Skip to main content
Top expert badge
Recommended expert
Profile header background

Halil Oeztoprak-Principal Cloud & DevSecOps Architect (AWS / Azure / Terraform / Kubernetes / CI-CD)

Halil Oeztoprak - Principal Cloud & DevSecOps Architect (AWS / Azure / Terraform / Kubernetes / CI-CD) - profile avatar
Profile header overlay
Bonn, Germany

Check rate

Experience

Sep 2025 - Present
Frankfurt, Germany
Hybrid

Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD)

KfW Bankengruppe

Position Summary
Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD) at KfW Bankengruppe
Industries
Banking and Finance
Business Areas
Information Technology
Operations
  • Regulated environment within a German banking group (approx. 8,500 employees, hybrid cloud strategy).

  • Responsible for operating, provisioning, and continuously securing business-critical platforms – including a GenAI chat application, a big data/AI platform, and data science workspaces based on Azure Virtual Desktops and VMs. Ownership of Azure DevOps projects for ShaiHulud and React2Shell, as well as BSI alerts – Security Operations improvements across the SDLC.

  • Deployment responsibility for the GenAI chat application, big data/AI platform (BDAI), and data science workspaces (AVD/VM-based) in the respective landing zones.

  • Deployment & release management: end-to-end responsibility for deploying portal and service applications across multiple Azure landing zones, including technical approvals, compliance with development team deployment guidelines, and ensuring ITIL-based change and release processes via ServiceNow.

  • Azure landing zones & network architecture: design, provisioning, and operation of Azure landing zones for 3-tier web applications with enhanced network segmentation, VNet peering, hub-and-spoke architectures, private endpoints, and firewall integration across separate subscriptions and tenants.

  • Azure DevOps governance & operations: ownership of the Azure DevOps organization, including projects, repositories, and CI/CD pipelines; implementation of governance requirements such as branch policies, approval gates, permission models, and audit-ready operating structures.

  • Infrastructure as Code (Terraform): design, implementation, and operation of a modular Terraform architecture for standardized cloud infrastructure deployment, including state management, provider versioning, reusability, and policy-as-code approaches.

  • CI/CD pipeline engineering: design, operation, and optimization of complex YAML-based CI/CD pipelines with multi-stage deployments, template standardization, self-hosted agents, integrated secret management, and automated quality and security checks.

  • Git migration & platform consolidation: planning and execution of repository and pipeline migration from Azure DevOps to GitLab CI/CD, including automated scripts, full Git history transfer, pipeline porting, and platform consolidation.

  • Container & platform operations (AKS): operation and security assessment of containerized workloads on Azure Kubernetes Service, centralization of on-premises container registries for ACR.

  • OpenShift (OCP) security reviews: security assessment of code baselines, build pipelines, and deployment processes for on-premises OpenShift clusters with critical applications, and derivation of specific hardening recommendations.

  • Shift-left security & DevSecOps transformation: introduction of a company-wide shift-left approach for early security integration in development and deployment processes, enabling developers to perform self-led security checks and sustainably reduce vulnerabilities before production (IDE integrations, pre-commit hooks, local scanners).

  • Software supply chain security: analysis and mitigation of supply chain risks in NPM- and Yarn-based applications through dependency audits, CI/CD pipeline hardening, token rotation, and restriction of risky build and lifecycle mechanisms.

  • Frontend & framework security (React / Next.js): security assessment and coordination of critical vulnerability remediation across platform applications and web frameworks, including coordination and complementary technical mitigations with all teams following BSI alerts.

  • Software composition analysis (SCA): introduction and operation of automated vulnerability scans for container images, pipelines/artifacts, and third-party dependencies, including SBOM exports within CI/CD pipelines.

  • SAST/DAST integration: design and piloting of static and dynamic application security tests in close collaboration with security architecture and development teams, for continuous improvement of code and runtime security, and establishing operational acceptance tests.

  • Artifact & registry consolidation: analysis and consolidation of all package and container repositories for service applications and AKS workloads, aiming for a centralized, secured registry strategy with centralized vulnerability scanning and governance.

  • Dependency-Track & SBOM strategy: advising the compliance board on introducing a central SBOM and vulnerability management platform to increase enterprise-wide dependency transparency and accelerate CVE response capability.

  • CI/CD pipeline hardening: security analysis and cleanup of the existing pipeline landscape by removing unused pipelines, improving secrets hygiene, implementing least-privilege principles, and isolating build agent environments.

  • Azure Web Application Firewall (WAF) optimization: analysis and tuning of existing Azure WAF rules (OWASP Top 10 Core Rule Set, DSR/SDC, custom rules) to defend against known vulnerabilities and exploit patterns, including reducing false positives and improving threat detection.

  • Documentation & stakeholder communication: creating and maintaining technical documentation, runbooks, and architecture overviews in Jira and Confluence, as well as active knowledge transfer between operations, development, security, and compliance stakeholders.

Aug 2025 - Nov 2025
Mannheim, Germany

Principal Cloud Solutions Architect & Senior DevSecOps Engineer

risiq GmbH

Position Summary
Principal Cloud Solutions Architect & Senior DevSecOps Engineer at risiq GmbH
Industries
Banking and Finance
Business Areas
Information Technology
Product Development
Quality Assurance
  • Banking risk management platform for a finance startup (42 cloud services, 50+ employees). Multi-account AWS landing zone, multi-stage Kubernetes cluster provisioning with EKS and ECS, plus a front-end web interface via AWS Amplify. GDPR, C5, BaFin, and DORA-compliant CI/CD deployment pipelines via GitHub Enterprise.

  • Implemented a multi-account strategy with AWS Control Tower and Account Factory for Terraform (AFT) for secure separation of development, test, and production environments, plus centralized governance and compliance monitoring using a fully automated GitOps model.

  • Established data residency in EU regions, implemented encryption at rest and in transit, and built audit trails and logging mechanisms for full traceability of personal and business-critical data.

  • Deployed highly available EKS clusters with auto-scaling, Pod Security Standards, Network Policies, and integration of AWS Fargate for serverless container workloads and ECS for a hybrid container strategy.

  • Developed automated deployment pipelines with GitHub Enterprise Actions, measuring and optimizing change failure rate, lead time, mean time to recovery, and deployment frequency, including automated rollback mechanisms, OWASP, SAST, and DAST integration with SonarQube and Burp Suite Enterprise.

  • Integrated AWS Security Hub, GuardDuty, Config Rules, and Inspector for continuous security and compliance monitoring, and implemented IAM roles with least-privilege principle and MFA enforcement.

  • Onboarded additional AWS accounts into the customer’s CSPM/CNAPP portal based on Wiz Security.

  • Built high-performance backend APIs: scalable microservices architecture with AWS Lambda, API Gateway, and RDS/DynamoDB for risk data processing, including CDN integration.

  • AWS Amplify frontend deployment and infrastructure co-development for a responsive web application using React/Angular, automated build and deployment pipelines, tenant-specific for banks, and Auth0 integration for secure user authentication and authorization.

  • Implemented comprehensive monitoring and custom metrics for business KPIs and SLA monitoring of risk management functions.

  • Established a multi-region strategy with automated backups, cross-region replication, RTO/RPO-optimized recovery processes, and regular disaster recovery tests.

  • Developed automated compliance checks, policy-as-code via OPA, continuous vulnerability scans via Dependency-Track, and AWS Config integration for configuration drift detection plus audit-ready documentation.

Apr 2025 - Sep 2025
Mannheim, Germany

Enterprise Cloud Solutions Architekt / Senior DevOps Engineer

Bilfinger SE

Position Summary
Enterprise Cloud Solutions Architekt / Senior DevOps Engineer at Bilfinger SE
Industries
Professional Services
Business Areas
Information Technology
Operations
Quality Assurance
  • 2,500 workloads for over 17,000 employees worldwide.

  • Multi-account AWS landing zone, multi-stage Kubernetes cluster deployment with Amazon EKS, ECS, and AWS Fargate, hybrid networking with global IP Address Management (IPAM) and WAN, using Transit Gateways and Palo Alto Firewalls (Pan-OS) across six operational cloud regions.

  • Service ownership of AWS cloud landing zones, including operation, continuous improvement, and ensuring compliance with corporate standards and governance for all subsidiaries.

  • Conducted security and compliance analyses (DevSecOps) and mapped findings to frameworks like NIST, ISO 27001, and PCI DSS.

  • Performed AWS Well-Architected Reviews to evaluate and optimize existing multi-account landing zone architectures.

  • Centralized and consolidated multiple AWS landing zones and built a global network architecture to Azure Prisma Hub.

  • Operated and optimized incident, change, and problem management processes via ServiceNow for AWS global networking / Azure Global WAN.

  • Analyzed, optimized, and migrated DaaS workloads (desktop-as-a-service), comparing and transitioning from Nutanix Frame and AWS WorkSpaces Classic to AWS WorkSpaces Pools.

  • Tuned storage performance and throughput optimization for Amazon FSx for Windows File Server.

  • Introduced and operated a centralized firewall and traffic inspection setup with Palo Alto Networks (PAN-OS).

  • Designed and implemented a fully automated AWS landing zone solution with built-in security and compliance mechanisms.

  • Built and maintained IaC pipelines using Azure DevOps for repeatable, secure deployments including security gates.

  • Rolled out global AWS WorkSpaces Pools for over 500 CAD/engineering end users, including enablement and architecture optimization.

  • Implemented staging environments for Kubernetes workloads, including separation of dev/test/prod and access control.

  • Integrated Dependency-Track for SBOM analysis and implemented additional security services such as AWS Inspector, GuardDuty, and Security Hub.

  • Connected the AWS environment to external SOC providers, including SIEM integration.

  • Onboarded the new landing zone into the CSPM tool (SentinelOne Singularity Cloud Platform), including continuous security posture management.

  • Documentation, quality assurance, and knowledge transfer to internal engineering and security teams.

Aug 2023 - Mar 2025
Hanover, Germany

Enterprise Cloud Solutions Architekt / Senior DevOps Engineer

Concordia Versicherungsgesellschaft auf Gegenseitigkeit a.G.

Position Summary
Enterprise Cloud Solutions Architekt / Senior DevOps Engineer at Concordia Versicherungsgesellschaft auf Gegenseitigkeit a.G.
Industries
Insurance
Business Areas
Information Technology
  • 450 workloads across multiple data centers and branch offices.

  • AWS cloud piloting, multi-account AWS landing zone, multi-stage Kubernetes cluster deployment with EKS and ECS, hybrid networking with Direct Connect, Transit Gateway, and site-to-site VPN.

  • Configured a Well-Architected AWS multi-account landing zone, including workload accounts and organizational units (OUs) for multi-stage Kubernetes clusters.

  • Advised the customer on multi-account and multi-stage strategies in AWS.

  • Implemented the Account Factory for Terraform (AFT) to scale the AWS landing zone and automate security and compliance across the organization.

  • Applied security and compliance policies according to BSI, VAIT, C5, BaFin, and DORA requirements.

  • Configured and activated service control policies (SCPs) and guardrails in AWS Control Tower and AWS Organizations.

  • Enabled security standards and configured AWS-native security services like SecurityHub, GuardDuty, and IAM Access Analyzer following best practices.

  • Configured and activated compliance standards for resources using AWS Config and AWS Trusted Advisor.

  • Prepared decision templates for service strategies, especially for implementing and managing key management services for compliance and data encryption in AWS.

  • Planned and configured hybrid connectivity, including data center integration with dynamic routing strategies via BGP VPN/failover and network segmentation.

  • Developed and deployed secure, compliance-aligned EC2 images based on CIS frameworks and STIG.

  • Automated infrastructure deployment with Terraform across multiple AWS accounts via Azure DevOps YAML pipelines.

  • Built IaC and CI/CD deployment pipelines including security gates with SAST and DAST integration using Trivy and tfsec, and Kubernetes deployments via ArgoCD.

  • Implemented role-based access control (RBAC) and attribute-based access control (ABAC) in AWS IAM and integrated AWS Identity Center for comprehensive identity management.

  • Set up comprehensive CloudWatch monitoring, including log aggregation and real-time analytics.

  • Established centralized backup management and business continuity and disaster recovery planning with AWS Backup services.

  • Produced thorough documentation, including runbooks and operational manuals.

  • Conducted quality and performance reviews.

Aug 2022 - Aug 2023
Germany

Senior Cloud Consultant / Senior Cloud Solutions Architect

Allgeier Group SE / Naggaro SE

Position Summary
Senior Cloud Consultant / Senior Cloud Solutions Architect at Allgeier Group SE / Naggaro SE
Industries
Information Technology
Business Areas
Information Technology
Operations
  • Various clients across industries, supporting 1,500+ EUC users and five main applications, including infrastructure migrations.

  • AWS MSP, multi-account AWS landing zone, multi-tenant AppStream 2.0 fleets, and Amazon WorkSpaces Classic deployment with Terraform and AFT.

  • Configured multiple AWS multi-account landing zones, including workload accounts and organizational units (OUs).

  • Implemented and managed SCPs and guardrails in AWS Control Tower and AWS Organizations, including regional usage restrictions and establishing an account security and compliance concept following AWS best practices.

  • Planned, configured, and automated deployment of multiple VPCs and infrastructures for AWS VDI technologies, focusing on Amazon AppStream 2.0 and Amazon WorkSpaces.

  • Developed, automated, and deployed images for Amazon AppStream 2.0 and AWS WorkSpaces services via Terraform and image pipelines.

  • Designed migration strategies and planned and executed lift-and-shift migrations of client applications and servers to AWS.

  • Fully automated client infrastructure and application deployment in multi-stage, multi-account setups via Terraform and CI/CD pipelines.

  • Configured and conducted end-to-end testing for multi-user streaming via AppStream 2.0, including autoscaling and fleet management.

  • Created and deployed standardized Amazon WorkSpaces setups, including Active Directory domain join and standard GPOs.

  • Integrated AWS WorkSpaces services with Microsoft Active Directory workloads and identity providers for user synchronization, including single sign-on via SCIM.

  • Implemented Azure Active Directory synchronization for Microsoft 365 and Entra ID using Entra ID Connect.

  • Configured CloudWatch monitoring and enabled application monitoring for client applications.

  • Set up centralized backup management with AWS Backup service for various client organizations.

Apr 2022 - Aug 2022
Berlin, Germany

Lead IT Consultant and Team Lead of the dedicated 3rd Level Global IT Operations Team

Atotech Deutschland GmbH & Co. KG

Position Summary
Lead IT Consultant and Team Lead of the dedicated 3rd Level Global IT Operations Team at Atotech Deutschland GmbH & Co. KG
Industries
Chemical
Business Areas
Information Technology
  • 1,250+ workloads and over 5,500 users, spread across globally networked data centers and offices in regions such as Asia/Pacific, EMEA, and the USA.

  • Active Directory Security Assessment: Performing detailed analyses of security settings, identifying existing vulnerabilities, and evaluating the current security level.

  • Configuration of the Microsoft Services Hub Log Analytics Workspace: Building a centralized monitoring management system for collecting and analyzing security-related log data.

  • Advanced Group Policy Management 4.0: Implementing advanced group policy management with granular security controls for Group Policy Objects (GPOs).

  • Tier-0 Security Concept: Designing and implementing a Tier-0 concept to separate security levels across the organization in Active Directory and the GPO structure, including logical optimizations.

  • Hardening Service Accounts: Reviewing and hardening service accounts with a focus on password policies, pruning weak accounts, and moving to gMSA accounts (Group Managed Service Accounts).

  • Hardening User Account Policies: Tightening user account policies and password requirements according to current best practices.

  • General AD Hardening: Implementing extensive hardening measures based on CIS benchmarks and BSI security guidelines.

  • Entra ID Connect update and redesign: Updating and redesigning the Entra Connect implementation to optimize user synchronization between on-premises and cloud identities.

  • Log4Shell Response: Implementing additional security measures to address the Log4Shell vulnerabilities and enabling automated patch management using Red Hat Satellite and WSUS.

Apr 2022 - Aug 2022
Bonn, Germany

Cloud Consultant

IVG Immobilien GmbH

Position Summary
Cloud Consultant at IVG Immobilien GmbH
Industries
Real Estate
Business Areas
Information Technology
  • Advising on the planning, architecture, and full implementation of a scalable Windows Virtual Desktop environment for 500+ users.

  • Building and configuring host pools (pooled & personal) with automated user assignment and load balancing according to the Azure Well-Architected Framework.

  • Developing and operating a fully automated image pipeline (Golden Image build & deployment) with Azure Image Builder – including regular updates, security hardening, and integration of CAD applications.

  • Implementing App Attach (MSIX/App Attach) for dynamic application delivery: packaging, storage integration (Azure Files), assignment, and lifecycle management for different user groups in Entra ID.

  • Integrating FSLogix for user profile management (Azure Files) to ensure high-performance, persistent user profiles with GPO enforcement.

  • Implementing monitoring & logging (Azure Monitor, Log Analytics workspace) for proactive troubleshooting and capacity planning.

  • Automating scaling and maintenance processes for session hosts (start VM on connect, scheduled agent updates, autoscaling).

  • Implementing Conditional Access policies and multi-factor authentication for secure remote access to the AVD desktops.

  • Creating operational documentation, runbooks, and handing over to IT operations.

Nov 2020 - Apr 2022
Berlin, Germany

Lead IT Consultant | Team Lead of the dedicated 3rd Level Global IT Operations Team

Atotech Deutschland GmbH & Co. KG

Position Summary
Lead IT Consultant | Team Lead of the dedicated 3rd Level Global IT Operations Team at Atotech Deutschland GmbH & Co. KG
Industries
Chemical
Business Areas
Information Technology
Operations
  • 1,250+ workloads and over 5,500 users spread across globally networked data centers and offices worldwide.

  • Providing strategic support for the AWS cloud migration to ensure a smooth transformation of the IT infrastructure.

  • Leading the 3rd-level Global IT Operations team responsible for the uninterrupted operation of the global IT landscape.

  • Ensuring global 3rd-level support for all data centers and locations worldwide, including DMZs and global secure platforms.

  • Managing IT processes: performing and overseeing consulting, monitoring, incident, change, and problem management processes.

  • Running a hybrid, heterogeneous IT infrastructure on-premises and in the cloud at 3rd-level support.

  • Responsible for Microsoft backend services in a single-forest, multi-domain Active Directory setup.

  • Supporting Microsoft 365 services, Exchange Online (hybrid), Microsoft Endpoint Manager (SCCM/EPM), Intune MDM, MDT, and the rollout of Windows 10/11 clients.

  • Global operation of the SCCM backend, software distribution, and management of distribution points.

  • Implementing and operating monitoring solutions such as SCOM & Zabbix.

  • Ensuring operation including VMware virtualization, Riverbed systems, storage and network services, Citrix VDI infrastructure, and Red Hat Linux & Satellite.

  • Migration and transformation: planning and executing migrations, rehosting, redeployments, and rearchitecting of services into the AWS cloud.

  • Security and vulnerability management in the global IT environment.

  • Managing external service providers, partners, and strategic vendor management in an international enterprise context.

Jul 2020 - Nov 2020
Germany

Senior IT Consultant

Atotech Deutschland GmbH & Co. KG

Position Summary
Senior IT Consultant at Atotech Deutschland GmbH & Co. KG
Industries
Chemical
Manufacturing
Business Areas
Information Technology
  • 1,250+ workloads and over 5,500 users worldwide.

  • Providing comprehensive consulting and support to the client during the AWS cloud migration preparation phase.

  • Conducting detailed assessments for around 250+ Linux servers and over 50 Linux applications.

  • Introducing Red Hat Satellite for efficient patch management of Red Hat and CentOS servers.

  • Modernizing the Linux servers with minor and major release changes to prepare for cloud requirements.

  • Conducting AWS Migration Readiness Assessments (MRA) for resources, tools, and workforce skills.

  • Installing AWS discovery and inventory tools to analyze application dependencies.

  • Creating comprehensive documentation of the Linux system landscape as a basis for cloud rehosting.

Jun 2020 - Nov 2021
Germany

Team Lead & Lead IT Consultant | Senior Modern Digital Workplace Consultant

Allgeier Group SE

Position Summary
Team Lead & Lead IT Consultant | Senior Modern Digital Workplace Consultant at Allgeier Group SE
Industries
Energy
Healthcare
Business Areas
Information Technology
Project Management
  • Various industries (energy, healthcare), team leadership and setup for Microsoft 365 onboardings, including resource and deployment planning.

  • Planning, managing, and executing complex Microsoft 365 onboarding projects for clients like CENTOGENE, Powerlines Group GmbH, and Onyx Germany GmbH.

  • Managing heterogeneous platforms including Windows 10/11, macOS, Android, and iOS.

  • Migrating email services, calendars, and mailboxes to Exchange Online.

  • Configuring and deploying Microsoft Teams including B2B scenario integration.

  • Device management, configuration, and automation via Microsoft Intune.

  • Developing automated policies in PowerShell and GitHub to increase efficiency.

  • Implementing device compliance and security policies based on CIS benchmarks and BSI standards.

  • Designing and implementing a secure corporate app store, including black and whitelisting through Entra ID groups.

  • Extending management strategies to macOS and enabling fully automated deployments using Windows Autopilot and JAMF.

  • Creating detailed runbooks and process documentation.

Mar 2020 - Jul 2020
Wuppertal, Germany

IT Consultant & Technical Migration Lead

gkv informatik GbR

Position Summary
IT Consultant & Technical Migration Lead at gkv informatik GbR
Industries
Insurance
Business Areas
Information Technology
Project Management
  • Healthcare insurance environment, Citrix infrastructure backend services, IGEL thin clients for BARMER.

  • Initiation and planning of the migration project for Citrix infrastructure outsourcing.

  • Design and technical implementation of migration paths for the existing Citrix infrastructure.

  • Development of a new Citrix back-end for future operations.

  • Identification and implementation of migration strategies for user profiles and software packages.

  • Design of a new Active Directory group structure, including naming conventions.

  • Securing the migration process by identifying critical configurations like Citrix UPM and GPOs.

  • Coordinating and managing external service providers during the transition.

Sep 2018 - Mar 2020
Berlin, Germany

IT Consultant, Team and Transition Manager

IT Dienstleistungszenrum Berlin (ITDZ)

Position Summary
IT Consultant, Team and Transition Manager at IT Dienstleistungszenrum Berlin (ITDZ)
Industries
Information Technology
Government and Administration
Business Areas
Information Technology
Operations
  • 750+ workloads, HP enclosure cluster with 64 server systems, 4500 Citrix users.

  • Knowledge transfer and handover of operation manuals and concepts to specialist departments.

  • Setup, operation, and management of the Citrix Hypervisor (XenServer) virtualization environment.

  • Optimization of the Citrix XenApp/XenDesktop infrastructure as well as the Citrix Hypervisor.

  • Hardening of the Citrix desktop design using group policies according to the CIS framework and BSI standards.

  • Performance optimization in Citrix Hypervisor virtualization and Provisioning Services.

  • Monitoring of infrastructure services using SCOM and CheckMK.

  • Design and implementation of a FollowMe/PullPrinting solution according to BSI standards, including full encryption.

Mar 2018 - Aug 2018
Stuttgart, Germany
Remote

IT Consultant

BAM Deutschland AG

Position Summary
IT Consultant at BAM Deutschland AG
Industries
Construction
Business Areas
Information Technology
Quality Assurance
  • 2nd and 3rd level support for Citrix remote workspaces.

  • Implementation and rollout of Windows 10 clients using Baramundi.

  • Interim management of the Exchange server.

  • Software packaging and endpoint management.

  • Mobile device management via MobileIron/MobilePASS.

  • Quality management and documentation.

Jan 2017 - Mar 2018
Germany

IT Consultant

Telefónica Germany GmbH & Co. OHG

Position Summary
IT Consultant at Telefónica Germany GmbH & Co. OHG
Industries
Telecommunication
Business Areas
Information Technology
Operations
  • Over 750 server workloads, virtual RedHat server farms in two data centers.

  • Responsible for VMware vCenter administration in a global context.

  • ITIL-compliant incident management and change request handling with BMC Remedy.

  • Release and deployment management for RedHat application platforms.

  • Coordination of international resources for minor and major release migrations from RedHat 6 to RedHat 7.

  • Development of a patch management concept for RedHat server systems in compliance with ISO standards.

  • Implementation and commissioning of the RedHat Satellite platform 6.2.

  • Migration of RedHat licenses to RHSM and asset inventory including CMDB integration.

  • Analysis of the global IT infrastructure and creation of a monitoring concept including SLAs.

  • BASH and PowerShell scripting to automate IT processes.

Sep 2016 - Dec 2016
Munich, Germany

IT Consultant

Landeshauptstadt München

Position Summary
IT Consultant at Landeshauptstadt München
Industries
Government and Administration
Business Areas
Information Technology
Quality Assurance
  • Over 500 workloads, virtualization of physical and virtual servers.

  • Execution of P2V (Physical to Virtual) virtualization of physical servers with VMware.

  • V2V (Virtual to Virtual) conversion of KVM/QEMU server systems into VMware vCenter.

  • Coordination and scheduling for virtualization processes.

  • Virtualization of RedHat, SLES, and Microsoft Windows servers.

  • Integration of the virtualized systems into the central data center.

  • Implementation of service and process monitoring as well as quality assurance of migration processes.

Jun 2016 - Sep 2016
Germany

IT Consultant

World Hotels GmbH

Position Summary
IT Consultant at World Hotels GmbH
Industries
Tourism
Business Areas
Information Technology
  • Azure cloud infrastructure, SharePoint Server, MS SQL Server 2012, Reporting Services.

  • Developed a cloud migration plan following a lift-and-shift approach.

  • Migrated database from MS SQL Server 2008 to MS SQL Server 2012.

  • Set up and deployed SharePoint and database servers in the Azure cloud.

  • Carried out the lift-and-shift migration for Microsoft servers with testing phases.

  • Customized and created SQL Server reports, including trend analyses.

  • Performed quality control and prepared operational manuals.

Dec 2015 - Feb 2016
Stuttgart, Germany

Junior Identity & Access Management (IAM) Consultant

IT Baden-Württemberg (BITBW)

Position Summary
Junior Identity & Access Management (IAM) Consultant at IT Baden-Württemberg (BITBW)
Industries
Government and Administration
Business Areas
Information Technology
  • Designed and implemented an IAM environment with Microsoft Identity Manager (MIM).

  • Developed attribute flows and synchronization rules for Active Directory user objects.

  • Set up and secured the perimeter network (DMZ), including a reverse proxy.

  • Integrated and tested IAM tools for single sign-on (SSO) applications.

  • Configured the SSO identity provider and integrated it with Active Directory Federation Services (ADFS).

Sep 2013 - Nov 2015
Bochum, Germany

IT System Administrator / Project Administrator

Med 360° SE

Position Summary
IT System Administrator / Project Administrator at Med 360° SE
Industries
Healthcare
Business Areas
Information Technology
Project Management
  • Managed 275 workstations, 50 servers, across six locations.

  • Designed and built a new standards-compliant server room.

  • Carried out Active Directory migration projects (Windows Server 2003 to 2012/R2).

  • Replaced Microsoft Exchange Server with Zarafa groupware on Linux.

  • Automated rollout of Windows 7 and replaced Windows XP clients via OPSI.

  • Connected multiple sites via site-to-site VPN.

  • Introduced a Citrix terminal server system for KIS applications across locations.

  • Set up Nagios monitoring with CheckMK.

  • Implemented a new ticket system (OTRS) and a Linux-based CRM system (vTiger).

  • Managed and coordinated external service providers.

Jan 2012 - Jan 2013
Herne, Germany

System Programmer / Main Project during Fixed-Term Position

rku.it GmbH

Position Summary
System Programmer / Main Project during Fixed-Term Position at rku.it GmbH
Industries
Information Technology
Business Areas
Information Technology
  • Managed two data centers with over 2000 server systems and various network components.

  • Developed a monitoring system architecture based on Nagios.

  • Implemented the Nagios master server and configured the platform.

  • Successfully migrated from Nagios to Check_MK OMD (Open Monitoring Distribution).

  • Integrated AIX, Linux, and Windows servers into the monitoring system.

  • Mapped service dependencies and prioritized business-critical applications.

  • Monitored systems via SNMP and WMI, including alert configuration.

  • Integrated monitoring results into the ticket system (Omnitracker).

Sep 2011 - Nov 2011
Herne, Germany

Trainee - IT Specialist for System Integration

rku.it GmbH

Position Summary
Trainee - IT Specialist for System Integration at rku.it GmbH
Industries
Information Technology
Business Areas
Information Technology
  • Successfully replaced physical HP ProLiant file servers and HP EVA 6000 SAN systems.

  • Implemented a high-availability Microsoft failover cluster under VMware.

  • Connected the new cluster to a NetApp storage system.

  • Carried out data migration, ensuring NTFS permissions.

  • Configured and managed backups to ensure data security.

Aug 2008 - Jul 2009
Bochum, Germany

IT Support Intern

R.iT GmbH

Position Summary
IT Support Intern at R.iT GmbH
Industries
Information Technology
Business Areas
Customer Service
Information Technology
  • Providing 1st and 2nd level support for end users.

  • Administering and maintaining Microsoft Small Business Server for multiple clients.

  • Diagnosing and fixing issues in real time to ensure smooth operations.

  • Coordinating support tasks while meeting SLAs and KPIs.

Industry Experience

See where this freelancer has spent most of their professional time.

Experienced in Information Technology, Healthcare, Insurance, Chemical, Government and Administration, and Energy.

Information Technology
Healthcare
Insurance
Chemical
Government and Administration
Energy
Profile match chart

Business Area Experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Operations, Project Management, Quality Assurance, Customer Service, and Product Development.

Information Technology
Operations
Project Management
Quality Assurance
Customer Service
Product Development
Profile match chart

Summary

My focus is on migrating and transforming complex enterprise infrastructures in hybrid and multi-cloud environments – especially in designing, building, and operating automated AWS multi-account landing zones, conducting Well-Architected Reviews, and migrating and integrating demanding end-user computing (EUC) workloads such as AppStream 2.0, WorkSpaces, Azure Virtual Desktop, and Nutanix Frame.

I bring in-depth expertise in identity and access management (IAM) integration, zero-trust architectures, Kubernetes, infrastructure as code (IaC), CI/CD pipelines, and comprehensive automation.

In the area of cloud security and compliance, I have extensive project experience with frameworks like BSI, ISO 27001, VAIT, DORA, C5, and NIS-2, and I have successfully implemented CSPM/CNAPP, SIEM, and DevSecOps processes and sustainably established operational security measures.

I focus on secure IT and cloud architecture, automated infrastructure, and reliable, compliant operation of distributed cloud and end-user computing services with VDI technologies.

Skills

  • Aws Multi-Account Architecture And Governance: Design, Deployment, And Consolidated Operation Of Scalable Landing Zones Using Aws Control Tower, Organizations, Transit Gateway, Direct Connect, And Account Factory For Terraform (Aft). Development And Implementation Of Automated Governance Policies For Secure And Compliant Management Of Complex Multi-Account Environments, As Well As Automation Of Recurring Operational Processes.

  • Cloud Security And Compliance: Implementation And Continuous Optimization Of Security And Compliance Frameworks By Integrating Securityhub, Guardduty, Aws Inspector, And Cspm Solutions Like Tenable, Sentinelone, Singularity Platform, And Wiz. Execution Of Measures According To Bsi, Bait, Vait, And Pci Requirements, Establishment Of Siem Integrations For Monitoring And Analyzing Security Events, And Establishment Of Best Practices In Cloud Security Management.

  • Infrastructure Automation And Devops: Development And Operation Of Terraform-Based Infrastructure Workflows, Implementation Of Iac Pipelines Via Azure Devops, Github Enterprise, Gitlab, And Integration Of Automated Security And Quality Checks (Sast/Dast With Trivy, Tfscan, Tflint, Snyk Security, Etc.). Building And Optimizing Ci/Cd Processes For Efficient And Consistent Delivery, As Well As Maintaining Automated Server Image Pipelines For Reproducible Environments.

  • Kubernetes And Container Operations: Running And Managing Containerized Workloads With Eks/Ecs, Including Governance And Separation Of Dev, Test, And Prod Environments. Implementing Monitoring, Staging, And Observability Solutions For Stable, Production Container Landscapes, As Well As Automations For Deployment And Scaling.

  • End User Computing & Identity: Planning, Implementation, And Securing Of Microsoft 365 Tenants, Including Entra Id, Active Directory Security, Microsoft 365 Tenant Management, And Intune Integration. Carrying Out Demanding Migration Projects For End User Computing Platforms Like Workspaces, Appstream, And Azure Virtual Desktop / Nutanix Frame To Modernize And Secure Digital Work Environments.

  • Shift-Left Security & Devsecops Transformation: Introducing A Company-Wide Shift-Left Approach For Early Integration Of Security Into Development And Deployment Processes, Enabling Developers To Perform Independent Security Checks, And Sustainably Reducing Vulnerabilities Before Production (Ide Integrations, Pre-Commit Hooks, Local Scanners).

  • Software Supply Chain Security: Analysis And Mitigation Of Supply Chain Risks In Npm- And Yarn-Based Applications Through Dependency Audits, Securing Ci/Cd Pipelines, Token Rotation, And Restriction Of Risky Build And Lifecycle Mechanisms.

  • Frontend & Framework Security (React / Next.Js): Security Assessment And Coordination Of Fixing Critical Vulnerabilities Across All Platform Applications And Web Frameworks, Including Alignment And Additional Technical Mitigations With All Teams Following Bsi Alerts.

  • Software Composition Analysis (Sca): Introduction And Operation Of Automated Vulnerability Scans For Container Images, Pipelines/Artifacts, And Third-Party Dependencies, Including Sbom Exports Within Ci/Cd Pipelines.

  • Sast/Dast Integration: Design And Piloting Of Static And Dynamic Application Security Tests In Close Collaboration With Security Architecture And Development Teams For Continuous Improvement Of Code And Runtime Security, And Establishment Of Operational Acceptance Tests (Oats).

  • Artifact & Registry Consolidation: Analysis And Consolidation Of All Package And Container Repositories For Service Applications And Aks Workloads, Aiming For A Centralized, Secured Registry Strategy With Centralized Vulnerability Scanning And Governance.

  • Dependency-Track & Sbom Strategy: Advising The Compliance Board On Introducing A Central Sbom And Vulnerability Management Platform To Increase Enterprise-Wide Dependency Transparency And Accelerate Cve Response Capability.

  • Ci/Cd Pipeline Hardening: Security Analysis And Cleanup Of The Existing Pipeline Landscape By Removing Unused Pipelines, Improving Secrets Hygiene, Implementing Least-Privilege Principles, And Isolating Build Agent Environments.

  • Openshift (Ocp) Security Reviews: Security Assessment Of Code Baselines, Build Pipelines, And Deployment Processes For On-Premises Openshift Clusters With Critical Applications, And Derivation Of Specific Hardening Recommendations.

  • Azure Web Application Firewall (Waf) Optimization: Analysis And Tuning Of Existing Azure Waf Rules (Owasp Top 10 Core Rule Set, Dsr/Sdc, Custom Rules) To Defend Against Known Vulnerabilities And Exploit Patterns, Including Reducing False Positives And Improving Threat Detection.

  • Documentation & Stakeholder Communication: Creating And Maintaining Technical Documentation, Runbooks, And Architecture Overviews In Jira And Confluence, As Well As Active Knowledge Transfer Between Operations, Development, Security, And Compliance Stakeholders.

  • Aws Multi-Account Landing Zones / Azure Landingzones

  • It & Cloud Security | Compliance And Governance

  • Terraform And Devops Automation

  • Devsecops Automation And Developer Experience (Dx)

  • Kubernetes And Microservice Architectures And Ci/Cd Processes

  • Identity And Access Management In Hybrid And Multi-Cloud Contexts

  • Modern Digital Workplace In An Euc Context With Vdi Technologies

  • It Operations Leadership And Execution Of Large-Scale Cloud Migrations

Languages

German
Native
Turkish
Native
English
Advanced

Education

Aug 2009 - Jun 2012

IHK Bochum / rku.IT GmbH

IT Specialist – System Integration · Bochum, Germany · 2

IT Specialist – System Integration

Certifications & licenses

AWS Certified AI Practitioner

AWS Certified Machine Learning Engineer – Associate

AWS Certified Advanced Networking – Specialty

AWS Certified DevOps Engineer – Professional

AWS Certified Developer – Associate

AWS Certified Security – Specialty

AWS Certified Solutions Architect – Professional

HashiCorp Certified: Terraform Associate

Microsoft Certified: Azure AI Fundamentals

Microsoft Certified: Azure Solutions Architect Expert

AWS Certified Cloud Practitioner

AWS Certified Solutions Architect Associate

AWS Certified SysOps Administrator – Associate

LaceWork Shield Certified - Associate CSPM/CNAPP

Microsoft Certified: Azure Administrator Associate

Microsoft Certified: Azure Developer Associate

Microsoft Certified: Azure Virtual Desktop Specialty

Microsoft Certified: CyberSecurity Architect Expert

Microsoft Certified: Identity And Access Administrator Associate

Microsoft 365 Certified: Modern Desktop Administrator Associate

Microsoft Certified: Azure Fundamentals

ITIL® V4 Foundation Certificate

Microsoft Certified Professional (MCP)

Microsoft Certified Solutions Associate: (MCSA) Windows Server

Citrix Certified Associate - Virtualization (CCA-V)

Microsoft Certified Technology Specialist (MCTS)

Statistics

Experience

Total positions 21
Experience in Information Technology 4.5 y
Avg length 9 m
Longest experience 2 y 2 m

Global Experience

Countries worked in 1 (Germany)
Primary country Germany

Expertise

Recent roles Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD), Principal Cloud Solutions Architect & Senior DevSecOps Engineer, Enterprise Cloud Solutions Architekt / Senior DevOps Engineer
Main industries Information Technology, Healthcare, Insurance
Main business areas Information Technology, Operations, Project Management

Qualifications

Certifications earned 26

Profile

Created
Last Update

Frequently asked questions

Have questions? Find more information here.

Halil is based in Bonn, Germany and can operate in on-site, hybrid, and remote work models.
Halil speaks the following languages: German (Native), Turkish (Native), English (Advanced).
Halil has at least 15 years of experience. During this time, Halil has worked in at least 17 different roles and for 18 different companies. The average length of individual experience is 1 year and 8 months. Note that Halil may not have shared all experience and actually has more experience.
Based on recent experience, Halil would be well-suited for roles such as: Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD), Principal Cloud Solutions Architect & Senior DevSecOps Engineer, Enterprise Cloud Solutions Architekt / Senior DevOps Engineer.
Halil's most recent position is Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD) at KfW Bankengruppe.
In recent years, Halil has worked for KfW Bankengruppe, risiq GmbH, Bilfinger SE, Concordia Versicherungsgesellschaft auf Gegenseitigkeit a.G., and Allgeier Group SE / Naggaro SE.
Halil is most experienced in industries like Information Technology, Healthcare, and Chemical. Halil also has some experience in Insurance, Government and Administration, and Energy.
Halil is most experienced in business areas like Information Technology, Operations, and Project Management. Halil also has some experience in Quality Assurance, Customer Service, and Product Development.
Halil has recently worked in industries like Chemical, Insurance, and Energy.
Halil has recently worked in business areas like Information Technology, Operations, and Project Management.
Halil attended IHK Bochum / rku.IT GmbH for IT Specialist – System Integration.
Halil has 26 certificates. Among them, these include: AWS Certified AI Practitioner, AWS Certified Machine Learning Engineer – Associate, and AWS Certified Advanced Networking – Specialty.
Halil is immediately available part-time for suitable projects.
Halil's rate depends on the specific project requirements. Please use the Meet button on the profile to schedule a meeting and discuss the details.
To hire Halil, click the Meet button on the profile to request a meeting and discuss your project needs.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Market avg: 688-848 €
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.