Hello, I'm Lokesh.

I'm a

Designing secure, scalable, automated cloud platforms using AWS, Kubernetes, Terraform, GitOps, and DevSecOps best practices.

Open to New Opportunities

Available immediately · Remote · Hybrid · Full-time · Contract

Senior DevOps · DevSecOps · Platform Engineering Hyderabad, India  · Open to Remote Global Opportunities

/ About

Platform engineer, obsessed with reliability.

I'm an AWS DevOps Engineer, DevSecOps Engineer, and Platform Engineer with 6+ years of experience designing secure, scalable, and automated cloud-native infrastructure. My work spans AWS Cloud, Kubernetes, Platform Engineering, GitOps, CI/CD automation, Infrastructure as Code, and DevSecOps, helping organizations accelerate software delivery, improve platform reliability, and operate production environments with confidence.

I've designed and managed production workloads on AWS, built end-to-end CI/CD and GitOps pipelines, automated infrastructure provisioning with Terraform and Ansible, and deployed cloud-native applications on Amazon EKS. My focus is on creating resilient, highly available platforms that simplify operations and enable development teams to deliver software faster and more securely.

Security is embedded into every platform I build. I integrate DevSecOps practices throughout the software delivery lifecycle by incorporating automated security scanning, policy enforcement, and compliance into CI/CD pipelines. I also implement Kubernetes security best practices, including RBAC, IRSA, OIDC, Network Policies, Secrets Management, and runtime security to build secure-by-design platforms.

Beyond automation and deployment, I'm passionate about Platform Engineering and Observability. I build reliable, production-ready systems using Prometheus, Grafana, Amazon CloudWatch, Datadog, and OpenTelemetry, enabling proactive monitoring, faster incident response, and improved platform performance.

I'm always exploring modern cloud-native technologies, Kubernetes best practices, GitOps workflows, and DevSecOps strategies to build platforms that are automated by default, secure by design, and engineered for scale. Most of my work has been on enterprise production systems, and I'm always happy to discuss the architecture, engineering decisions, and challenges behind the platforms I've built.

0+
Years of Experience
0+
Microservices Delivered
0+
CI/CD Pipelines
0%
Faster Releases
0%
Cloud Cost Reduction
0.0%
Production Availability
/ Experience

6+ years engineering cloud-native platforms, DevSecOps automation, and scalable Kubernetes infrastructure.

Jul 2024 — Present

DevSecOps Engineer

ASICS Technologies, India
  • Designed a GitOps platform using GitLab CI/CD, Argo CD, and Amazon EKS for 30+ microservices, reducing release time by 45%.
  • Implemented DevSecOps security gates across SAST, SCA, IaC, container, and DAST scanning, embedding security throughout the software delivery lifecycle.
  • Optimized EKS workloads with HPA, KEDA, Cluster Autoscaler, and Karpenter, reducing AWS compute costs by 30%.
  • Hardened Kubernetes with RBAC, IRSA, Vault, Kyverno, and Istio, enforcing least-privilege access and secure service-to-service communication.
  • Engineered observability and centralized logging with ELK, Datadog, and Alertmanager, reducing MTTR by 50%.
Sep 2021 — Jul 2024

DevOps Engineer

Larsen & Toubro (L&T), India
  • Built and maintained CI/CD pipeline for 40+ microservices using GitHub Actions and Argo CD, improving release velocity.
  • Integrated SonarQube, Trivy, SAST, dependency, and container scanning into pipelines, strengthening application security.
  • Containerized application services using Docker multi-stage builds, reducing image sizes by 60% and improving build efficiency.
  • Provisioned AWS infrastructure across EC2, S3, VPC, and IAM using Terraform, accelerating infrastructure delivery by 80%.
  • Deployed and operated microservices on Kubernetes, standardizing application delivery with reusable Helm charts across environments.
Apr 2020 — Aug 2021

Cloud Support Associate

Progile Infotech, India
  • Provided L1/L2 support for AWS and Azure production infrastructure, troubleshooting Compute, Networking, Storage, Connectivity, and performance issues.
  • Managed AWS IAM, Azure RBAC, MFA, and access controls, enforcing least-privilege security practices.
  • Managed backup and recovery operations using EBS Snapshots, S3, Azure Backup, and Recovery Services Vault.
  • Automated cloud operations using AWS Lambda, Azure Automation, Bash, Python, And AWS/Azure CLI, reducing manual operational effort.
  • Reduced AWS and Azure cloud costs by 30% through right-sizing, usage analysis, and automated resource shutdown.
/ Skills

An opinionated, production-grade engineering toolkit.

Cloud

AWSEKSEC2S3IAMVPCLambdaRDSRoute53ALBCloudWatchAzure

Containers

DockerKubernetesEKSHelmDocker ComposeKarpenterHPACluster Autoscaler

Infrastructure as Code

TerraformTerraform ModulesAnsible PlaybooksAnsible RolesDynamic Inventory

CI/CD

GitHub ActionsGitLab CIJenkinsArgo CDBlue-GreenCanary

Security · DevSecOps

SonarQubeTrivySnykCheckovOWASP ZAPGitHub Advanced SecurityVaultIRSARBACOIDC

Observability

PrometheusGrafanaDatadogCloudWatchELK StackAlertmanagerLoki

Networking · Mesh

NGINX IngressIstioAWS ALBRoute53SSL/TLSVPC Peering

Automation · Scripting

PythonBashShellYAML

Databases

PostgreSQLMySQLMongoDBRedisElasticsearchDynamoDB
/ DevSecOps Pipeline

From commit to production - secured, automated, and observable.

22 stages · 90+ integrated tools · Signed artifacts · policy-gated deployments · real-time observability 

Pipeline Success
98.7%
Avg Execution
20m 42s
Critical Vulns
0
High / Med / Low
0 · 2 · 14
Code Coverage
86%
Artifacts Signed
127
Deployments
2.5k+
Pods Running
184
Operations Center

Interactive Kubernetes Ops Console

A live, production-style view of an EKS platform — traffic, resources, security, GitOps, observability, autoscaling and cost — all reacting to real-time events. Click any tile to inspect it.

Cluster Health
99.99%
Running Pods
187
Nodes
24
CPU
48%
Memory
61%
Requests/sec
2,347
p95 Latency
24ms
Argo CD
Healthy
Falco Alerts
2
Est. Spend
$842 /mo
Chaos Simulator
Steady state
Live Traffic Flow — Users → EKS
All paths healthy
Kubernetes Resource Topology
prod-eks-01
Security & Policy Enforcement
All controls passing
Falco
Kyverno
OPA Gatekeeper
Trivy
Cert Manager
NetworkPolicy
RBAC
IRSA
Secrets Manager
Cosign
GitOps Deployment Pipeline
rev 1487·Syncing
Developer
GitHub
Pull Request
GitHub Actions
Unit Tests
SonarQube
Semgrep
Gitleaks
Docker Build
Trivy
SBOM
Cosign
Amazon ECR
Helm
GitOps Repo
Argo CD
Development
Staging
Production EKS
Observability — Prometheus · Grafana · Loki · Tempo · OTel
CPU46%
Memory59%
Req/s2543
p95 Latency30ms
Error Rate0.11%
SLO Availability99.919%
Autoscaling — HPA · Karpenter · Cluster Autoscaler
Simulated Traffic40%
HPA Pods
23
Karpenter Nodes
11
Spot Ratio
50%
Metrics ServerHPAPods↑KarpenterNodes↑Cluster Autoscaler
Cost Optimization — FinOps
Karpenter saved $312 this mo.
Monthly estimate$917
EKS Control Plane$73
Worker Nodes (EC2)$412
EBS + PV Storage$128
Load Balancers$62
Data Transfer$94
RDS Postgres$148
Spot 62%
Idle 4 pods
Rightsizing: 3 hints
/ Featured Projects

Production-grade cloud platforms, engineered to scale. 

AWSKubernetesTerraform

Cloud-Native Trading & Portfolio Platform

Production-grade DevSecOps and GitOps platform for a scalable microservices-based trading application.

CHALLENGE Trading platform required high availability, zero-downtime releases, secure delivery, and scalable Kubernetes operations across 30+ microservices and multiple enviroments.
Solution Built and operated AWS EKS infrastructure using Terraform, GitHub Actions, GitLab CI/CD and Argo CD for CI/CD and GitOps delivery. Implemented Docker, Helm, Istio service mesh, and Datadog/Prometheus observability, and integrated Gitleaks, Semgrep, SonarQube, Snyk, Trivy, Checkov, SBOM generation, and Cosign signing into the DevSecOps lifecycle.
45% faster releases
60% fewer critical vulns
99.9% production availability
50% MTTR reduction
AWSKubernetesGitHub ActionsArgo CDTerraformIstioDatadogVaultSonarQubeSnyk
KubernetesCI/CDGitOps

IoT Smart Devices — Real-Time Monitoring

Secure, automated, and scalable DevOps platform for a IoT-connected smart device ecosystem.

CHALLENGE Supported 40+ IoT microservices across Dev, QA, and Production, required standardized CI/CD, hardened supply chains and scalable AWS infrastructure for reliable, consistent delivery.
Solution Implemented GitHub Actions + Argo CD workflows with integrated SAST, SCA, IaC, container, and DAST security controls. Developed reusable Terraform modules with S3/DynamoDB remote state. Automated AWS infrastructure provisioning with Ansible dynamic inventory for scalable EKS/ Kubernetes environments.
40+ microservices delivered
60% smaller images
80% faster infra provisioning
40% faster incident detection
AWSGrafanaHelmGitHub ActionsTrivyEKSDockerAnsibleTerraform
CI/CDAWSPlatform Engineering

Continuous Personal Health — Philips Healthcare

CI/CD automation platform to accelerate release velocity for a healthcare application.

CHALLENGE Manual, drift-prone releases across Test/QA/UAT/Prod slowed engineering and increased risk.
Solution Designed Jenkins pipelines with Maven/Docker/Ansible across 50+ EC2 instances, eliminating drift. Docker Hub registry, Tomcat deploys, and comprehensive runbooks.
99% build success rate
75% fewer env issues
Weekly → daily releases
20% less senior-engineer dependency
JenkinsMavenDockerAnsibleAWS EC2Tomcat
AWSSecurityMonitoring

Digital Products & Subscriptions Platform

L1/L2 Cloud Operations & Reliability for a multi-cloud AWS + Azure environment.

CHALLENGE Multi-cloud (AWS + Azure) subscriptions platform required uptime, DR and cost governance.
Solution Automated backup/DR with Lambda + EBS Snapshots. Enforced IAM least-privilege + MFA. Cost governance via Cost Explorer, right-sizing and auto-shutdown scripts.
~70% less data-loss risk
25–30% monthly cost savings
30% MTTR reduction
AWSAzureLambdaIAMJiraITIL
/ Certifications

Credentials & continuous learning.

Kubernetes
CKA — Kubernetes Administrator
CNCF / Linux Foundation
Security
CKS — Kubernetes Security
CNCF / Linux Foundation
Resume

Latest resume, always live.

AWS DevOps · DevSecOps · Platform Engineer. Complete work history, tools, certifications and measurable outcomes — ATS-friendly PDF.

PDF
v2.3

Latest Resume

Version 2.3

AWS DevOps · DevSecOps · Platform Engineer

Updated
File size
103.1 KB
Downloads
606
Preview Resume
/ Contact

Let's build reliable platforms together.