Gideon Warui

Cloud Platform & DevSecOps Engineer

Download PDF

Summary

Cloud Platform & DevSecOps Engineer with 4+ years of experience across enterprise finance, fintech, NGO, and media. Core stack: Kubernetes (AWS EKS, Azure AKS, microk8s), Helm chart authoring, Terraform IaC across Azure and AWS, ArgoCD GitOps, and end-to-end CI/CD and DevSecOps automation. I build and operate production multi-cloud K8s platforms — including a full AWS EKS + Terraform + ArgoCD platform for a fintech startup, built and maintained solo (part-time, 2+ years) — and lead observability, cost-optimization, and AI enablement workstreams. In 2026, I am running a 78-lab public Kubernetes AI Infrastructure Lab program on AKS — covering GPU serving (vLLM/Triton), KEDA/HPA autoscaling, RAG systems, observability, and FinOps — everything provisioned and maintained with Terraform and Helm.

2026 Build Program (Public)

AI Infrastructure Lab Curriculum 2026 — a 45-week AKS-based lab program focused on Kubernetes internals, GPU model serving (vLLM/Triton), RAG systems, KEDA/HPA autoscaling, observability, chaos testing, and FinOps.

  • ~80 labs, 1–2 days each, namespace-isolated, instrumented, measurable, teardown-friendly
  • 2 posts/week cadence (~84 code-heavy posts): Monday infra concept + Thursday AI concept
  • Goal: publish reproducible evidence of AI infrastructure depth (not tutorial summaries)

Core Skills

KUBERNETES, HELM & TERRAFORM

  • Kubernetes — AKS · microk8s · kubeadm · multi-cluster operations · upgrades · scaling
  • Helm — chart authoring · templating · multi-env values · lifecycle management · upgrades
  • Terraform — Azure + AWS IaC · modules · workspaces · remote state · multi-environment
  • AWS — EKS · VPC · RDS · ECR · S3 · IAM/IRSA · Secrets Manager · Karpenter
  • Azure — AKS · VNets/Subnets · Functions · Front Door · Cloudflare failover · Traefik

DEVSECOPS, SRE & OBSERVABILITY

  • Azure DevOps CI/CD · GitHub Actions · ArgoCD (GitOps)
  • Trivy · Semgrep · Falco · Cosign
  • Prometheus · Grafana · Log Analytics · KQL
  • Incident response · DR planning · SLO-driven reliability
  • Kubecost · Azure Cost Management · FinOps reporting

DATA, ANALYTICS & AI SYSTEMS

  • Python · SQL · FastAPI · dbt
  • Data pipelines / ELT · Medallion architecture · DWH/Lakehouse
  • Azure AI Foundry · AI workflow integration + governance
  • RAG systems · pgvector · vector search patterns
  • Zoho Analytics · Tableau · Power BI

CURRENT LAB FOCUS (2026)

  • AKS GPU nodepools (T4/A100) · vLLM · Triton
  • KEDA/HPA autoscaling for LLM workloads
  • Qdrant / pgvector · RAG observability
  • Prometheus · Grafana · Loki for AI infra labs
  • Terraform + Helm lab automation

Experience

Cloud Platform & DevSecOps Engineer

Nov 2024 – Present

Old Mutual Group East Africa (via Invent Consulting)

  • Hands-on senior IC with de facto platform ownership across ~10 production AKS clusters supporting ~20 internal teams and ~5 vendor teams.
  • Built CI/CD + DevSecOps baseline from scratch across 9+ projects using GitHub Actions, Terraform (multi-environment AKS provisioning + modules), and Helm chart management; reduced deployment TAT from ~8 hours (manual) to ~10 minutes dev→staging and ~2–5 minutes to prod after approvals.
  • Improved flagship platform reliability from ~90% to formal ~99.9% SLO/uptime and defined reusable DR blueprints (multi-AZ AKS, HA DBs, Cloudflare -> Azure Front Door failover).
  • Built and operate production Azure AI Foundry tooling for Risk/Compliance/Audit/Ops; improved workflow accuracy from ~80% target to ~95% with governance + observability controls.
  • Identified ~US$150K/year savings on a managed Azure subscription scope (~US$47K/month baseline), with ~US$30K/year already implemented.

Solutions Architect & Platform/Infrastructure Engineer

2024 – Present

Syndikiza (Fintech) · Independent · Part-time

  • Designed and built the entire AWS + Kubernetes platform from scratch — VPC, EKS (K8s 1.34), RDS PostgreSQL (prod + nonprod), ECR, IAM/IRSA, Secrets Manager, and S3 — all provisioned via custom Terraform modules (vpc, eks, rds-postgres, secrets-manager).
  • Operate 16 ArgoCD applications across dev and production environments serving 5 microservices (Django + Java); automated GitOps with self-heal, unlimited retry, and Kustomize base/overlay pattern across all app repos.
  • Authored and maintain Helm-deployed platform stack: Traefik Gateway API (ingress + TLS termination), cert-manager (Let's Encrypt automation), Karpenter (spot + on-demand node autoscaling), External Secrets Operator (AWS Secrets Manager → K8s Secrets), and VictoriaMetrics/Loki/Grafana observability.
  • Implemented HPA (autoscaling/v2) for all production Django services and Karpenter NodePool taint patterns to isolate production workloads on on-demand nodes; achieved cost-optimized platform at ~$185–270/month through single shared cluster + spot instance strategy.
  • Delivered full security posture: IRSA for pod-level AWS access (no long-lived credentials), non-root containers, read-only root filesystems, Security Group least-privilege, and AWS CloudTrail + K8s audit logging.

Senior Data & AI Platform Engineer

Nov 2024 – Feb 2026

NCBA Bank — CarDuka Platform (via Invent Consulting)

  • Started with a V1 CI/CD enablement sprint (GitHub Actions deployment automation), then expanded into V2 data/AI/platform engineering for the marketplace rebuild.
  • Owned data architecture, pipelines, warehouse/lakehouse evolution, and DB operations across ~21 databases; expanded into AKS/Kubernetes debugging, Helm-managed deployments, Terraform infrastructure updates, observability, and autoscaling work with NCBA cloud/DevOps teams.
  • Built production/pilot AI and data features including valuation, Similar Cars, CLM/LTV, liquidity balancing, RAG-based review/search, KYC processing, and content moderation workflows.
  • Impact highlights: Similar Cars increased listing views ~3x; valuation engine improved pricing/listing accuracy ~13%; KYC pilot reduced verification TAT from ~24h to <1h.
  • Designed and secured approval for the reusable Azure architecture + CI/CD templates for the broader Duka marketplace roadmap through 2028.

Data Architect & Data Engineer

Jul 2024 – Feb 2025

World Relief (East & Central Africa) (via Invent Consulting)

  • Designed and delivered a Microsoft Fabric lakehouse + self-service data platform integrating 1,400+ datasets across 6+ countries.
  • Replaced manual Excel + R-script reporting workflows with automated daily pipelines, improving reporting/data turnaround from ~2 weeks to daily refreshes.
  • Shipped a production FastAPI self-service data API/platform on Azure Container Apps with Entra ID country-scoped RBAC and multi-format exports (Excel/CSV/TSV/JSON/XML).
  • Trained and onboarded teams in Kenya, Uganda, and Rwanda; handed over the production platform after funding cuts constrained wider rollout.

Data Lead & Data Engineer

Feb 2023 – Aug 2024

Yakwetu Online Limited

  • Joined as first data hire; designed and built the AWS data/analytics platform from scratch — architecture decisions, service selection (S3 data lake, EC2 compute, CloudWatch observability, IAM access controls), and full platform operations — progressing from Data Engineer to Data Lead.
  • Built recommendation and watch analytics systems that increased transactions (~8%), reduced abandonment (~15%), and improved engagement/watch time.
  • Optimized ad campaign spend (~10% reduction) while bringing CPC below $0.03 and established Tableau reporting for revenue/content/campaign visibility.
  • Helped hire 5 interns (2 retained full-time) and established data SOPs for cataloging, taxonomy, schema management, and optimization.

Freelance Data Scientist

Jan 2022 – Feb 2023

Upwork & Fiverr (Independent)

  • Delivered short 2–3 month freelance projects across hospitality, logistics, and healthcare (predictive modeling, BI dashboards, and lightweight data warehousing).
  • Built predictive modeling workflows for a hotel franchise across 4 counties and fleet dashboards + predictive repairs planning for a logistics company.
  • Delivered miniature PostgreSQL + Tableau data warehouse/reporting setups for 2 clinic operations teams.
Full experience details →

Education

Bachelor of Science in Mechatronic Engineering

Dedan Kimathi University of Technology · May 2017 – May 2022

Completed campus in Dec 2021 · Graduated May 2022 · Automotive Mechatronics specialization.

Certificate in Data Science

Moringa School · Feb 2022 – Nov 2022 (Part-time)

Certificate in DevOps Engineering

Moringa School · Aug 2023 – Dec 2023 (Intensive)

Cloud Computing Program

ALX Africa · Jan 2024 – Jun 2024

Certifications

In progress: KCSA · CKA · CKAD · CKS · HashiCorp Terraform Associate