Open to Lead / Principal Platform & DevSecOps roles · UK-basedNo sponsorship required

Lead Platform
Engineer

DevOps · SRE · Security Architecture

12 years designing, building and operating the cloud, CI/CD, observability and security foundations that engineering teams ship on. I turn infrastructure complexity into reusable, product-like platform capabilities, then hand teams the keys safely.

12+
Years cloud & DevSecOps
30%
MTTR reduction
85%
Manual RBAC effort removed
15+
Pipelines standardised
100+
IaC pull requests reviewed
Platform EngineeringDevOps & SREInfrastructure as CodeHashiCorp Vault EnterpriseAzure Key VaultSecrets ManagementIAM & Zero-TrustCI/CD SecuritySupply Chain SecurityMulti-Cloud (Azure/AWS/GCP)HITRUST / ISO 27001Observability & SLOsPolicy-as-Code

I build platforms
teams can ship on.

I started in systems administration, moved into DevOps while the discipline was still finding its shape, and settled where the interesting problems actually live, the intersection of platform engineering, reliability and cloud security.

For the last 12 years that work has been in regulated environments: financial services and health-tech, HITRUST and ISO 27001 scope, FCA reporting before that. It means I know what "secure" costs when it has real consequences, and what it costs when it is only a checkbox.

My through-line is treating infrastructure as a product. Landing zones, pipeline templates, secrets engines and observability frameworks get versioned, documented and supported like anything else with users, so squads self-serve safely instead of raising tickets. At Craneware I set those standards across every engineering squad as the individual-contributor technical authority. At PayPal I ran the global Vault Enterprise and Jenkins platforms for 20+ international teams.

I write a lot of Terraform, a lot of Python, and (reluctantly) a lot of YAML. Based in the UK with full right to work, open to Lead, Principal and Head of Platform roles, hands-on or leading a team.

Scope & leadership

CTO / VP

Stakeholder reach

Trusted advisor presenting infrastructure risk plans and platform roadmaps to CTO and VP-level stakeholders, and representing platform engineering in architecture forums alongside Software Architects and the Head of Security.

20+ teams

Standards adopted

IaC, CI/CD and observability patterns I defined were adopted organisation-wide, across all engineering squads at Craneware and 20+ global engineering teams at PayPal.

4 mentored

Engineers grown

Mentored engineers through weekly coaching sessions and workshops; 2 direct mentees promoted to senior. Reviewed and coached on 100+ infrastructure pull requests.

How I think about the work

Security by design

Controls belong in the pipeline and the module, not in a review meeting. Least-privilege, dynamic credentials, audit trails and policy-as-code are the default path, so the secure way is also the easy way.

Platform as a product

Landing zones, pipeline templates and secrets engines are products with users, versions and docs. Good platform work is invisible: teams self-serve safely and never think about what is underneath.

Reliability is measured

Opinions about reliability are worth nothing without SLOs, dashboards and MTTR numbers. I build the observability first, then argue from evidence, that is how 30% MTTR reduction gets defended.

Calm under pressure

Production incidents do not improve with panic. Clear ownership, structured troubleshooting, honest post-mortems and a runbook library that means the same failure never costs twice.

The full platform stack

Depth from raw infrastructure through delivery pipelines to security governance and reliability, the whole path a change takes from a developer's laptop to a monitored production workload.

Cloud Platforms

Azure (HITRUST-aligned)95%
GCP88%
AWS80%

Infrastructure as Code

Terraform / OpenTofu96%
Terragrunt86%
ARM / Bicep · Ansible · Packer84%

CI/CD & Delivery

Azure DevOps Pipelines93%
Jenkins (shared libraries)90%
GitHub Actions85%

Secrets & Identity

Secrets Management (Vault / Key Vault)98%
IAM & Zero-Trust · Entra ID92%
Auth0 · OIDC · SAML · PKI88%

SRE & Observability

Azure Monitor · Log Analytics · KQL92%
Prometheus · Grafana88%
Splunk · Nagios · incident response84%

Containers & Runtime

Azure Container Apps · Dapr90%
Kubernetes · AKS · GKE · Helm88%
Docker · container supply chain90%

Security & Compliance

Policy-as-Code · Azure Policy90%
SAST / SCA gates (SonarQube, Snyk)90%
HITRUST · ISO 27001 · SOC 288%

Automation & Data

Python automation92%
C# · PowerShell · Bash85%
Azure SQL / PostgreSQL (de-facto DBA)84%

Tools & technologies

Cloud & OS

Azure
AWS
GCP
Linux

Infrastructure as Code

Terraform
OpenTofu
Ansible
Packer

CI/CD & Delivery

Azure DevOps
Jenkins
GH Actions
Git

Containers & Runtime

Kubernetes
Docker
Helm
Dapr

Security & Secrets

Vault
SonarQube
Snyk
Auth0

Observability

Prometheus
Grafana
Splunk
Elastic

Languages & Data

Python
PowerShell
Bash
PostgreSQL

Also in the toolbox

AzureAWSGCPTerraformOpenTofuTerragruntARM / BicepAnsiblePackerAzure DevOpsJenkinsGitHub ActionsGitGitHubHelmDockerKubernetesAKSGKEAzure Container AppsDaprHashiCorp VaultAzure Key VaultEntra IDAuth0SAML / OIDCPKI / TLSSonarQubeSnykPalo AltoAzure PolicyWorkload Identity FederationAzure MonitorLog AnalyticsKQLPrometheusGrafanaSplunkNagiosPythonC#PowerShellBashLinuxAzure SQLPostgreSQLAzure Data FactoryDatabricksPower BIHITRUSTISO 27001SOC 2CIS benchmarksFinOpsPrivate Endpoints

Certifications

HashiCorp Terraform Associate 002

HashiCorp

2023

HashiCorp Vault Associate 002

HashiCorp

2023

GCP Professional Engineer

Edureka

2023

Azure DevOps Solutions AZ-400

Microsoft

2022

Azure Fundamentals AZ-900

Microsoft

2022

IBM Certified Data Analytics

IBM

2021

Excel to MySQL: Analytic Techniques

Duke University

2021

Toastmasters International: Communication

Toastmasters

2012

Education

MBA (Finance)

Jain University / Pondicherry University

2010 – 2012 · First Class · 4.0 GPA

PG Diploma in Business Management

Pondicherry University

2010 – 2012

12 years. Real systems.
Real consequences.

Regulated financial services and health-tech throughout, where the platform has to be auditable, not just working.

Jul 2023 – Jan 2026

Senior DevOps / Platform Engineer (Technical Lead)

Azure · HITRUST-Aligned SaaS

The Craneware Group

Senior technical lead for platform engineering and SRE across a HITRUST-aligned SaaS platform, setting the CI/CD, IaC and observability standards adopted by every engineering squad as an individual-contributor technical authority.

80% ↓ policy non-compliance30% ↓ MTTR85% ↓ manual RBAC effort99.9%+ availability
  • Azure Landing Zones & policy-as-code: Designed and delivered a reusable Azure Landing Zone architecture as a shared platform capability in Terraform/OpenTofu: hub-and-spoke networking, management group hierarchies and custom Azure Policy guardrails enforcing tagging, SKU restrictions and private endpoints. Cut policy non-compliance by 80% and produced continuous HITRUST audit evidence.

  • Containerised & serverless platforms: Operated 20+ Azure Container Apps in production: revision strategies, HTTP/event-driven scaling, Dapr integration and managed identity bindings with zero-downtime deployments. Led an AKS proof-of-concept deploying SonarQube as a Kubernetes-native workload with Helm; the resulting ADR was adopted as the platform’s forward migration path.

  • CI/CD security guardrails: Embedded SonarQube and Snyk SAST/SCA as mandatory, self-service quality gates in every Azure DevOps pipeline: coverage thresholds, code-smell limits and security hotspot policies enforced across all squads without slowing delivery.

  • Secrets management platform: Owned enterprise secrets management as a shared capability across every Azure environment: RBAC access policies, managed identity integration and automated rotation for credentials, connection strings and API keys, eliminating hardcoded secrets across 15+ microservices and all CI/CD pipelines.

  • HashiCorp Vault SME: PoC & architecture: Designed and delivered a Vault Enterprise proof-of-concept on Azure evaluating dynamic secret issuance, PKI certificate automation and AppRole/Managed Identity auth, producing a formal security architecture recommendation and migration roadmap adopted by security and platform leadership.

  • CA & SAML certificate lifecycle: Owned all CA and SAML signing/encryption certificates and OIDC client credentials across platform environments: rotation cycles, Auth0 SSO certificate updates and Key Vault-based automated renewal, reducing SSO certificate incidents by over 90% and manual renewal effort by ~60%.

  • SRE observability & reliability: Built SRE observability foundations (Azure Monitor, Log Analytics, KQL) as reusable dashboards and alerting frameworks contributing to a 30% MTTR reduction; automated RBAC provisioning for Azure SQL, cutting manual effort ~85% with audit-ready compliance reporting.

  • IaC modernisation: Led the full migration from ARM templates to Terraform/OpenTofu, standardising 15+ Azure DevOps pipelines around reusable modules, approval gates and integrated security checks, materially reducing onboarding time for new services.

  • Platform operations & FinOps: Ran a FinOps review cadence (Azure Cost Management, KQL dashboards) surfacing idle VMs, orphaned disks and over-provisioned resources; acted as de-facto DBA for Azure SQL and PostgreSQL (schema changes, indexing, failover testing) maintaining 99.9%+ availability on HITRUST-compliant workloads.

  • Cross-team leadership & mentoring: Represented platform engineering in architecture forums with Software Architects, Product Engineering Leads and the Head of Security; presented infrastructure risk plans and platform roadmaps to CTO/VP stakeholders; authored runbooks and architectural guidance while mentoring engineers through weekly coaching sessions and workshops.

Jun 2022 – Jul 2023

Senior DevSecOps Engineer, Cloud Infrastructure L4

GCP (80%) · AWS (20%) · Regulated Finance

PayPal

Built and operated the core GCP platform and the global HashiCorp Vault Enterprise secrets platform serving 20+ international engineering teams in a regulated financial services environment.

30+ pipelines migrated~70% ↓ config overhead20+ teams servedZero production outages
  • Platform engineering (GCP): Built and operated the core GCP platform with Terraform and Terragrunt as reusable, product-like infrastructure: GKE cluster provisioning, VPC design, Cloud NAT and IAM Workload Identity Federation; the IaC patterns were adopted globally across 20+ engineering teams.

  • CI/CD platform migration: Bamboo & CircleCI → Jenkins: Sole lead migrating 30+ pipelines from Atlassian Bamboo and CircleCI onto a centralised Jenkins platform on GCP, delivered with zero production outages and ~70% reduction in configuration overhead, producing a single auditable delivery platform with RBAC-enforced approval gates and integrated Vault dynamic credential injection.

  • GitHub Actions & Helm chart deployments: Designed GitHub Actions workflows for GCP-native microservices: Docker build/push to GCR, Helm chart templating and deployment to GKE with HPA and PodDisruptionBudget; maintained a Helm chart library for all Kubernetes-native workloads with Vault secret injection via vault-action.

  • HashiCorp Vault Enterprise: platform lead: Architected and operated Vault Enterprise HA clusters on GCP as the authoritative self-service secrets platform for 20+ global engineering teams: dynamic secrets with TTL-based lease rotation, a PKI engine for internal CA/TLS issuance, and AppRole and LDAP auth backends.

  • Vault governance & security hardening: Designed enterprise namespace policies and RBAC models enforcing separation of duties across production, staging and development secret paths; implemented Vault audit logging to Splunk for real-time anomaly detection and compliance evidence; integrated MFA and LDAP auth meeting PayPal’s regulated financial services controls.

  • Observability & reliability: Built full-stack observability as a foundational platform capability (Prometheus, Grafana, Nagios, Splunk and Slack alerting) across GCP hybrid environments, covering access anomalies, platform health and security signals for faster incident detection and response.

  • Supply chain security: Embedded Vault-based dynamic credential injection into every Jenkins template, eliminating static credentials from all CI/CD workflows; implemented Snyk and SonarQube quality gates plus ACL IP-blocking and just-in-time IAM role vending for ephemeral build access.

  • DNS migration: Route53 → Cloud DNS: Led the DNS migration workstream of the AWS-to-GCP product migration: audited all Route53 hosted zones, scripted zone replication in Python and Terraform, and executed a zero-downtime cutover using TTL pre-lowering strategies.

  • DevOps leadership & mentoring: Primary DevOps point of contact for multiple Hyperwallet squads; mentored 4 engineers (2 promoted to senior); collaborated daily with security architects and SRE teams across time zones, representing the platform in engineering leadership forums alongside senior managers and architects.

Jun 2020 – Jun 2022

DevOps Engineer

AWS (50%) · Azure (50%)

Kalosbyte Systems Pvt Ltd

Delivered multi-cloud migrations and standardised hybrid CI/CD for client platforms across AWS and Azure, acting as the primary technical contact through delivery.

50+ servers migratedMulti-AZ resilienceGreenfield Azure landing zones
  • Multi-cloud migrations: Led on-prem-to-AWS migrations re-hosting 50+ Linux servers onto EC2 with multi-AZ, ELB and Auto Scaling; delivered greenfield Azure environments (VNets, NSGs, App Services, Azure SQL) for new client onboardings.

  • Hybrid CI/CD & security hardening: Built CI/CD pipelines across AWS and Azure using Jenkins and Azure DevOps as standardised delivery patterns; implemented Ansible config-as-code, Azure Policy, AWS Config rules and SELinux hardening.

  • Container orchestration & customer-facing delivery: Deployed and operated Kubernetes on AWS EC2 with HAProxy load-balancing; served as primary technical contact across both platforms, presenting migration progress to client IT management.

  • Incident management & runbooks: Led incident response and maintenance windows for critical workloads across AWS and Azure; maintained a post-incident learning library and runbooks to reduce repeat failures.

May 2014 – Jun 2020

BI Data Engineer & IT Infrastructure Engineer

On-prem · Azure Data · Power BI

Economy Engraveers

Owned the on-premise server estate and built the Azure data platform and reporting layer serving senior stakeholders.

50+ on-prem servers100k+ record datasets
  • Azure data platform: Built Azure Data Factory and Databricks pipelines for ETL across CRM/ERP sources; delivered Power BI dashboards using DAX, Power Query and Power Pivot over 100k+ record datasets for senior stakeholders.

  • Infrastructure: Designed and maintained LAN/WAN and 50+ on-premise servers: provisioning, SELinux patching, capacity management and monitoring; provided technical support ensuring data delivery SLAs were met.

Feb 2013 – Apr 2014

Financial Data Analyst

Regulated Finance · FCA / UCITS

Northern Trust Corp

Performed daily fund valuation and regulatory reporting for UK-domiciled funds. That grounding in regulated controls and audit trails still shapes how I design platforms.

FCA / UCITS reportingFull audit trail
  • NAV calculation & Bloomberg: Performed daily Net Asset Value calculations for UK-domiciled mutual funds and OEICs, reconciling holdings, accruals and corporate actions; used Bloomberg Terminal to validate market pricing and reference data; prepared FCA/UCITS regulatory reports with full audit trail.

  • Blockchain & digital assets: Contributed to an internal POC evaluating blockchain-based settlement infrastructure for fund transactions, analysing DLT applicability to NAV reconciliation and cross-border payment flows.

  • Data integrity & stakeholder coordination: Maintained data governance standards across fund accounting systems, reconciling custodian records, Bloomberg feeds and portfolio data as front/middle-office liaison.

References available on request · UK-based · Full right to work · No sponsorship required

What I actually built

Six platform capabilities, each shipped as something other teams consume, with the architecture, not just the outcome.

AZURE LANDING ZONE · HUB-AND-SPOKEMGMT GROUPSPlatformLanding ZonesSandboxDecommissionedAZURE POLICY ⛨ tagging · SKU restriction · private endpoints · deny-public-IPHUB VNetfirewall · bastion · DNSProd spokeAKS · ACAStaging spokeApp SvcDev spokeContainer AppsData spokeSQL · PG
01Platform Architecture

Azure Landing Zone: reusable foundation with policy guardrails

80% ↓ policy non-compliance · continuous HITRUST audit evidence

Environments had grown organically with no consistent network, identity or governance baseline. I designed a reusable Azure Landing Zone in Terraform/OpenTofu: management group hierarchy, hub-and-spoke networking, private endpoints and custom Azure Policy guardrails enforcing tagging and SKU restrictions, shipped as a shared platform capability squads consume, not a one-off deployment.

AzureTerraformOpenTofuAzure PolicyHub-and-spokeHITRUST

Write-up in progress · happy to walk through it

VAULT ENTERPRISE · HA SECRETS PLATFORMAUTH BACKENDSAppRoleLDAP + MFAManaged Ident.KubernetesVAULT HAnode-0 · activenode-1 · standbynode-2 · standbyraft storage · auto-unsealENGINESPKI · CA/TLSDynamic DBKV v2Transitaudit → Splunk20+ teamszero static creds
02Security Architecture

HashiCorp Vault Enterprise: global self-service secrets platform

20+ global engineering teams served · zero static credentials in CI/CD

At PayPal, global teams each had their own approach to secrets. I architected and operated HA Vault Enterprise clusters on GCP as the authoritative secrets platform: dynamic secrets with TTL lease rotation, a PKI engine for internal CA/TLS issuance, AppRole and LDAP auth, namespace policies enforcing separation of duties, and audit logging into Splunk for real-time anomaly detection.

HashiCorp VaultGCPTerraformTerragruntPKISplunk
Read case study →
CI/CD CONSOLIDATION · 30+ PIPELINESBEFOREBamboo12 pipelinesCircleCI14 pipelinesad-hoc scripts4 pipelinesJENKINSon GCP · HA· shared libraries· dynamic agents· RBAC gates⚿ Vault dynamic credsAFTER0production outages~70%config overhead ↓1auditable platform100%gated approvals
03Delivery Engineering

CI/CD consolidation: 30+ pipelines from Bamboo & CircleCI to Jenkins

Zero production outages · ~70% ↓ configuration overhead

Three delivery tools, three security models, no single audit trail. As sole lead I migrated 30+ pipelines onto a centralised Jenkins platform on GCP with shared libraries, dynamic build agents, RBAC-enforced approval gates and Vault dynamic credential injection, one auditable delivery platform that regulated financial services controls could actually be evidenced against.

JenkinsGCPShared librariesVaultRBACTerraform
Read case study →
SECURE SUPPLY CHAIN · MANDATORY GATES1commitsigned2SASTSonarQube3SCASnyk4buildJIT identity5signattestation6deploygatedpolicy-as-code · coverage thresholds · security hotspots · zero standing credentialsself-service for squads · enforced by default · no delivery slowdown
04DevSecOps

Secure software supply chain: mandatory, self-service quality gates

SAST/SCA enforced across every squad · no delivery slowdown

Security gates fail when they feel like a tax. I embedded SonarQube and Snyk SAST/SCA as mandatory but self-service gates into every Azure DevOps pipeline: coverage thresholds, code-smell limits, security hotspot policies, paired with just-in-time IAM role vending and dynamic credential injection so build agents never hold standing access.

SonarQubeSnykAzure DevOpsPolicy-as-CodeJIT IAMSBOM

Write-up in progress · happy to walk through it

RUNTIME PLATFORM · CONTAINER APPS → AKSingressHTTPS · WAFCONTAINER APPS ENV · 20+ appssvc-1daprmgd-idsvc-2daprmgd-idsvc-3daprmgd-idsvc-4daprmgd-idblue/green revisions · HTTP + event-driven scale-to-zeroAKSHelm · SonarQube PoCHPA · PodDisruptionBudgetADR: forward migration path✓ zero-downtime deploys
05Runtime Platform

Container & serverless runtime: 20+ Azure Container Apps in production

Zero-downtime deployments · AKS migration path ratified as ADR

Operated 20+ Azure Container Apps in production: revision strategies, HTTP and event-driven scaling, Dapr service invocation and managed identity bindings with zero-downtime rollouts. I then led an AKS proof-of-concept deploying SonarQube as a Kubernetes-native workload via Helm; the architecture decision record became the platform’s forward migration path.

Azure Container AppsDaprAKSHelmManaged IdentityKubernetes

Write-up in progress · happy to walk through it

SRE OBSERVABILITY · MTTR ↓ 30%MEAN TIME TO RECOVERY−30%SIGNALSAzure MonitorLog Analytics / KQLPrometheusGrafanaSplunkSLO alerts · runbooks · on-call
06Reliability Engineering

SRE observability foundations: 30% MTTR reduction

30% ↓ MTTR · 85% ↓ manual RBAC effort · 99.9%+ availability

Alerting was noisy and dashboards were per-team snowflakes. I built reusable Azure Monitor, Log Analytics and KQL dashboards and alerting frameworks as a shared platform capability, alongside automated RBAC provisioning for Azure SQL with audit-ready compliance reporting, cutting MTTR by 30% and removing ~85% of manual access-change effort.

Azure MonitorLog AnalyticsKQLPrometheusGrafanaSLOs
Read case study →

What colleagues say

"Raj has a rare combination of deep technical knowledge and the ability to explain complex infrastructure problems to non-technical stakeholders. He improved our security posture significantly while keeping the team unblocked."

Engineering Manager

Financial Technology (reference available)

"One of the most thorough infrastructure code reviewers I've worked with. He catches security issues before they become incidents."

Senior Software Engineer

SaaS Platform (reference available)

Full LinkedIn recommendations available on request

Let's work
together.

Whether you're hiring for a Lead or Principal Platform Engineering, DevSecOps or SRE role, building out a platform function, or working through a specific infrastructure or security challenge, I'd like to hear from you. I typically reply within one working day.

LocationUnited Kingdom · open to remote