheus
Cilium
ArgoCD
Crossplane
Docker
Grafana
Rancher
Air-Gapped
German
Full Professional
English
Full Professional
Arabic
Full Professional
Persian
native
Estonian
limited

Einsatzorte

Einsatzorte

3544 Eisenberg (+50km) Jena (+50km)
Deutschland
möglich

Projekte

Projekte

2025 - today: Independent Kubernetes and Cloud Native consultancy ? sovereign, secure, open-source infrastructure

Customer: (on request), Eisenberg (Germany)
Role: Founder & Cloud Native Consultant

Tasks:
Architected and delivered a greenfield production Kubernetes platform for an international SaaS client on AWS/EKS, owning the end-to-end design across GitOps delivery (ArgoCD), identity (Keycloak), secure networking (WireGuard) and observability (Prometheus/Grafana), with infrastructure-as-code in OpenTofu and Ansible, and took the client from zero to production-ready

2021 - 2025: various

Customer: CLARK SE, Frankfurt (Germany)

Tasks:
  • 2023 - 2025 - Senior Platform Engineer
    • Drove the internal EKS platform as a product, running weekly open consulting hours, demos and change announcements that scaled adoption to ~100 engineers across a dozen international teams
    • Designed and extended the platform with custom operators, CRDs and Crossplane, enabling self-service infrastructure provisioning for application teams and standardizing GitOps delivery across GitHub Actions, Jenkins and CircleCI
    • Hardened the software supply chain with External Secrets, Trivy, Cosign, Renovate and Dependabot, and cut CI/CD pipeline times by over 30% through build-cache optimization and Rails deployment changes
    • Designed an automated lifecycle and cost-optimization system for preview environments (configurable TTLs, automatic cleanup, off-hours scaledown), replacing a manual process and meaningfully reducing non-production cloud spend
  • 2021 - 2022 - Senior Software Engineer, Enablement Team
    • Maintained and evolved core shared services for stream-aligned product teams, and defined the microservice blueprints that standardized how new services were scaffolded, with CI, deployment and observability built in
    • Redesigned the local development environment around containerized, reproducible workflows, replacing a brittle machine-dependent setup with consistent onboarding across teams

2019 - 2021: Development and integration of a GDPR-compliant anonymization library

Customer: Hüttig & Rompf AG, Frankfurt (Germany)
Role: Software Engineer

Tasks:
  • Designed and integrated a GDPR anonymization library into a large legacy Rails system covering personal, financial, and regulated customer data, and built internal API abstractions that normalized and aggregated data from bank, creditor, and financial service APIs for financing recommendation logic
  • Introduced automated CI/CD pipelines on GitLab and a standardized Vagrant-based developer environment, improving deployment consistency and local onboarding across the engineering team

2015 - 2019: P2PE-validated environment for cardholder data

Customer: EveryPay, Tallinn (Estonia)
Role: DevOps & Backend Engineer

Tasks:
  • Operated within a P2PE-validated cardholder data environment and worked with compliance specialists to implement and improve the transaction risk scoring engine enforcing fraud detection rules in production
  • Owned the Chef-based infrastructure-as-code layer for production AWS infrastructure (EC2, RDS, VPC, IAM, S3, CloudFormation, ELB, Route 53 and CloudWatch), ran Rails deployments with Capistrano and maintained the Vagrant-based local development environment used across the engineering team

2011 - 2015: Earlier Experience
  • Linux Systems Consultant, GBG Holding (Tehran, 2013?2015): Migrated physical infrastructure to virtualized environments, administered firewall, caching and VoIP/telecom systems, and mentored internal teams on Linux administration and security
  • Linux Engineer, Parspooyesh Fanavar (Tehran, 2011?2013): Contributed to Xamin, a custom Linux distribution for virtualization infrastructure, and deployed Linux servers for national telecom clients integrating FreeRadius, Kerberos, OpenLDAP and PostgreSQL

Aus- und Weiterbildung

Aus- und Weiterbildung

CERTIFICATIONS
  • Kubernetes: CKA, CKAD, CKS, KCNA, KCSA
  • Linux: LFCS
  • Agile: Certified ScrumMaster

Position

Position

Senior Platform Engineer & Cloud Native Architect

Kompetenzen

Kompetenzen

Top-Skills

Kubernetes DevSecOps Cloud Architect Sovereign Cloud Cloud Native Cloud Engineer Linux Helm Terraform GitOps GitLab CI/CD DevOps Keycloak AWS Prometheus Cilium ArgoCD Crossplane Docker Grafana Rancher Air-Gapped

Produkte / Standards / Erfahrungen / Methoden

PROFILE
CNCF Kubestronaut, platform engineer and architect with 15+ years across fintech, insurtech and telecom. I own the end-to-end design of secure, open-source Kubernetes platforms, from target architecture and technology selection through GitOps workflows, supply-chain controls and production rollout and stay hands-on in the cluster, on-premises, public or hybrid cloud. I set the platform standards and self-service tooling that engineering teams build on and lead platform delivery across cross-functional teams. Familiar with European sovereign-cloud initiatives, including the Apeiro Reference Architecture. Available for remote and on-site engagements across Germany and the EU.

TECHNICAL SKILLS
  • Kubernetes
    • kubeadm, Kubespray, Rancher, Gardener, Helm, Kustomize, custom Operators and CRDs, Crossplane
  • GitOps & Automation
    • ArgoCD, FluxCD, Terraform/OpenTofu, Ansible, GitLab CI, Jenkins
  • Security & Supply Chain
    • Falco, Trivy, kube-bench, OPA, Kyverno, Network Policies, Cosign, SBOM, External Secrets, Vault, Keycloak, Cert-Manager and Harbor
  • Observability
    • Prometheus, Thanos, Grafana, Loki, Fluentd, OpenTelemetry and ELK
  • Networking
    • Cilium, Gateway API, Istio, CoreDNS and WireGuard
  • Platforms
    • Bare Metal, On-Premises, AWS, Hetzner Cloud, familiar with GCP
  • Linux & Systems
    • System administration, kernel and systemd internals, networking and firewalls, storage and filesystems, virtualization and containers, performance tuning, security hardening and shell scripting
  • Programming & Data
    • ?Ruby/Rails, Go, Python, SQL, PostgreSQL, MySQL, Redis/Valkey and MongoDB

Einsatzorte

Einsatzorte

3544 Eisenberg (+50km) Jena (+50km)
Deutschland
möglich

Projekte

Projekte

2025 - today: Independent Kubernetes and Cloud Native consultancy ? sovereign, secure, open-source infrastructure

Customer: (on request), Eisenberg (Germany)
Role: Founder & Cloud Native Consultant

Tasks:
Architected and delivered a greenfield production Kubernetes platform for an international SaaS client on AWS/EKS, owning the end-to-end design across GitOps delivery (ArgoCD), identity (Keycloak), secure networking (WireGuard) and observability (Prometheus/Grafana), with infrastructure-as-code in OpenTofu and Ansible, and took the client from zero to production-ready

2021 - 2025: various

Customer: CLARK SE, Frankfurt (Germany)

Tasks:
  • 2023 - 2025 - Senior Platform Engineer
    • Drove the internal EKS platform as a product, running weekly open consulting hours, demos and change announcements that scaled adoption to ~100 engineers across a dozen international teams
    • Designed and extended the platform with custom operators, CRDs and Crossplane, enabling self-service infrastructure provisioning for application teams and standardizing GitOps delivery across GitHub Actions, Jenkins and CircleCI
    • Hardened the software supply chain with External Secrets, Trivy, Cosign, Renovate and Dependabot, and cut CI/CD pipeline times by over 30% through build-cache optimization and Rails deployment changes
    • Designed an automated lifecycle and cost-optimization system for preview environments (configurable TTLs, automatic cleanup, off-hours scaledown), replacing a manual process and meaningfully reducing non-production cloud spend
  • 2021 - 2022 - Senior Software Engineer, Enablement Team
    • Maintained and evolved core shared services for stream-aligned product teams, and defined the microservice blueprints that standardized how new services were scaffolded, with CI, deployment and observability built in
    • Redesigned the local development environment around containerized, reproducible workflows, replacing a brittle machine-dependent setup with consistent onboarding across teams

2019 - 2021: Development and integration of a GDPR-compliant anonymization library

Customer: Hüttig & Rompf AG, Frankfurt (Germany)
Role: Software Engineer

Tasks:
  • Designed and integrated a GDPR anonymization library into a large legacy Rails system covering personal, financial, and regulated customer data, and built internal API abstractions that normalized and aggregated data from bank, creditor, and financial service APIs for financing recommendation logic
  • Introduced automated CI/CD pipelines on GitLab and a standardized Vagrant-based developer environment, improving deployment consistency and local onboarding across the engineering team

2015 - 2019: P2PE-validated environment for cardholder data

Customer: EveryPay, Tallinn (Estonia)
Role: DevOps & Backend Engineer

Tasks:
  • Operated within a P2PE-validated cardholder data environment and worked with compliance specialists to implement and improve the transaction risk scoring engine enforcing fraud detection rules in production
  • Owned the Chef-based infrastructure-as-code layer for production AWS infrastructure (EC2, RDS, VPC, IAM, S3, CloudFormation, ELB, Route 53 and CloudWatch), ran Rails deployments with Capistrano and maintained the Vagrant-based local development environment used across the engineering team

2011 - 2015: Earlier Experience
  • Linux Systems Consultant, GBG Holding (Tehran, 2013?2015): Migrated physical infrastructure to virtualized environments, administered firewall, caching and VoIP/telecom systems, and mentored internal teams on Linux administration and security
  • Linux Engineer, Parspooyesh Fanavar (Tehran, 2011?2013): Contributed to Xamin, a custom Linux distribution for virtualization infrastructure, and deployed Linux servers for national telecom clients integrating FreeRadius, Kerberos, OpenLDAP and PostgreSQL

Aus- und Weiterbildung

Aus- und Weiterbildung

CERTIFICATIONS
  • Kubernetes: CKA, CKAD, CKS, KCNA, KCSA
  • Linux: LFCS
  • Agile: Certified ScrumMaster

Position

Position

Senior Platform Engineer & Cloud Native Architect

Kompetenzen

Kompetenzen

Top-Skills

Kubernetes DevSecOps Cloud Architect Sovereign Cloud Cloud Native Cloud Engineer Linux Helm Terraform GitOps GitLab CI/CD DevOps Keycloak AWS Prometheus Cilium ArgoCD Crossplane Docker Grafana Rancher Air-Gapped

Produkte / Standards / Erfahrungen / Methoden

PROFILE
CNCF Kubestronaut, platform engineer and architect with 15+ years across fintech, insurtech and telecom. I own the end-to-end design of secure, open-source Kubernetes platforms, from target architecture and technology selection through GitOps workflows, supply-chain controls and production rollout and stay hands-on in the cluster, on-premises, public or hybrid cloud. I set the platform standards and self-service tooling that engineering teams build on and lead platform delivery across cross-functional teams. Familiar with European sovereign-cloud initiatives, including the Apeiro Reference Architecture. Available for remote and on-site engagements across Germany and the EU.

TECHNICAL SKILLS
  • Kubernetes
    • kubeadm, Kubespray, Rancher, Gardener, Helm, Kustomize, custom Operators and CRDs, Crossplane
  • GitOps & Automation
    • ArgoCD, FluxCD, Terraform/OpenTofu, Ansible, GitLab CI, Jenkins
  • Security & Supply Chain
    • Falco, Trivy, kube-bench, OPA, Kyverno, Network Policies, Cosign, SBOM, External Secrets, Vault, Keycloak, Cert-Manager and Harbor
  • Observability
    • Prometheus, Thanos, Grafana, Loki, Fluentd, OpenTelemetry and ELK
  • Networking
    • Cilium, Gateway API, Istio, CoreDNS and WireGuard
  • Platforms
    • Bare Metal, On-Premises, AWS, Hetzner Cloud, familiar with GCP
  • Linux & Systems
    • System administration, kernel and systemd internals, networking and firewalls, storage and filesystems, virtualization and containers, performance tuning, security hardening and shell scripting
  • Programming & Data
    • ?Ruby/Rails, Go, Python, SQL, PostgreSQL, MySQL, Redis/Valkey and MongoDB

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.