Available for projects · Q3 2026

I build cloud platforms
that ship.

Artem Kozlenkov — Multi-Cloud Platform Engineer. I design platform foundations: Azure Landing Zones, cloud networking & security, identity & access, and application runtimes (Kubernetes, serverless, containers) across Azure, AWS, and GCP.

8+
years of platform engineering
60%
faster deployment times
AK
Artem Kozlenkov
// Switzerland · Hybrid/Remote
01

Selected work

platform engineering, shipped

Senior Cloud Engineer

Current

Zühlke Engineering AGSchlieren, Zürich

Aug 2025 – Present

Designing and operating secure multi-cloud platforms (Azure, AWS, GCP) for enterprise customers — from architecture through daily operations, including on-premises-to-cloud migrations and cloud-native modernization of containerized applications with zero downtime.

  • Architect Azure Landing Zones using Cloud Adoption Framework (CAF) with Terraform — management group hierarchy, subscription governance, RBAC, and Azure Policy guardrails
  • Implement Policy-as-Code with Azure Policy and Terraform for continuous compliance enforcement across platform resources
  • Drive on-premises-to-cloud migrations and cloud-native modernization of containerized applications — each with zero downtime
  • Automate operations and CI/CD with GitHub Actions, Azure DevOps, and Jira, cutting manual deployment cycles from ~45 minutes to under 10 minutes
  • Cut infrastructure provisioning time by 40% through reusable, versioned Terraform modules
  • Establish observability, performance, and monitoring practices, improving average time-to-resolution by ~25%
  • Lead 2 VCS platform migrations and container workload transitions; resolved 50+ security audit findings via code and architecture reviews
  • Design and deploy GCP platform environments focusing on GKE Kubernetes runtime, VPC networking, Cloud NAT, firewall rules, and IAM security policies
AzureTerraformAKSArgoCDAzure DevOpsGitHub ActionsJiraGCPGKEGCP NetworkingGCP IAMCAF

Senior Cloud Engineer

Glencore AGBaar, Zug

Dec 2023 – Aug 2025

Delivered enterprise-scale Azure platform governance, networking, and identity solutions for a global commodity trading organization.

  • Implemented Azure Policy-as-Code with Terraform and GitLab CI/CD, automating enforcement of 100+ governance and compliance policies across the entire tenant — custom policy definitions, initiative assignments, and exemption workflows
  • Designed private networking architecture for Azure Databricks and Azure AI Foundry — VNet injection, Private Link, DNS resolution, and network security groups
  • Automated Azure Private DNS zone management with Terraform and Python — multi-subscription DNS resolution, conditional forwarding, and private endpoint integration, cutting manual DNS work by ~80%
  • Reduced onboarding time for new environments by ~60% by operating Azure landing zones and secure PaaS platforms with reusable Terraform modules
  • Led development of 40+ Terraform modules and IaC standards; managed 15+ epics/releases in a SAFe-like setup
  • Coached and onboarded 6 new colleagues and established consistent code review and DevOps practices
  • Implemented Azure RBAC strategy with custom role definitions, PIM for just-in-time access, and managed identity integration for workload authentication
  • Designed key vault architecture for secrets management with soft-delete, purge protection, and private endpoint access patterns
AzureTerraformGitLab CI/CDAzure PolicyAzure DatabricksPythonGitHub ActionsPrivate LinkKey VaultRBAC

Senior Cloud Engineer

V-Zug AGZug

Aug 2022 – Nov 2023

Designed Azure IoT platform architectures and managed containerized application runtimes at scale with GitOps delivery.

  • Designed Azure IoT architectures with Java Spring Boot microservices and device models for several thousand connected devices
  • Operated containerized services on AKS with Helm, CI/CD, and GitOps, achieving 99.9% availability of the core platform
  • Built telemetry pipelines with IoT Hub, Event Hubs, Azure Functions, and Databricks processing several million messages daily
  • Implemented comprehensive security controls across the platform: X.509/TLS certificate lifecycle, PKI infrastructure, RBAC, VNet isolation, and Private Link for PaaS services
  • Configured Azure Container Registry with geo-replication, vulnerability scanning, and image trust policies for a secure container supply chain
  • Wrote 25+ Terraform modules for repeatable IaC and security/network controls, significantly increasing the Defender Secure Score
  • Configured monitoring, alerting, autoscaling, and chaos testing, reducing incident detection and response time by ~40%
Azure IoTAKSHelmAzure DevOpsTerraformKubernetesGrafanaPrometheusAzure FunctionsEvent HubsContainer Registry

Cloud Platform Engineer

Go-E GmbHBerlin, Germany

Sep 2021 – Aug 2022

Operated Java Spring Boot microservices on AWS EKS for 15+ customer systems with service mesh and GitOps platform delivery.

  • Operated Java Spring Boot microservices on Amazon EKS for 15+ customer systems, with gRPC and AWS App Mesh service mesh for service-to-service communication
  • Automated AWS platform infrastructure with Terraform — VPC, subnets, IAM roles, security groups, EKS cluster configuration, and node group management
  • Built GitLab CI/CD pipelines with Amazon ECR and ArgoCD for GitOps-driven platform deployments including Helm chart automation
  • Managed Kubernetes workloads with Helm charts, custom operators, and horizontal pod autoscaling based on custom metrics
  • Set up platform observability with CloudWatch, Prometheus/Grafana dashboards, and OpenTelemetry distributed tracing
  • Managed multi-cloud cost governance across Azure and AWS — resource tagging, budget alerts, and cost allocation reporting
  • Created AWS Service Catalog offerings with standardized infrastructure products for self-service platform consumption
AWS EKSTerraformJava Spring BootArgoCDgRPCGitLab CI/CDGrafanaCloudWatchHelmApp Mesh

Cloud DevOps Engineer

Foxbase GmbHDüsseldorf, Germany

Jul 2020 – Aug 2021

Operated and optimized AWS platform infrastructure for 20+ customer environments with IaC, networking, and Kubernetes governance.

  • Operated and optimized AWS cloud platform for 20+ customer environments with Terraform IaC — multi-account VPC design, IAM policies, S3 storage, and EC2 compute
  • Architected VPC networking, security groups, NACLs, and subnet segmentation for multi-tier application isolation
  • Implemented Kubernetes governance patterns on EKS — RBAC, namespace isolation, resource quotas, and network policies
  • Set up centralized monitoring platform with CloudWatch alarms, log aggregation, and Grafana visualization dashboards
  • Automated CI/CD pipelines and established cloud DevOps standards, runbooks, and best practices for platform operations
AWSTerraformKubernetesGrafanaCloudWatchGitLab CI/CDEC2VPC

Backend Engineer

Q.One GmbHEssen, Germany

May 2018 – May 2020

Architected containerized backend services and established CI/CD platform practices for development teams.

  • Architected Java Spring and PHP Symfony microservices deployed as containerized workloads on Kubernetes — 30+ workloads in production
  • Established automated CI/CD pipeline platform using GitLab CI for build, test, and deployment workflows
  • Containerized services with Docker — multi-stage builds, image optimization, and private registry management
  • Configured Kubernetes application runtime with Deployment, Service, Ingress, ConfigMap, and Secret resources
  • Practiced test-driven development with 85% code coverage across the codebase
  • Implemented application performance monitoring with Prometheus metrics, Grafana dashboards, and CloudWatch log analysis
JavaPHPDockerKubernetesPrometheusGrafanaGitLab CI/CDCloudWatch

Backend Engineer

FreelanceKyiv, Ukraine

2014 – 2017

Developed Java OSGi backend modules, administered Linux servers, and automated the infrastructure lifecycle.

  • Developed Java OSGi backend modules for enterprise service platforms
  • Administered Linux servers and built an automated infrastructure lifecycle management system
JavaOSGiLinux
02

Stack

core platforms, tools, and supporting tech

Platform foundations: Landing Zones · Networking · Identity · K8s · Serverless — Azure primary, multi-cloud by design.

Azure Platform & Landing Zones★ primary
Azure Landing Zones (CAF)Management Groups & SubscriptionsAzure Kubernetes Service (AKS)Azure Policy & BlueprintsAzure App Service & FunctionsAzure Container AppsAzure DevOps & ReposAzure Monitor & Log AnalyticsAzure Event Hub / IoT HubEvent Grid / Service Bus
Application Runtime Environments★ primary
Kubernetes (AKS / EKS / GKE)Docker & Container RuntimesServerless Functions (Azure / AWS)Azure Container AppsHelm / KustomizeService Mesh (Istio / App Mesh)GCP Cloud RunKnative / KEDA AutoscalingNginx
Cloud Networking★ primary
Azure VNets, Subnets & PeeringAzure Firewall & Application GatewayPrivate Link & Private DNSAzure VPN Gateway & ExpressRouteAWS VPC, Subnets & Transit GatewayGCP VPC, Cloud NAT & Private AccessDNS Management (Azure / Route53 / Cloud DNS)Load Balancers & Traffic Manager
Identity & Access Management
Azure AD / Entra IDRBAC & Custom RolesManaged Identities & Service PrincipalsConditional Access & PKIAWS IAM Roles & PoliciesGCP IAM & Service AccountsKey Vault / Secrets ManagementHashicorp VaultX.509 / TLS Certificate Lifecycle
Security & Compliance
Azure Policy & Defender for CloudNetwork Security Groups (NSG / ASG)Azure Firewall & WAFEncryption at Rest & in TransitISO 27001 / NIS2 ComplianceSecurity Posture & Vulnerability MgmtGitleaks & Secret Scanning
IaC & Policy-as-Code★ primary
Terraform (HCL)BicepAzure Policy (JSON / ARM)ARMAnsibleAzure AutomationCloud Adoption Framework (CAF)Terragrunt / TerramatePackerAWS CloudFormation / CDK
DevOps & GitOps★ primary
Azure DevOpsGitHub ActionsGitLab CI/CDArgoCDHelm / Kustomize / FluxJenkinsJira
Programming & Scripting
PythonGoBash / PowerShellTypeScript / JavaScriptJava / SpringPHP / SymfonyLinux (Ubuntu/RHEL)WSL2Pytest / Selenium
Monitoring & Observability
Azure Monitor / Log AnalyticsGrafana / PrometheusApplication InsightsDefender for CloudCloudWatch & CloudTrailELK StackOpenTelemetry
Multi-Cloud & Hybrid
Azure (Expert)AWS (Proficient)GCP (Working Knowledge)On-Premise / Hybrid ConnectivityMulti-Cloud Governance & Cost Mgmt
Data & AI
Azure OpenAIAzure AI FoundryAzure MLAzure SearchAzure DatabricksAWS BedrockAWS SageMakerGoogle Vertex AIGeminiAzure SQL / Cosmos DBPostgreSQLRedis
03

Let's build

Have a project or opportunity? Let's talk.