DevOps & Cloud Platform Engineering
Terraform · Azure · Kubernetes · GitOps · CI/CD · Observability
I am a System Engineer moving into DevOps and Platform Engineering roles. I build small, reproducible platforms that make infrastructure changes, delivery controls and recovery paths inspectable through code, tests, CI evidence and runbooks.
My background combines systems integration with International Information Systems (B.Sc.). I am looking for a full-time DevOps, Cloud Platform or Infrastructure Automation role around Augsburg, hybrid in Munich or remote across Germany.
- Azure Platform IaC
Terraform, AzureRM v5, secretless GitHub OIDC, policy tests, security scans and a protected apply path. - GitOps Platform Lab
Kubernetes Desired State, Argo CD reconciliation, Kustomize overlays, SLOs, observability and a tested recovery exercise. - Incident Automation Lab
Prometheus, Grafana, Loki and OpenTelemetry signals correlated into explainable, approval-safe incident triage. - Azure & Microsoft 365 Tenant Guard
Read-only inventory, deterministic governance checks, evidence exports and approval-gated remediation.
| Capability | Inspectable evidence |
|---|---|
| Infrastructure as Code | Terraform modules, native policy tests, AzureRM contracts and documented teardown |
| CI/CD controls | Pull-request verification, security scans, OIDC plan identities and protected manual apply |
| Platform operations | Kubernetes, Kustomize, Argo CD self-healing and Git-based drift recovery |
| Observability | Prometheus metrics, Grafana dashboards, Loki logs, OpenTelemetry traces and SLO burn rates |
| Reliability | Failure injection, runbooks, recovery exercises and explicit production boundaries |
| Supply-chain safety | CodeQL, Trivy, Checkov, dependency audits, SHA-pinned actions and SPDX SBOMs |
- Git records the intended state; automation makes changes reviewable and repeatable.
- Short-lived identity and least privilege replace long-lived cloud credentials.
- Read-only discovery comes before any approval-gated change.
- Tests, execution captures and runbooks turn a demo into operational evidence.
- Limitations stay visible. These public labs do not claim customer or production-cluster usage.
Additional work is available in the engineering portfolio, including data quality automation, a private-AI platform lab and product engineering across Swift, Go and Cloudflare Workers.



