08/02/2026 updated


100 % available
Platform & Cloud Architect | Kubernetes, Terraform | AWS GCP Azure OCI | DevOps & SRE
Sofia, Bulgaria
Worldwide
BSc Business Information Technologies, Plovdiv University Paisii HilendarskiAbout me
Sixteen years in infrastructure, ten architecting platforms inside PCI DSS and ISO scope for payment providers and banks. In regulated environments a careless fix is worse than no fix, so I move fast without improvising and document what I changed. AWS, GCP, Azure and OCI.
Argo CDGitOpsGitHub ActionsHelmKubernetes SecurityAmazon Web ServicesMicrosoft AzureCloud EngineeringVirtual Private ServersLinuxDevOpsPython (Programming Language)PostgreSQLAnsiblePrometheus
Kubernetes & Platform Engineering
Expertise in designing and operating multi-region Kubernetes estates on GKE, EKS, and AKS, including Helm, ArgoCD, FluxCD, Kustomize, Skaffold, ingress-nginx, cert-manager, ExternalDNS, External Secrets, Karpenter, and Velero. Proven track record of building production-grade clusters from scratch with default deny-all NetworkPolicies, private nodes, and Dataplane v2.
Security & Compliance (PCI DSS / ISO 27001)
Deep experience with PCI DSS and ISO 27001 scope work, audit evidence, and security-as-architecture. Tooling includes Vault, Keycloak, SOPS, sealed-secrets, OPA Gatekeeper, Kyverno, Trivy in CI, CIS benchmarks, kube-bench, NetworkPolicies, Istio mTLS, Twingate, CrowdStrike Falcon, and Cloud Armor.
Infrastructure as Code & Cloud Automation
Authoring reusable, versioned Terraform custom modules and pipelines across GCP, AWS, and Azure. Experience with Terragrunt, Config Connector, Ansible, and Packer. Platforms managed include GKE, Cloud Build, Cloud Deploy, Spanner, Apigee X, Pub/Sub, AWS EKS, IAM, VPC, Lambda, RDS, Route53, ALB/NLB, and Azure AKS, Azure DevOps, Key Vault, and Service Bus.
CI/CD & Delivery Pipelines
Hands-on experience with GitHub Actions, GitLab CI, Jenkins, Azure DevOps, Cloud Build, Cloud Deploy, GitOps, progressive delivery, and release-please and Renovate for automated release management.
Observability & SRE
Building observability stacks with Prometheus, Alertmanager, Grafana, Grafana Alloy, Grafana Cloud, OpenTelemetry, Tempo, Loki, ELK, Fluentd, Datadog, New Relic, and Splunk. Defining and enforcing SLOs, error budgets, and synthetic probes on critical payment journeys.
Data & Messaging Systems
Operational experience with PostgreSQL, MySQL, MariaDB, MongoDB, Cassandra, Elasticsearch, OpenSearch, Kafka, RabbitMQ, ActiveMQ, and Redis in regulated production environments.
Languages & Scripting
Proficiency in Python, Bash, Ruby, and Groovy for automation and tooling. Linux administration across RHEL, CentOS, Ubuntu, and Debian. Networking and proxy experience with Nginx, Istio, and Ambassador.
Zero-Downtime Migrations
Led a live data-center to data-center migration of a payment-processing platform with zero downtime and zero lost transactions, including rollback plan execution, all within PCI DSS and ISO scope.
Expertise in designing and operating multi-region Kubernetes estates on GKE, EKS, and AKS, including Helm, ArgoCD, FluxCD, Kustomize, Skaffold, ingress-nginx, cert-manager, ExternalDNS, External Secrets, Karpenter, and Velero. Proven track record of building production-grade clusters from scratch with default deny-all NetworkPolicies, private nodes, and Dataplane v2.
Security & Compliance (PCI DSS / ISO 27001)
Deep experience with PCI DSS and ISO 27001 scope work, audit evidence, and security-as-architecture. Tooling includes Vault, Keycloak, SOPS, sealed-secrets, OPA Gatekeeper, Kyverno, Trivy in CI, CIS benchmarks, kube-bench, NetworkPolicies, Istio mTLS, Twingate, CrowdStrike Falcon, and Cloud Armor.
Infrastructure as Code & Cloud Automation
Authoring reusable, versioned Terraform custom modules and pipelines across GCP, AWS, and Azure. Experience with Terragrunt, Config Connector, Ansible, and Packer. Platforms managed include GKE, Cloud Build, Cloud Deploy, Spanner, Apigee X, Pub/Sub, AWS EKS, IAM, VPC, Lambda, RDS, Route53, ALB/NLB, and Azure AKS, Azure DevOps, Key Vault, and Service Bus.
CI/CD & Delivery Pipelines
Hands-on experience with GitHub Actions, GitLab CI, Jenkins, Azure DevOps, Cloud Build, Cloud Deploy, GitOps, progressive delivery, and release-please and Renovate for automated release management.
Observability & SRE
Building observability stacks with Prometheus, Alertmanager, Grafana, Grafana Alloy, Grafana Cloud, OpenTelemetry, Tempo, Loki, ELK, Fluentd, Datadog, New Relic, and Splunk. Defining and enforcing SLOs, error budgets, and synthetic probes on critical payment journeys.
Data & Messaging Systems
Operational experience with PostgreSQL, MySQL, MariaDB, MongoDB, Cassandra, Elasticsearch, OpenSearch, Kafka, RabbitMQ, ActiveMQ, and Redis in regulated production environments.
Languages & Scripting
Proficiency in Python, Bash, Ruby, and Groovy for automation and tooling. Linux administration across RHEL, CentOS, Ubuntu, and Debian. Networking and proxy experience with Nginx, Istio, and Ambassador.
Zero-Downtime Migrations
Led a live data-center to data-center migration of a payment-processing platform with zero downtime and zero lost transactions, including rollback plan execution, all within PCI DSS and ISO scope.
Languages
BulgarianNative speakerEnglishFluent
Project history
Independent senior-only consultancy covering multiple engagements: payments and travel commerce platform on GCP with PCI DSS scope (12 GKE Autopilot clusters across 4 US and EU regions, ArgoCD GitOps, zero-trust via Twingate, Grafana Alloy observability, error-budget policy); digital asset exchange in Japan on AWS (Terraform module library, CI/CD pipelines, full-scale Kubernetes clusters production-ready); cybersecurity company on AWS (Kubernetes environments from code, custom Helm charts); enterprise product platform on Azure (AKS in Terraform, FluxCD GitOps, production support for AKS, ActiveMQ, PostgreSQL, MongoDB, SOPS, Key Vault, ELK).
Migrated HashiCorp Vault from on-prem Enterprise to open source Vault on GKE with zero downtime. All secrets engines, policies, and auth methods rebuilt in Terraform. Owned Cassandra as distributed store including schema design, replication topology, scaling, backup and restore. Apache Kafka as event backbone feeding Elasticsearch and OpenSearch, delivery on GitHub Actions with ArgoCD.
Back-to-back enterprise client assignments growing from DevOps Software Engineer through Senior to Consultant. Multiple enterprise clients on AWS (2021-2022): reliability, scaling, security posture, VPC, Route53, ALB/NLB, Nginx, Apache, Terraform modules, Kubernetes clusters, SLOs on Datadog/New Relic/Splunk, Istio, Ambassador, Firebase, App Center, Python and Bash automation. Global payment provider (2018-2021): led live data-center migration with zero downtime and zero lost transactions under PCI DSS and ISO scope, dashboards and runbooks to PCI-scope expectations, platform on Ansible, Docker, Jenkins, OSGi, Kafka, MariaDB, Cassandra, ELK, Fluentd, Logstash. Payment provider test automation (2018-2019): independent automated regression testing in CI/CD pipeline across three browser families, macOS and Android API 21+ devices, fully Dockerized.