N
nvimq's photo
Nurdaulet Bolat
From Netherlands
$50/hr or $120,000/yr

Active 8 hours ago


Share this profile:

Senior DevSecOps & Platform Engineer

DevOps Engineer
Available for hire
Years of experience
8+ years
Experience level
Senior

I have been designing and building secure cloud architectures, Kubernetes platforms, and CI/CD pipelines for over 8 years. I have achieved significant improvements in system resiliency for EU-regulated FinTechs and SaaS platforms, including 99.99% uptime, 40% faster deployment frequencies, and major reductions in cloud spend. I am looking for remote B2B contracts where I can help engineering teams scale their infrastructure reliably. What sets me apart is my deep focus on GitOps and DevSecOps: I don't just provision infrastructure; I embed policy-as-code (Kyverno/OPA), dynamic secrets (Vault), and strict security controls directly into the developer workflow from day one.

Employment History

Senior Site Reliability Engineer (DevSecOps) at nvimq Current 2023 - Now
Engagement via nvimq (own consultancy). Client name under NDA - EU-regulated FinTech platform, 15 EKS clusters, PCI-DSS scope. • Pioneered the transition to a GitOps operating model using ArgoCD and Vault dynamic secrets (Entra ID SSO integration). Built secure, self-service CI/CD "Golden Paths" that cut developer onboarding from 3 weeks to 1 week and accelerated deployment frequency by 40%. • Architected a multi-account AWS Landing Zone with strict SCPs, reducing privilege-escalation risks by 80%. Enforced a zero-privilege policy across 15 EKS clusters by writing and deploying Kyverno admission controllers and Golang mutating webhooks to block root access and non-compliant images at deploy time. • Eliminated 120+ hours of manual audit toil per cycle by engineering Python/Go automation that pulls evidence directly from AWS and GitLab APIs for SOC2 continuous compliance. Embedded Trivy, SonarQube, and Gitleaks into shift-left pipelines to intercept 95% of vulnerabilities pre-production. • Championed a symptom-based alerting culture (SLI/SLO) via Prometheus/Grafana, targeting a 99.99% success rate for critical transaction APIs. Led P1 incident response during a cascading OOMKilled failure across EKS; contained the blast radius via rapid HPA scaling, subsequently introducing automated rollbacks on failed health checks. • Conducted deep audits of Kubernetes resource requests/limits and decommissioned orphaned assets across 8 AWS accounts, slashing monthly cloud spend by 25% (~$12,000/mo).
DevOps & Infrastructure Engineer at nvimq 2020 - 2022
Engagement via nvimq (own consultancy). Clients under NDA: 12 client environments, 45+ production services, 200+ nodes. • Cut environment provisioning time from days to under 2 hours across 12 major client environments by developing modular Terraform/Terragrunt architectures and robust Ansible playbooks. • Designed advanced deployment strategies (blue-green and rolling updates) in GitLab CI and Jenkins, enabling safe, multiple-times-a-day releases for 45+ production services with zero downtime. • Deployed a centralized observability stack (Splunk, Prometheus, Grafana) across 200+ production nodes. Reduced MTTR by 45% by replacing noisy, CPU-based triggers with user-centric, SLO-driven alerts and actionable on-call runbooks. • Narrowed the unpatched CVE exposure window to under 48 hours by automating CIS Benchmark compliance scans and patch management pipelines for base Linux AMIs and Docker images.
Linux System & Infrastructure Engineer at nvimq 2018 - 2020
Engagement via nvimq (own consultancy). Client under NDA: European managed cloud provider, 100+ bare-metal nodes. • Architected and maintained a highly available bare-metal and virtualized infrastructure fleet (100+ nodes), achieving 99.9% uptime for core client services. • Engineered high-throughput reverse proxy architectures (Nginx/HAProxy) scaling to handle 10,000+ RPS, alongside deep network hardening via custom iptables and VPN topologies. • Spearheaded the modernization of legacy monolithic workloads by driving a large-scale migration into Docker-based containerized environments, laying the groundwork for a complete microservices transition. • Eliminated massive operational toil by engineering robust Bash and Python automation suites for system provisioning, disaster recovery (backups), and log lifecycle management.

Education

Bachelor of Scienc at University of Amsterdam Current 2018 - Now