I build cloud platforms
that ship.
Artem Kozlenkov — Multi-Cloud Platform Engineer. I design platform foundations: Azure Landing Zones, cloud networking & security, identity & access, and application runtimes (Kubernetes, serverless, containers) across Azure, AWS, and GCP.
Selected work
platform engineering, shipped
Senior Cloud Engineer
CurrentZühlke Engineering AG — Schlieren, Zürich
Designing and operating secure multi-cloud platforms (Azure, AWS, GCP) for enterprise customers — from architecture through daily operations, including on-premises-to-cloud migrations and cloud-native modernization of containerized applications with zero downtime.
- Architect Azure Landing Zones using Cloud Adoption Framework (CAF) with Terraform — management group hierarchy, subscription governance, RBAC, and Azure Policy guardrails
- Implement Policy-as-Code with Azure Policy and Terraform for continuous compliance enforcement across platform resources
- Drive on-premises-to-cloud migrations and cloud-native modernization of containerized applications — each with zero downtime
- Automate operations and CI/CD with GitHub Actions, Azure DevOps, and Jira, cutting manual deployment cycles from ~45 minutes to under 10 minutes
- Cut infrastructure provisioning time by 40% through reusable, versioned Terraform modules
- Establish observability, performance, and monitoring practices, improving average time-to-resolution by ~25%
- Lead 2 VCS platform migrations and container workload transitions; resolved 50+ security audit findings via code and architecture reviews
- Design and deploy GCP platform environments focusing on GKE Kubernetes runtime, VPC networking, Cloud NAT, firewall rules, and IAM security policies
Senior Cloud Engineer
Glencore AG — Baar, Zug
Delivered enterprise-scale Azure platform governance, networking, and identity solutions for a global commodity trading organization.
- Implemented Azure Policy-as-Code with Terraform and GitLab CI/CD, automating enforcement of 100+ governance and compliance policies across the entire tenant — custom policy definitions, initiative assignments, and exemption workflows
- Designed private networking architecture for Azure Databricks and Azure AI Foundry — VNet injection, Private Link, DNS resolution, and network security groups
- Automated Azure Private DNS zone management with Terraform and Python — multi-subscription DNS resolution, conditional forwarding, and private endpoint integration, cutting manual DNS work by ~80%
- Reduced onboarding time for new environments by ~60% by operating Azure landing zones and secure PaaS platforms with reusable Terraform modules
- Led development of 40+ Terraform modules and IaC standards; managed 15+ epics/releases in a SAFe-like setup
- Coached and onboarded 6 new colleagues and established consistent code review and DevOps practices
- Implemented Azure RBAC strategy with custom role definitions, PIM for just-in-time access, and managed identity integration for workload authentication
- Designed key vault architecture for secrets management with soft-delete, purge protection, and private endpoint access patterns
Senior Cloud Engineer
V-Zug AG — Zug
Designed Azure IoT platform architectures and managed containerized application runtimes at scale with GitOps delivery.
- Designed Azure IoT architectures with Java Spring Boot microservices and device models for several thousand connected devices
- Operated containerized services on AKS with Helm, CI/CD, and GitOps, achieving 99.9% availability of the core platform
- Built telemetry pipelines with IoT Hub, Event Hubs, Azure Functions, and Databricks processing several million messages daily
- Implemented comprehensive security controls across the platform: X.509/TLS certificate lifecycle, PKI infrastructure, RBAC, VNet isolation, and Private Link for PaaS services
- Configured Azure Container Registry with geo-replication, vulnerability scanning, and image trust policies for a secure container supply chain
- Wrote 25+ Terraform modules for repeatable IaC and security/network controls, significantly increasing the Defender Secure Score
- Configured monitoring, alerting, autoscaling, and chaos testing, reducing incident detection and response time by ~40%
Cloud Platform Engineer
Go-E GmbH — Berlin, Germany
Operated Java Spring Boot microservices on AWS EKS for 15+ customer systems with service mesh and GitOps platform delivery.
- Operated Java Spring Boot microservices on Amazon EKS for 15+ customer systems, with gRPC and AWS App Mesh service mesh for service-to-service communication
- Automated AWS platform infrastructure with Terraform — VPC, subnets, IAM roles, security groups, EKS cluster configuration, and node group management
- Built GitLab CI/CD pipelines with Amazon ECR and ArgoCD for GitOps-driven platform deployments including Helm chart automation
- Managed Kubernetes workloads with Helm charts, custom operators, and horizontal pod autoscaling based on custom metrics
- Set up platform observability with CloudWatch, Prometheus/Grafana dashboards, and OpenTelemetry distributed tracing
- Managed multi-cloud cost governance across Azure and AWS — resource tagging, budget alerts, and cost allocation reporting
- Created AWS Service Catalog offerings with standardized infrastructure products for self-service platform consumption
Cloud DevOps Engineer
Foxbase GmbH — Düsseldorf, Germany
Operated and optimized AWS platform infrastructure for 20+ customer environments with IaC, networking, and Kubernetes governance.
- Operated and optimized AWS cloud platform for 20+ customer environments with Terraform IaC — multi-account VPC design, IAM policies, S3 storage, and EC2 compute
- Architected VPC networking, security groups, NACLs, and subnet segmentation for multi-tier application isolation
- Implemented Kubernetes governance patterns on EKS — RBAC, namespace isolation, resource quotas, and network policies
- Set up centralized monitoring platform with CloudWatch alarms, log aggregation, and Grafana visualization dashboards
- Automated CI/CD pipelines and established cloud DevOps standards, runbooks, and best practices for platform operations
Backend Engineer
Q.One GmbH — Essen, Germany
Architected containerized backend services and established CI/CD platform practices for development teams.
- Architected Java Spring and PHP Symfony microservices deployed as containerized workloads on Kubernetes — 30+ workloads in production
- Established automated CI/CD pipeline platform using GitLab CI for build, test, and deployment workflows
- Containerized services with Docker — multi-stage builds, image optimization, and private registry management
- Configured Kubernetes application runtime with Deployment, Service, Ingress, ConfigMap, and Secret resources
- Practiced test-driven development with 85% code coverage across the codebase
- Implemented application performance monitoring with Prometheus metrics, Grafana dashboards, and CloudWatch log analysis
Backend Engineer
Freelance — Kyiv, Ukraine
Developed Java OSGi backend modules, administered Linux servers, and automated the infrastructure lifecycle.
- Developed Java OSGi backend modules for enterprise service platforms
- Administered Linux servers and built an automated infrastructure lifecycle management system
Stack
core platforms, tools, and supporting tech
Platform foundations: Landing Zones · Networking · Identity · K8s · Serverless — Azure primary, multi-cloud by design.
Let's build
Have a project or opportunity? Let's talk.