Open for new projects · Q3 2026

Michal Ormos

DevSecOps Specialist · Stockholm & Bratislava

I build and operate secure cloud platforms. The boundary between development and operations is where most teams either accelerate or quietly bleed — I help them land on the right side of that line with automation, hardened pipelines and security treated as a first-class citizen.

What I do

I work as a DevSecOps specialist, currently splitting time between Stockholm and Bratislava. I help organisations design cloud platforms, ship automation and keep the lights on — with security baked in instead of bolted on at the end. Most of my recent work has been around AWS, Azure and vulnerability management at scale.

I prefer small, embedded engagements where I can see the system end-to-end: from the IAM policy to the IRSA-bound pod to the alert that pages someone at 03:00. Outside of contracts I mentor people moving into security and ops — from soft skills to the realities of running services in production.

based
Stockholm (SE) · Bratislava (SK) · CET timezone, async-friendly
focus
Cloud architecture · CI/CD · Security · Vulnerability management
languages
English · Slovak · Czech
edu
Brno University of Technology — Faculty of Information Technology
company
Independent · SK business reg. 54788722

Tools I use

Cloud

  • AWS
  • Azure
  • Google Cloud
  • Alibaba Cloud

Platform & Ops

  • Linux
  • Docker
  • Kubernetes
  • Terraform
  • Ansible
  • GitHub Actions
  • GitLab CI
  • ArgoCD

Languages & Data

  • Python
  • Bash
  • Go
  • SQL
  • PostgreSQL
  • MySQL

Security

  • Vulnerability management
  • SAST / DAST
  • SBOM
  • Cloud hardening
  • IAM design
  • Secrets management
  • Incident response

Observability

  • Prometheus
  • Grafana
  • CloudWatch
  • OpenTelemetry
  • ELK

Verified

AWS Solutions Architect — Associate AWS · 2024
Microsoft Azure Administrator AZ-104 · 2024
Microsoft Azure Security Engineer AZ-500 · 2024
Certified Kubernetes Administrator CKA · 2025
ISO/IEC 27001 Lead Implementer PECB · 2025
HashiCorp Certified: Terraform Associate 003 · 2025

How I can help

Cloud architecture

Designing platforms on AWS, Azure or GCP — multi-account organisations, network topology, IAM, cost guardrails. Secure defaults, room to grow.

Automation & CI/CD

From local dev loops to production pipelines with SAST, DAST, SBOM and policy gates baked in. Less clicking, more shipping.

Cloud operations

Day-to-day running of cloud platforms — observability, alerting, incident response and uptime you can actually measure.

Security review & hardening

Reviewing IAM, network exposure, secrets handling and supply chain. Finding the cracks before someone else does.

Vulnerability management

Building or operationalising vulnerability management — from scanner deployment to triage workflows and SLAs that don't drown teams.

Mentoring

1:1 mentoring for engineers moving into DevOps, SRE or security. Technical and the human side — career, interviews, on-call.

How engagements work

Discovery

30-min intro call, then a short paid discovery (1–3 days) to map the system, risks and goals. You get a written brief either way.

Plan

Scoped proposal: outcomes, milestones, who does what. Fixed-price or daily rate, your call. No retainers you can't cancel.

Ship

Embedded with your team. Code, IaC and runbooks live in your repos from day one. Weekly written updates.

Hand-over

Documentation, training and a clean exit. The goal is your team running things confidently without me.

Selected work

A few anonymised projects. Details on request under NDA.

Stockholm · SaaS · 2025

AWS Organization hardening for a mid-market SaaS

Inherited a single-account AWS environment, no SCPs, IAM Users for humans, shared root credentials. Rebuilt as multi-account Organization with SSO, Control Tower guardrails, IAM Identity Center and a baseline that survives audits.

30 days to baseline 0 human IAM users left SOC 2 audit passed first pass
EU · FinTech · 2024

CI/CD with security gates without slowing the team

Pipelines were "passing" with secrets in repos and outdated base images. Designed a GitHub Actions pipeline with SAST (Semgrep), DAST (ZAP), container scanning (Trivy), SBOM (Syft) and OIDC-based deploys. Gates fail builds with clear, actionable output.

~6 min total pipeline time 0 static credentials in CI −40% high-sev findings in 90 days
EU · B2B platform · 2024

Vulnerability management that engineers actually use

Scanner data lived in a dashboard nobody opened. Wired findings into the team's existing tracker with risk-based SLAs, owner routing and weekly digest. Built a small Python service to deduplicate and prioritise.

−70% MTTR on critical findings 1 source of truth instead of three 3 security FTEs freed up

What people say

Michal joined for what we thought was a 4-week cleanup and ended up rewriting our whole AWS landing zone. The boring stuff finally works.
— Engineering Manager · SaaS, Stockholm
Pragmatic, calm, asks the right questions. We have a security posture our auditors stop arguing with.
— CTO · FinTech, EU
Best 1:1 mentor I had moving from sysadmin to SRE. Direct, no fluff, and actually checks in.
— SRE · ex-mentee, now at scale-up

Recent posts

Hardening an AWS Organization in 30 days: a practical checklist CI/CD security gates that don't slow the team down Vulnerability management at scale: what actually matters

all writing →

Notes from the field

Say hello

Open to interesting work, collaborations and mentoring. The fastest way to reach me is a 30-min intro call — or just email.

Stockholm

Sweden · CET
info@michalormos.eu +46 76 100 25 39

Bratislava

Slovakia · CET
info@michalormos.eu +421 918 061 863