Resume / CV: Oleksii Koshelenko, Senior Platform Engineer

Text Only
With Photo
$ whoami

Oleksii Koshelenko

Senior Platform Engineer
Multi-Cloud (Azure · GCP · AWS) | FinOps | CI/CD | Observability
443
VMs associated under observability, 389 legacy alerts analyzed, 28 rules deployed to production
62
Azure subscriptions under automated cost governance, proactive anomaly detection across all environments
694
automated tests gating a reusable 6-stage GitLab CI template, zero-downtime slot deploys
47 to 29
GB/day Log Analytics ingestion, ~81% syslog trim, so on-call noise and cost both drop
201K+
rows migrated across production databases via custom Python tooling with FK integrity handling
55
CI/CD variables audited, SQL secrets moved behind a User-Assigned Managed Identity
63K
lines of production Rust with 769 tests, plus a multi-agent audit harness catching pre-deploy defects
5+
enterprise teams coordinated across product, security, and cloud engineering in multiple time zones

Platform / DevOps engineer with 10 years keeping production systems alive in high-consequence, regulated environments: FinTech (PCI DSS), banking, healthcare, and industrial. Bare-metal and sysadmin roots, now focused on multi-cloud platform engineering across Azure, GCP, and AWS, specializing in FinOps and observability, designing cost governance, self-service CI/CD, and reliability that let product teams ship safely. I care about the cloud bill as much as the uptime.

Cloud PlatformsAzure (Monitor, Policy, Arc, Logic Apps, Key Vault, App Service, AKS, Automation, OpenAI), GCP (GKE, Cloud Run, IAM, Org Policy), AWS (Lambda, EC2, S3, IAM)
AI-Assisted EngineeringAI in the engineering loop, multi-agent fan-out/verify code audits, agent-assisted IaC review, repo-local agent skills, Claude Code, Cursor, Vertex AI / Gemini, LLM inference (Cloud Run, SSE streaming, provider failover)
Infrastructure as CodeTerraform, Terragrunt, Pulumi, OpenTofu, Bicep, Ansible, Policy-as-Code
CI/CD & AutomationGitLab CI, GitHub Actions, Azure DevOps, Jenkins, ArgoCD (GitOps), Automation Runbooks, Self-service Platforms (IDP)
Containers & OrchestrationDocker, Kubernetes (AKS, GKE), Helm
ObservabilityAzure Monitor, Log Analytics, DataDog, Grafana, Prometheus, Zabbix, KQL
Security & GovernanceZero-Trust (UAMI, OIDC, Workload Identity), Key Vault, Azure RBAC, Azure Policy, PCI DSS
FinOps & ReliabilitySRE, Cost Anomaly Detection, Budget Governance, Rightsizing, SLI/SLO & Error Budgets, Incident Response / On-call, AMBA Framework
Languages & SystemsRust (Tauri, async, AEAD/crypto, 63K LOC), Python, PowerShell, Bash, JavaScript, KQL, YAML

Senior Platform Engineer

DevOpsDive Consulting, Enterprise Cloud Engagements
Aug 2025 - Present
  • Analyzed 389 legacy SolarWinds alerts and deployed 28 service alert rules to production (Apr 2026) for a banking hybrid estate, designing 5 DCR types and 8 team-specific Action Groups via Bicep IaC and associating 443 VMs (413 VM + 22 SQL), with autonomous incident detection and no missed critical alerts over 4+ months.
  • Built a reusable 6-stage GitLab CI template (~995 lines) with coverage gates against 694 automated tests, zero-downtime slot deployments and UAMI zero-trust auth, and migrated two production .NET services onto it, making it the pattern for every subsequent service migration.
  • Redesigned monolithic log collection into role-specific DCR architecture, filtering Level 4 noise from 200+ servers and restricting AD/DNS/DFS to 6 Domain Controllers, eliminating redundant ingestion across the entire Windows fleet.
  • Implemented Azure Policy health check automation for 26 App Services with 5-round phased rollout through change advisory board approval in banking maintenance windows, with no customer-facing downtime.
  • Audited all 55 GitLab CI/CD variables on a production service, moved SQL connection-string secrets to Azure Key Vault behind a User-Assigned Managed Identity with no service-principal secrets, and identified 30 variables as dead.
  • Engineered a production-grade Rust systems codebase (offline-first sync engine, versioned AEAD crypto envelope on audited primitives) with a signed, notarized multi-target release pipeline and 769 tests; run a repo-local multi-agent audit harness over it and over production IaC, catching real defects (unscoped Key Vault, racing VNet peerings) before deploy.
  • Built autonomous capacity monitoring via Logic App and KQL, cutting the daily disk report from 103 to 33 rows through server-side NFS filtering, split Critical/Proactive thresholds by OS, and routed actionable alerts to Windows and Linux teams daily with zero manual intervention.
  • Cut Log Analytics ingestion from 47 to 29 GB/day and trimmed syslog volume by ~81% at a banking client, set up cost-anomaly coverage across 62 subscriptions, and created production budget alerts with per-team thresholds.
  • Worked GCP inside a multi-tenant enterprise estate for a global advertising group: cross-tenant migration scoping across 8 projects, IAM and ADC troubleshooting, org-policy and CI/CD onboarding patterns, plus Vertex AI and Cloud Run inference workloads. Google Cloud Professional DevOps Engineer certified.
  • Coordinated delivery across 5+ enterprise teams (product, TechOps, security, cloud engineering) spanning multiple time zones, built a developer onboarding platform with runbooks, architecture guides, and decision logs, reducing ramp-up from weeks to days.

Systems / DevOps Engineer, promoted to Cloud Platform Developer (Tech Lead)

EPAM Systems · Global eCommerce (Bosch), AWS security & cloud education | Azure & AWS
Sep 2023 - Aug 2025
  • Owned end-to-end DevOps for a global commerce platform (Bosch, Azure + AWS), shipping KQL observability dashboards that reduced incident triage 30%.
  • Provisioned Azure infrastructure via Terraform and GitHub Actions CI/CD for AKS-hosted services, with FinOps rightsizing delivering a meaningful recurring cost reduction.
  • Led a 4-engineer DevOps team building foundational Terraform modules (VNets, NSGs, Private DNS) and mentored 8+ engineers on IaC and CI/CD, presenting the platform architecture at an internal EPAM tech conference.
  • Delivered CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions) with Commercetools backup automation via Azure Logic Apps (RPO under 1 hour), and migrated an AWS security Lambda fleet (~50 functions) off EOL Python 3.8 to 3.11 with no broken integrations, and provided technical expertise at AWS Weeks 2024.

System Administrator

Involve Software (FinTech) · Contract, part-time
Feb 2024 - Oct 2024
  • Administered FinTech infrastructure (PCI DSS scope), managing VPN servers, MikroTik/UBNT networking, Ansible automation, and Grafana-based security monitoring while leading budget planning and IT procurement.

System Administrator, Team Lead

Profit Center FX (FinTech)
Nov 2022 - Sep 2023
  • Directed a 4-person IT team for a FinTech trading platform, deploying Zabbix monitoring that cut incident response by 60%, managing Proxmox/Docker/Jenkins CI/CD infrastructure with 99.9% uptime, and overseeing IT budget and procurement.

Computer Systems Engineer

CDC Pharmbiotest (Healthcare)
Feb 2020 - Jun 2022
  • Built CRM system from scratch that decreased processing time by 40%, deployed KVM virtualization and Zabbix monitoring, and automated 85% of routine IT tasks supporting 100+ users in clinical research.

Software Engineer / Design Engineer

PJSC LINIK (Oil Refining)
Apr 2016 - Feb 2020
  • Supported enterprise IT for 1,500+ users across industrial facilities, managing Active Directory, MS SQL Server, McAfee Endpoint Security, and automating system provisioning across refinery operations.
Professional Cloud DevOps EngineerGoogle Cloud
Azure Administrator Associate (AZ-104)Microsoft
Ethical HackerCisco
AWS Certified Cloud PractitionerAWS
Top 1000 Worldwide, Google Cloud Skills Boost 2024Google Cloud

Specialist, Laser & Optoelectronics Engineering

Kharkiv National University of Radio Electronics (KNURE)
2011 - 2015