Ralf Ramge
Infrastructure Automation Architect
Experience
Security Architect
Federal Employment Agency
Responsibility for the design, migration, and integration of a security- and audit-critical HashiCorp Vault platform in the trust center of a nationwide authority with system-critical importance.
Analysis and realignment of the existing HashiCorp Vault landscape, including production and planned use cases
Design, proof-of-concept, migration, and integration of HashiCorp Vault Enterprise, taking into account the authority's PKI and operational processes
Design and implementation of an automated certificate and secrets management system for 300 Kubernetes clusters and several thousand certificates in the trust center
Securing the Vault platform using hardware security modules (HSM)
The solution enables a highly available, audit-compliant, and automated operation of certificate and secrets use cases in a highly regulated environment.
Technologies used: HashiCorp Vault Enterprise, Terraform, Ansible, OpenSSL, PKI, HSM
HashiCorp Nomad Consultant
E.ON SE
Technical responsibility for the time-critical stabilization, migration, and integration of a distributed Nomad platform in the production environment of an international energy company.
Migration and integration of 16 production Nomad clusters with several hundred containers into a consolidated operations and security architecture
Increased availability and operational reliability by implementing end-to-end TLS encryption
Integration of Nomad, Consul, Vault, and Terraform into existing automation and operations processes
Structured knowledge transfer to internal teams for the sustainable continuation of the platform
The project ensured the stable operation of business-critical workloads under high time pressure and reduced operational risks in a complex, distributed platform landscape.
Technologies used: Nomad, Consul, Vault, Terraform, Packer, Traefik, Amazon Web Services
Cloud Architect
Porsche AG
Architecture, design, and implementation of a standardized AWS baseline architecture for running a specialized software solution in 3D modeling.
Design and implementation of a reproducible AWS Landing Zone as a foundation for a secure and scalable platform operation
Development of a modular Terraform base module library as a reusable foundation for dynamic infrastructure provisioning (approx. 150 resource types in 45 modules)
Empowering and technically guiding external teams to use the Terraform modules productively in the project context
Integration of Amazon EKS for containerized workloads
Aligning the architecture with internal development and operations requirements
The solution created a clean, maintainable, and extensible cloud foundation on which the specialized application can be run in a standardized and reproducible way.
Technologies used: Terraform, Amazon Web Services, Elastic Kubernetes Service (EKS)
HashiCorp Terraform & Vault Expert
DEVK Deutsche Eisenbahn Versicherung AG
Support for the design and setup of a PKI and secrets infrastructure based on HashiCorp Vault in a regulated insurance environment.
Design and setup of a PKI infrastructure using HashiCorp Vault OSS and Enterprise
Technical consulting and integration of Vault as part of pre-sales decisions
Development of a Terraform backend for automated provisioning of Vault environments
The project laid the technical foundation for secure, audit-ready management of certificates and secrets in the target architecture.
Technologies used: Terraform, Vault Enterprise, HSM
HashiCorp Terraform Integration Partner
T-Systems (Schweiz AG) / Schweizerische Bundesbahnen (SBB)
Design and implementation of core platform building blocks for automated provisioning of IaaS resources in a national critical infrastructure environment.
Development of dynamic, multitenant Terraform modules for the Open Telekom Cloud as a basis for standardized infrastructure provisioning in SBB's private cloud
Design and implementation of Packer templates for automated creation of security-compliant system images (RHEL 7/8/9, Windows Server)
Focus on reusability, standardization, and long-term maintainability of the platform
The results formed the technical basis for consistent, reproducible, and audit-ready infrastructure automation in a highly available environment.
Technologies used: Terraform, Packer, Vault
Oracle Cloud Infrastructure Architect / Terraform Expert
Opitz Consulting Deutschland GmbH
Technical ownership for modernizing and stabilizing a production Terraform platform without affecting ongoing operations.
Upgraded an existing Terragrunt/Terraform production environment from Terraform OSS 0.12 to 1.0
Migrated and consolidated around 450 Terraform state files with about 1,800 infrastructure resources
Analyzed and optimized existing CI/CD processes and performed structured code refactoring
Designed and delivered a tailored Terraform training program for internal teams
The project reduced technical risks, ensured the platform's future readiness, and enabled internal teams to continue development independently.
Technologies used: Terraform, Terragrunt, Packer, Ansible, Oracle Cloud Infrastructure
Head of Managed Cloud Services
Diso AG
Built and took technical responsibility for the Managed Cloud Services area with a focus on standardized, automated cloud and platform services.
Designed and established a managed cloud service portfolio for enterprise customers
Defined technical standards and operating models for cloud and platform services
Provided technical leadership and worked closely with internal engineering and delivery teams
Reviewed and improved the existing ISO 27001 implementation
Short-term leadership and development role as part of the strategic realignment of the service portfolio and ISO 27001 recertification.
ICT Specialist
Eidg. Departement für Verteidigung, Bevölkerungsschutz und Sport
Designed and introduced a comprehensive infrastructure automation framework for the Swiss Army's command base (FUB).
Designed and implemented automated infrastructure processes based on HashiCorp tools
Supported the transition from traditional waterfall processes to agile ways of working
Collaborated in security-critical projects and value streams as part of the "Erneuerung" program
The project improved reproducibility, traceability, and operational security of the infrastructure in a military environment with high security requirements.
Technologies used: Terraform, Vault, Consul, Packer, DevOps, Scrum
Cloud Architect
BearingPoint Software Solutions GmbH
Architected, designed, and implemented a cost-efficient testing platform in Oracle Cloud Infrastructure for a mission-critical software product.
Benchmarked and migrated bare-metal IaaS environments from IBM SoftLayer to OCI
Automated the infrastructure with Terraform and Packer
The new target architecture reduced cloud operating costs by about 60% while improving scalability and operational stability.
Technologies used: Terraform, Packer, Vault, Oracle Cloud Infrastructure, Oracle Database
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Government and Administration, Information Technology, Professional Services, Energy, Automotive, and Insurance.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Operations, and Product Development.
Summary
I take on responsibility for security- and audit-critical infrastructure automation in regulated environments like government agencies, banks, insurance companies, and telcos.
For over 25 years, I have designed, migrated, and operated IT platforms where misconfigurations, manual interventions, or dependence on individual people are not an option. My focus is on building and running fully auditable infrastructure-, security-, and policy-as-code platforms based on the HashiCorp stack and Ansible.
In projects, I have been able to:
- measurably increase operational and audit security,
- eliminate manual changes, and
- reduce cloud operating costs by up to 60%.
I have designed, implemented, and integrated platforms where infrastructure, access, and security resources are automated, highly available, and audit-compliant in multitenant environments handling a high five- to six-figure number of resources.
I am typically brought in when platforms are under regulatory responsibility, must pass audits, and need to operate reliably, reproducibly, and without implicit expert knowledge.
Skills
Technical Qualifications
- Oracle Solaris 7/8/9/10/11 (Certified) – 30 Years (+++)
- Oracle Linux / Red Hat Enterprise Linux – 20 Years (++)
- General Linux Engineering – 25 Years (++ )
- Oracle Cloud Infrastructure (Oci) Architecture – 8 Years (++ )
- Amazon Web Services Architecture – 3 Years (+)
- Organisational Transformation To Devops / Agile / Scrum – 6 Years (+++)
- It Project Management And Technical Leadership – 17 Years (+)
- Leadership Experience With Personnel Responsibility – 8 Years (+)
- Infrastructure Provisioning – 8 Years (+++)
- Network Automation (Service Discovery & Service Meshes) – 7 Years (+++)
- Secrets Management, Mfa & Zero Trust (Security-as-code) – 5 Years (+++)
- Application Orchestration (Containers, Vms, Bare Metal, Processes) – 3 Years (+++)
- Implementation Of Enterprise Policies (Policy-as-code) – 2 Years (+++)
- Oci Generative Ai Dedicated Clusters (Llm Training, Fine-tuning) – 1 Year (++ )
- Prompt Engineering (Chain-of-thought, Least-to-most, Step-back, Etc.) – 1 Year (++ )
- Retrieval-augmented Generation (Rag) – 1 Year (++ )
- Hashicorp Terraform & Packer – Infrastructure Provisioning – 8 Years (+++)
- Hashicorp Vault – Secrets Management, Pki, Encryption-as-a-service – 5 Years (+++)
- Hashicorp Consul – Service Discovery, Service Defined Data Center – 7 Years (+++)
- Hashicorp Nomad – Application Deployment & Orchestration – 3 Years (+++)
Soft Skills
- It Service Management (Itsm, Itil) – 20 Years (++ )
- Project Management (Pmbok) – 4 Years (+)
- Devops & Agile Methods (Implementation, Training) – 8 Years (+++)
- Scrum & Nexus Frameworks – 6 Years (+)
- Technical Guidance And Training – 15 Years (+++)
- Client Perspective And Service Orientation – 15 Years (+++)
- Team Leadership (Primary Belbin Role: Shaper) – 15 Years (+++)
- Time And Resource Management – 12 Years (++ )
- Target Group-oriented Communication – 6 Years (++ )
- Technical And Disciplinary Leadership Responsibility – 17 Years (+++)
- Personnel Management – 8 Years (++ )
- Decision-making And Prioritization – 15 Years (+++)
- Continuous Improvement Processes – 17 Years (+++)
Personal Attributes
- Preference For Independent Work
- Very High Level Of Personal Responsibility
- Strong Initiative And Proactive Project Execution
- High Empathy For Customers And Diversity
- Excellent Communication Skills
- Highly Structured Approach
Keywords
- Oracle Cloud Infrastructure
- Oci
- Aws
- Amazon Web Services
- Cloud Migration
- Cloud Architecture
- Hybrid Cloud
- Public Cloud
- Private Cloud
- Generative Ai Infrastructure
- Oci Generative Ai
- Llm Deployment
- Llm Fine-tuning
- Llm
- Rag
- Retrieval-augmented Generation
- Infrastructure As Code
- Iac
- Terraform
- Terraform Enterprise
- Packer
- Ansible
- Ansible Automation Platform
- Policy As Code
- Infrastructure Provisioning
- Network Automation
- Orchestration
- Automation
- Ci/cd
- Devops Automation
- Container
- Orchestration
- Hashicorp Vault
- Vault Enterprise
- Secrets Management
- Pki
- Public Key Infrastructure
- Mfa
- Encryption As A Service
- Hsm
- Hardware Security Module
- Root Ca
- Intermediate Ca
- Certificate Management
- Zero Trust Architecture
- Security As Code
- Iso 27001
- Iam Integration
- Generative Ai
- Oci Generative Ai Professional
- Large Language Models
- Prompt Engineering
- Retrieval-augmented Generation
- Fine-tuning
- Ai Infrastructure
- Private Ai
- Gpu Clusters
- Hashicorp Terraform
- Hashicorp Packer
- Hashicorp Vault
- Hashicorp Consul
- Hashicorp Nomad
- Service Mesh
- Service Discovery
- Nomad Cluster
- Consul Cluster
- Application Orchestration
- Hashicorp Partner
- Certified Hashicorp Implementation Partner
- Chip
- Ibm
- Ibm Partner
- Oracle Solaris
- Red Hat Enterprise Linux
- Rhel
- Oracle Linux
- Centos
- Linux Engineering
- Cloud Architect
- Infrastructure Architect
- It Consultant
- Security Architect
- Vault Consultant
- Terraform Expert
- Pki Specialist
- Devops Trainer
- Project Manager
- Team Lead
- Senior Engineer
- Devops
- Agile Methods
- Scrum
- Itil
- Itsm
- Continuous Improvement
- Project Management
- It Leadership
- Transition Management
- Organizational Development
- Customer Orientation
- Empathy
- Communication
- Team Leadership
- Autonomy
- Time Management
- Training
- Decision-making Skills
- Independent Work
- Oci Architect Associate
- Oci Generative Ai Professional
- Aws Certified Solutions Architect
- Hashicorp Vault Associate
- Hashicorp Terraform Associate
- Hashicorp Consul Associate
- Certified Implementation Partner
Languages
Education
Technical University of Kaiserslautern
No degree · Department of Technoinformatics · Kaiserslautern, Germany
Technical University of Kaiserslautern
Department of Computer Science · Kaiserslautern, Germany
Staatliches Speyer-Kolleg
General university entrance qualification (Abitur) · Speyer, Germany
Certifications & licenses
Oracle Cloud Infrastructure 2024 Certified Architect Associate
Oracle Cloud Infrastructure
Vault: Certified HashiCorp Implementation Partner
HashiCorp
HashiCorp Certified Consul Associate
HashiCorp
HashiCorp Certified Vault Associate
HashiCorp
Terraform: Certified HashiCorp Implementation Partner
HashiCorp
HashiCorp Certified Terraform Associate
HashiCorp
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Ralf based?
What languages does Ralf speak?
How many years of experience does Ralf have?
What roles would Ralf be best suited for?
What is Ralf's latest experience?
What companies has Ralf worked for in recent years?
Which industries is Ralf most experienced in?
Which business areas is Ralf most experienced in?
Which industries has Ralf worked in recently?
Which business areas has Ralf worked in recently?
What is Ralf's education?
Does Ralf have any certificates?
What is the availability of Ralf?
What is the rate of Ralf?
How to hire Ralf?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Security Architect
Nearby freelancers
Professionals working in or nearby Belp, Switzerland