Available for projects · Q3 2026

I build cloud platforms
that ship.

Artem Kozlenkov — Multi-Cloud Platform Engineer. I design platform foundations: Azure Landing Zones, cloud networking & security, identity & access, and application runtimes (Kubernetes, serverless, containers) across Azure, AWS, and GCP.

8+
years of platform engineering
60%
faster deployment times
AK
Artem Kozlenkov
// Switzerland · EU / Remote
01

Selected work

platform engineering, shipped

Cloud Platform | DevOps Engineer

Current

Zühlke AGSchlieren, Zürich

Aug 2025 – Present

Architecting enterprise-scale platform foundations and runtime environments across Azure and GCP for consulting clients.

  • Architect Azure Landing Zones using Cloud Adoption Framework (CAF) with Terraform — management group hierarchy, subscription governance, RBAC, and Azure Policy guardrails
  • Implement Policy-as-Code with Azure Policy and Terraform for continuous compliance enforcement across platform resources
  • Design secure cloud adoption strategies following Well-Architected Framework pillars: reliability, security, cost optimization, operational excellence
  • Lead application migrations to Azure Kubernetes Service (AKS) including cluster networking, identity integration, and container runtime configuration
  • Build GitOps pipelines with ArgoCD and Azure DevOps for automated, declarative platform deployments
  • Design and deploy GCP platform environments focusing on GKE Kubernetes runtime, VPC networking, Cloud NAT, firewall rules, and IAM security policies
  • Configure GCP IAM roles, service accounts, and security policies for production-grade workloads on GKE
  • Implement private networking architectures across Azure and GCP including Private Link, VPC peering, and Private Google Access
AzureTerraformAKSArgoCDAzure DevOpsGCPGKEGCP NetworkingGCP IAMCAF

Cloud Platform | DevOps Engineer

Glencore AGBaar, Zug

Dec 2023 – Aug 2025

Delivered enterprise-scale Azure platform governance, networking, and identity solutions for a global commodity trading organization.

  • Architected Azure Policy-as-Code solution using Terraform and GitLab CI/CD for enterprise governance across 500+ Azure resources — custom policy definitions, initiative assignments, and exemption workflows
  • Designed private networking architecture for Azure Databricks and Azure AI Foundry — VNet injection, Private Link, DNS resolution, and network security groups
  • Automated Azure Private DNS zone management with Terraform and Python — multi-subscription DNS resolution, conditional forwarding, and private endpoint integration
  • Streamlined Azure Landing Zone provisioning across management group hierarchy reducing deployment time by 60% via reusable Terraform modules
  • Led Terraform module development with enterprise-grade patterns — versioning, state management, remote backends, and module composition
  • Implemented Azure RBAC strategy with custom role definitions, PIM for just-in-time access, and managed identity integration for workload authentication
  • Designed key vault architecture for secrets management with soft-delete, purge protection, and private endpoint access patterns
AzureTerraformGitLab CI/CDAzure PolicyAzure DatabricksPythonGitHub ActionsPrivate LinkKey VaultRBAC

Cloud Platform | DevOps Engineer

V-Zug AGZug

Aug 2022 – Nov 2023

Designed Azure IoT platform architectures and managed containerized application runtimes at scale with GitOps delivery.

  • Designed Azure IoT platform architecture with microservices, digital twin device models, and event-driven processing at the edge
  • Deployed containerized services to AKS runtime environment using Helm charts, Azure DevOps pipelines, and GitOps workflows
  • Built telemetry platform handling 100K+ device events daily using IoT Hub, Event Hubs, Azure Functions (serverless), and stream processing
  • Implemented comprehensive security controls across the platform: X.509/TLS certificate lifecycle, PKI infrastructure, RBAC, VNet isolation, Private Link for PaaS services
  • Configured Azure Container Registry with geo-replication, vulnerability scanning, and image trust policies for secure container supply chain
  • Enabled platform observability with monitoring, alerting, and autoscaling for production reliability using Grafana and Prometheus
  • Implemented chaos testing procedures for resilience validation of Kubernetes workloads and event processing pipelines
Azure IoTAKSHelmAzure DevOpsTerraformKubernetesGrafanaPrometheusAzure FunctionsEvent HubsContainer Registry

Cloud Platform | DevOps Engineer

Go-E GmbHBerlin, Germany

Sep 2021 – Aug 2022

Deployed Go microservices on AWS EKS with service mesh and GitOps platform delivery.

  • Deployed Go microservices on Amazon EKS container runtime using gRPC and AWS App Mesh service mesh for service-to-service communication
  • Automated AWS platform infrastructure with Terraform — VPC, subnets, IAM roles, security groups, EKS cluster configuration, and node group management
  • Built GitLab CI/CD pipelines with Amazon ECR and ArgoCD for GitOps-driven platform deployments including Helm chart automation
  • Managed Kubernetes workloads with Helm charts, custom operators, and horizontal pod autoscaling based on custom metrics
  • Set up platform observability with CloudWatch, Prometheus/Grafana dashboards, and OpenTelemetry distributed tracing
  • Managed multi-cloud cost governance across Azure and AWS — resource tagging, budget alerts, and cost allocation reporting
  • Created AWS Service Catalog offerings with standardized infrastructure products for self-service platform consumption
AWS EKSTerraformGoArgoCDgRPCGitLab CI/CDGrafanaCloudWatchHelmApp Mesh

Cloud Platform | DevOps Engineer

Foxbase GmbHDüsseldorf, Germany

Jul 2020 – Aug 2021

Operated and optimized AWS platform infrastructure with IaC, networking, and Kubernetes governance.

  • Operated and optimized AWS cloud platform with Terraform IaC — multi-account VPC design, IAM policies, S3 storage, and EC2 compute
  • Architected VPC networking, security groups, NACLs, and subnet segmentation for multi-tier application isolation
  • Implemented Kubernetes governance patterns on EKS — RBAC, namespace isolation, resource quotas, and network policies
  • Set up centralized monitoring platform with CloudWatch alarms, log aggregation, and Grafana visualization dashboards
  • Automated CI/CD pipelines and established cloud DevOps standards, runbooks, and best practices for platform operations
AWSTerraformKubernetesGrafanaCloudWatchGitLab CI/CDEC2VPC

Backend Engineer

Q.One GmbHEssen, Germany

May 2018 – May 2020

Architected containerized backend services and established CI/CD platform practices for development teams.

  • Architected Java Spring and PHP Symfony microservices deployed as containerized workloads on Kubernetes
  • Established automated CI/CD pipeline platform using GitLab CI for build, test, and deployment workflows
  • Containerized services with Docker — multi-stage builds, image optimization, and private registry management
  • Configured Kubernetes application runtime with Deployment, Service, Ingress, ConfigMap, and Secret resources
  • Implemented application performance monitoring with Prometheus metrics, Grafana dashboards, and CloudWatch log analysis
JavaPHPDockerKubernetesPrometheusGrafanaGitLab CI/CDCloudWatch
02

Stack

core platforms, tools, and supporting tech

Platform foundations: Landing Zones · Networking · Identity · K8s · Serverless — Azure primary, multi-cloud by design.

Azure Platform & Landing Zones★ primary
Azure Landing Zones (CAF)Management Groups & SubscriptionsAzure Kubernetes Service (AKS)Azure Policy & BlueprintsAzure App Service & FunctionsAzure Container AppsAzure DevOps & ReposAzure Monitor & Log AnalyticsAzure Event Hub / IoT HubAzure SQL / Cosmos DBAzure Databricks / SynapseAzure AI Foundry / OpenAI
Application Runtime Environments★ primary
Kubernetes (AKS / EKS / GKE)Docker & Container RuntimesServerless Functions (Azure / AWS)Azure Container AppsHelm / KustomizeService Mesh (Istio / App Mesh)GCP Cloud RunKnative / KEDA Autoscaling
Cloud Networking★ primary
Azure VNets, Subnets & PeeringAzure Firewall & Application GatewayPrivate Link & Private DNSAzure VPN Gateway & ExpressRouteAWS VPC, Subnets & Transit GatewayGCP VPC, Cloud NAT & Private AccessDNS Management (Azure / Route53 / Cloud DNS)Load Balancers & Traffic Manager
Identity & Access Management
Azure AD / Entra IDRBAC & Custom RolesManaged Identities & Service PrincipalsConditional Access & PKIAWS IAM Roles & PoliciesGCP IAM & Service AccountsKey Vault / Secrets ManagementX.509 / TLS Certificate Lifecycle
Security & Compliance
Azure Policy & Defender for CloudNetwork Security Groups (NSG / ASG)Azure Firewall & WAFEncryption at Rest & in TransitISO 27001 / NIS2 ComplianceSecurity Posture & Vulnerability MgmtGitleaks & Secret Scanning
IaC & Policy-as-Code★ primary
Terraform (HCL)BicepAzure Policy (JSON / ARM)Cloud Adoption Framework (CAF)Terragrunt / TerramateAWS CloudFormation / CDK
DevOps & GitOps★ primary
Azure DevOpsGitHub ActionsGitLab CI/CDArgoCDHelm / Kustomize / FluxJenkins
Programming & Scripting
PythonGoBash / PowerShellTypeScript / JavaScriptJava / SpringPHP / Symfony
Monitoring & Observability
Azure Monitor / Log AnalyticsGrafana / PrometheusApplication InsightsDefender for CloudCloudWatch & CloudTrailELK StackOpenTelemetry
Multi-Cloud & Hybrid
Azure (Expert)AWS (Proficient)GCP (Working Knowledge)On-Premise / Hybrid ConnectivityMulti-Cloud Governance & Cost Mgmt
03

Let's build

Have a project or opportunity? Let's talk.