Gideon Warui
Cloud Platform & DevSecOps Engineer
Summary
Cloud Platform & DevSecOps Engineer with 4+ years of experience across enterprise finance, fintech, NGO, and media. Core stack: Kubernetes (AWS EKS, Azure AKS, microk8s), Helm chart authoring, Terraform IaC across Azure and AWS, ArgoCD GitOps, and end-to-end CI/CD and DevSecOps automation. I build and operate production multi-cloud K8s platforms — including a full AWS EKS + Terraform + ArgoCD platform for a fintech startup, built and maintained solo (part-time, 2+ years) — and lead observability, cost-optimization, and AI enablement workstreams. In 2026, I am running a 78-lab public Kubernetes AI Infrastructure Lab program on AKS — covering GPU serving (vLLM/Triton), KEDA/HPA autoscaling, RAG systems, observability, and FinOps — everything provisioned and maintained with Terraform and Helm.
2026 Build Program (Public)
AI Infrastructure Lab Curriculum 2026 — a 45-week AKS-based lab program focused on Kubernetes internals, GPU model serving (vLLM/Triton), RAG systems, KEDA/HPA autoscaling, observability, chaos testing, and FinOps.
- ›~80 labs, 1–2 days each, namespace-isolated, instrumented, measurable, teardown-friendly
- ›2 posts/week cadence (~84 code-heavy posts): Monday infra concept + Thursday AI concept
- ›Goal: publish reproducible evidence of AI infrastructure depth (not tutorial summaries)
Core Skills
KUBERNETES, HELM & TERRAFORM
- › Kubernetes — AKS · microk8s · kubeadm · multi-cluster operations · upgrades · scaling
- › Helm — chart authoring · templating · multi-env values · lifecycle management · upgrades
- › Terraform — Azure + AWS IaC · modules · workspaces · remote state · multi-environment
- › AWS — EKS · VPC · RDS · ECR · S3 · IAM/IRSA · Secrets Manager · Karpenter
- › Azure — AKS · VNets/Subnets · Functions · Front Door · Cloudflare failover · Traefik
DEVSECOPS, SRE & OBSERVABILITY
- › Azure DevOps CI/CD · GitHub Actions · ArgoCD (GitOps)
- › Trivy · Semgrep · Falco · Cosign
- › Prometheus · Grafana · Log Analytics · KQL
- › Incident response · DR planning · SLO-driven reliability
- › Kubecost · Azure Cost Management · FinOps reporting
DATA, ANALYTICS & AI SYSTEMS
- › Python · SQL · FastAPI · dbt
- › Data pipelines / ELT · Medallion architecture · DWH/Lakehouse
- › Azure AI Foundry · AI workflow integration + governance
- › RAG systems · pgvector · vector search patterns
- › Zoho Analytics · Tableau · Power BI
CURRENT LAB FOCUS (2026)
- › AKS GPU nodepools (T4/A100) · vLLM · Triton
- › KEDA/HPA autoscaling for LLM workloads
- › Qdrant / pgvector · RAG observability
- › Prometheus · Grafana · Loki for AI infra labs
- › Terraform + Helm lab automation
Experience
Cloud Platform & DevSecOps Engineer
Nov 2024 – PresentOld Mutual Group East Africa (via Invent Consulting)
- ›Hands-on senior IC with de facto platform ownership across ~10 production AKS clusters supporting ~20 internal teams and ~5 vendor teams.
- ›Built CI/CD + DevSecOps baseline from scratch across 9+ projects using GitHub Actions, Terraform (multi-environment AKS provisioning + modules), and Helm chart management; reduced deployment TAT from ~8 hours (manual) to ~10 minutes dev→staging and ~2–5 minutes to prod after approvals.
- ›Improved flagship platform reliability from ~90% to formal ~99.9% SLO/uptime and defined reusable DR blueprints (multi-AZ AKS, HA DBs, Cloudflare -> Azure Front Door failover).
- ›Built and operate production Azure AI Foundry tooling for Risk/Compliance/Audit/Ops; improved workflow accuracy from ~80% target to ~95% with governance + observability controls.
- ›Identified ~US$150K/year savings on a managed Azure subscription scope (~US$47K/month baseline), with ~US$30K/year already implemented.
Solutions Architect & Platform/Infrastructure Engineer
2024 – PresentSyndikiza (Fintech) · Independent · Part-time
- ›Designed and built the entire AWS + Kubernetes platform from scratch — VPC, EKS (K8s 1.34), RDS PostgreSQL (prod + nonprod), ECR, IAM/IRSA, Secrets Manager, and S3 — all provisioned via custom Terraform modules (vpc, eks, rds-postgres, secrets-manager).
- ›Operate 16 ArgoCD applications across dev and production environments serving 5 microservices (Django + Java); automated GitOps with self-heal, unlimited retry, and Kustomize base/overlay pattern across all app repos.
- ›Authored and maintain Helm-deployed platform stack: Traefik Gateway API (ingress + TLS termination), cert-manager (Let's Encrypt automation), Karpenter (spot + on-demand node autoscaling), External Secrets Operator (AWS Secrets Manager → K8s Secrets), and VictoriaMetrics/Loki/Grafana observability.
- ›Implemented HPA (autoscaling/v2) for all production Django services and Karpenter NodePool taint patterns to isolate production workloads on on-demand nodes; achieved cost-optimized platform at ~$185–270/month through single shared cluster + spot instance strategy.
- ›Delivered full security posture: IRSA for pod-level AWS access (no long-lived credentials), non-root containers, read-only root filesystems, Security Group least-privilege, and AWS CloudTrail + K8s audit logging.
Senior Data & AI Platform Engineer
Nov 2024 – Feb 2026NCBA Bank — CarDuka Platform (via Invent Consulting)
- ›Started with a V1 CI/CD enablement sprint (GitHub Actions deployment automation), then expanded into V2 data/AI/platform engineering for the marketplace rebuild.
- ›Owned data architecture, pipelines, warehouse/lakehouse evolution, and DB operations across ~21 databases; expanded into AKS/Kubernetes debugging, Helm-managed deployments, Terraform infrastructure updates, observability, and autoscaling work with NCBA cloud/DevOps teams.
- ›Built production/pilot AI and data features including valuation, Similar Cars, CLM/LTV, liquidity balancing, RAG-based review/search, KYC processing, and content moderation workflows.
- ›Impact highlights: Similar Cars increased listing views ~3x; valuation engine improved pricing/listing accuracy ~13%; KYC pilot reduced verification TAT from ~24h to <1h.
- ›Designed and secured approval for the reusable Azure architecture + CI/CD templates for the broader Duka marketplace roadmap through 2028.
Data Architect & Data Engineer
Jul 2024 – Feb 2025World Relief (East & Central Africa) (via Invent Consulting)
- ›Designed and delivered a Microsoft Fabric lakehouse + self-service data platform integrating 1,400+ datasets across 6+ countries.
- ›Replaced manual Excel + R-script reporting workflows with automated daily pipelines, improving reporting/data turnaround from ~2 weeks to daily refreshes.
- ›Shipped a production FastAPI self-service data API/platform on Azure Container Apps with Entra ID country-scoped RBAC and multi-format exports (Excel/CSV/TSV/JSON/XML).
- ›Trained and onboarded teams in Kenya, Uganda, and Rwanda; handed over the production platform after funding cuts constrained wider rollout.
Data Lead & Data Engineer
Feb 2023 – Aug 2024Yakwetu Online Limited
- ›Joined as first data hire; designed and built the AWS data/analytics platform from scratch — architecture decisions, service selection (S3 data lake, EC2 compute, CloudWatch observability, IAM access controls), and full platform operations — progressing from Data Engineer to Data Lead.
- ›Built recommendation and watch analytics systems that increased transactions (~8%), reduced abandonment (~15%), and improved engagement/watch time.
- ›Optimized ad campaign spend (~10% reduction) while bringing CPC below $0.03 and established Tableau reporting for revenue/content/campaign visibility.
- ›Helped hire 5 interns (2 retained full-time) and established data SOPs for cataloging, taxonomy, schema management, and optimization.
Freelance Data Scientist
Jan 2022 – Feb 2023Upwork & Fiverr (Independent)
- ›Delivered short 2–3 month freelance projects across hospitality, logistics, and healthcare (predictive modeling, BI dashboards, and lightweight data warehousing).
- ›Built predictive modeling workflows for a hotel franchise across 4 counties and fleet dashboards + predictive repairs planning for a logistics company.
- ›Delivered miniature PostgreSQL + Tableau data warehouse/reporting setups for 2 clinic operations teams.
Education
Bachelor of Science in Mechatronic Engineering
Dedan Kimathi University of Technology · May 2017 – May 2022
Completed campus in Dec 2021 · Graduated May 2022 · Automotive Mechatronics specialization.
Certificate in Data Science
Moringa School · Feb 2022 – Nov 2022 (Part-time)
Certificate in DevOps Engineering
Moringa School · Aug 2023 – Dec 2023 (Intensive)
Cloud Computing Program
ALX Africa · Jan 2024 – Jun 2024
Certifications
AWS Certified Solutions Architect – Associate
Amazon Web Services · 2025 – 2028
AWS Certified Cloud Practitioner
Amazon Web Services · 2025 – 2028
Kubernetes and Cloud Native Associate (KCNA)
CNCF · 2025 – 2028
Google Professional Data Engineer
Google Cloud · 2025 – 2027
In progress: KCSA · CKA · CKAD · CKS · HashiCorp Terraform Associate