DevOps & Platform Engineer

Talha

Multi-Cloud Infrastructure • KubernetesProduction Reliability

DevOps & Platform Engineer operating across multi-account AWS, Kubernetes (EKS), Terraform, and GitOps for high-scale distributed systems worldwide.

37+
multi-cloud & AWS accounts managed
3+
years building platform systems
80%
faster automated CI/CD runs
99.99%
production platform uptime

A selection of production-tested cloud platforms, GitOps architectures, and open-source systems.

CI/CD Automation Platform

End-to-end automated CI/CD platform using GitHub Actions to automate builds, container testing, and multi-environment deployments.

Features automated linting, containerized testing (Postgres + Redis), Trivy vulnerability scanning, ECR push, and staging-to-production manual approval gates supporting 100+ monthly builds.

GitHub ActionsDockerKubernetesCI/CDTrivySlack Alerts
View Repository
Grafana LGTM Observability Stack

Centralized production telemetry pipeline unifying logs, metrics, distributed traces, and continuous profiling for cloud-native workloads.

Combines Grafana, Loki, Mimir, Tempo, Alloy collector, and Prometheus to correlate telemetry across microservices from a single observability pane of glass.

GrafanaLokiMimirTempoAlloyPrometheusDistributed Tracing
View Repository
Enterprise Multi-Account AWS Landing Zone

Production multi-account cloud platform supporting distributed enterprise workloads with hub-and-spoke networking topology.

Configured with AWS Transit Gateway, VPC PrivateLink endpoints, IAM least-privilege, and KMS Separation of Duties controls provisioned via modular Terraform and Terragrunt.

AWS EKSTransit GatewayPrivateLinkKMS PoliciesTerraformTerragrunt
View Repository
Kubernetes Kyverno & Pod Security Hardening

Policy-as-code admission control enforcing Pod Security Standards Restricted profile and default-deny NetworkPolicies across clusters.

Enforces non-root execution, drops Linux capabilities, isolates sensitive namespaces, and restricts egress traffic via Istio REGISTRY_ONLY configuration.

KyvernoPSS RestrictedPSANetworkPoliciesIstio EgressAmazon EKS
View Repository

Designing resilient, automated cloud infrastructure and engineering zero-trust platforms that scale quietly.

Multi-Cloud & AWS Architecture

Scalable multi-account landing zones across 37+ accounts with Amazon EKS, VPC, Transit Gateway, PrivateLink, and RDS Aurora.

AWS EKSTransit GatewayPrivateLinkAurora RDSVPC NetworkingAzure Exposure

Kubernetes Platforms & DevSecOps

Production EKS engineering with Kyverno policy enforcement, Pod Security Standards (PSS Restricted profile), and default-deny NetworkPolicies.

Amazon EKSKyvernoPSS RestrictedNetworkPoliciesHelmKEDA

Istio & Egress Network Security

Controlling service mesh traffic, migrating unrestricted ALLOW_ANY outbound traffic to REGISTRY_ONLY allow-lists via ServiceEntries and VPC endpoints.

IstioServiceEntriesEgress GatewayVPC EndpointsSecurity Groups

GitOps & CI/CD Delivery Acceleration

Automated release pipelines cutting deployment runtime from 20m to 4m (80% faster) using GitHub Actions, ArgoCD, Jenkins, and Spacelift.

GitHub ActionsArgoCDJenkinsCircleCISpaceliftGitOps

Full Grafana LGTM Observability

Centralized telemetry reducing MTTR by ~50% across microservices through unified logs, metrics, distributed traces, and continuous profiling.

GrafanaLokiMimirTempoPyroscopeAlloyDatadog

Infrastructure as Code & Governance

Modular, version-controlled IaC using Terraform, OpenTofu, and Terragrunt with state locking, reviewable pull requests, and automated validation.

TerraformOpenTofuTerragruntAnsibleAWS SSMPython Automation
Cloud
AWS (EKS, EC2, ECS, VPC, IAM, S3, RDS Aurora, ElastiCache, Route53, CloudWatch, Transit Gateway, PrivateLink)Azure (Exposure)
Kubernetes
KubernetesAmazon EKSHelmDockerArgoCDKEDACluster AutoscalerIstio Service MeshKyvernoNetworkPoliciesPod Security Standards (PSS/PSA)
IaC & Tools
TerraformOpenTofuTerragruntAnsibleCloudFormationAWS Systems Manager (SSM)Bash ScriptingPython Automation
CI / CD
GitHub ActionsJenkinsCircleCIAWS CodePipelineSpaceliftArgoCD (GitOps)GitLab CI/CD Concepts
Observability
GrafanaLokiMimirTempoPyroscopeAlloyPrometheusAWS CloudWatchDatadogSentry
Security
AWS IAM (Least Privilege)KMS Policies (Separation of Duties)Kyverno Policy EnforcementPod Security Standards (Restricted)securityContext HardeningDefault-Deny NetworkPoliciesVPC Security, Security Groups & NACLs
Systems & OS
Linux (Ubuntu, CentOS)DNS & NetworkingSystem Performance AnalysisWindows & PowerShell Exposure
Architecture & AI
Cloud Infrastructure DesignHigh/Low-Level Technical Design (HLD/LLD)REST API SecurityMicroservices ArchitectureAI-Assisted TroubleshootingCursor, GitHub Copilot, Claude & MCP Concepts

I build reliable, automated, and self-healing cloud platforms. My work sits at the foundation: designing resilient multi-cloud architectures, eliminating operational toil, and leaving systems resilient against failure.

Operating Model

Remote · Working Worldwide

Distributed cloud collaboration

Credentials

AWS Solutions Architect & DevOps

BS Software Engineering (UMT)

Platform Core

Multi-Cloud, AWS & Amazon EKS

Zero-Trust Security & GitOps Delivery

Execution Standard

Understand existing environments, design practical solutions, automate via IaC, and validate in staging before production.

Security Mindset

Separation of Duties, IAM least-privilege, Kyverno admission policies, and default-deny network controls.

Reliability Standard

Correlated telemetry across logs, metrics, and traces with automated GitOps rollback workflows.

Have infrastructure worth automating or scaling?

Send architectural requirements, platform challenges, or current codebases. I collaborate with engineering teams worldwide and respond with practical next steps.

talha@devistio.com

Remote · Working Worldwide · +92 315 6569204