Imran I.
Senior DevOps / SRE | AWS EKS, Kubernetes, Terraform, ArgoCD | CKA
Production Kubernetes and AWS platforms that stay up, ship weekly, and cost less. Ten-plus years in cloud infrastructure, the last four of them running the internal platform for Upwork itself. What that looked like at Upwork (Jun 2022 to Jul 2026, first as Sr. Cloud Operations and Automation Engineer, then Sr. Infrastructure Engineer): 50+ microservices across multiple EKS clusters on multi-account AWS, with about 15 core services held to a 99.9% availability SLO and managed on error budgets, all delivered through GitOps (ArgoCD) and Terraform. A zero-downtime migration of a production EKS management cluster with an in-place Kubernetes upgrade. Environment provisioning cut from 2 to 3 days to same day, release cadence doubled, cloud spend down 10 to 15% through rightsizing, production incidents resolved in under 15 minutes with written postmortems. In parallel, for a fintech payments platform (Edge and WhizPay, Oct 2024 to present): the entire AWS estate as Terraform across 6 environments, about 40 ECS Fargate microservices, 19 RDS Postgres instances, CloudFront, SQS and SNS, with per-service IAM roles, RDS IAM authentication and field-level encryption in place of static credentials. What I take on: - Kubernetes and EKS: cluster builds, upgrades and node group migrations, Helm, ArgoCD, PodDisruptionBudgets, autoscaling, StatefulSets (Kafka, Redis, Postgres) - Infrastructure as code: Terraform modules and state design, per-environment isolation, drift and import work, Ansible, Packer - CI/CD: GitHub Actions, Jenkins, Bitbucket Pipelines, ArgoCD, plan-before-apply gates, least-privilege GitHub Apps - Reliability: SLOs and error budgets, Prometheus and Thanos, Grafana, ELK and OpenSearch, alert tuning, on-call, runbooks, root-cause analysis - Security: least-privilege IAM, secrets management, KMS, WAF, VPC and PrivateLink design, OIDC and SSO, OS hardening, jump host and VPN hardening - Cost: rightsizing, reserved capacity and Savings Plans reviews, FinOps reporting How I work: everything lands as code plus a runbook, changes are planned before they are applied, and you get written updates you can forward without editing. Certified Kubernetes Administrator (CKA). Earlier career across Azure, GCP and OpenStack with a telecom networking background (BGP, VLANs, SDN, Juniper certified), which still shows up whenever a problem turns out to be DNS, routing or TLS. Top Rated Plus on Upwork with $400K+ earned across 15 hourly contracts. If your stack is AWS with Kubernetes or ECS and you need someone to own it properly, send the details and I will tell you in the first reply whether it is a fit.