Cloud architecture
Designing platforms on AWS, Azure or GCP — multi-account organisations, network topology, IAM, cost guardrails. Secure defaults, room to grow.
I build and operate secure cloud platforms. The boundary between development and operations is where most teams either accelerate or quietly bleed — I help them land on the right side of that line with automation, hardened pipelines and security treated as a first-class citizen.
I work as a DevSecOps specialist, currently splitting time between Stockholm and Bratislava. I help organisations design cloud platforms, ship automation and keep the lights on — with security baked in instead of bolted on at the end. Most of my recent work has been around AWS, Azure and vulnerability management at scale.
I prefer small, embedded engagements where I can see the system end-to-end: from the IAM policy to the IRSA-bound pod to the alert that pages someone at 03:00. Outside of contracts I mentor people moving into security and ops — from soft skills to the realities of running services in production.
Designing platforms on AWS, Azure or GCP — multi-account organisations, network topology, IAM, cost guardrails. Secure defaults, room to grow.
From local dev loops to production pipelines with SAST, DAST, SBOM and policy gates baked in. Less clicking, more shipping.
Day-to-day running of cloud platforms — observability, alerting, incident response and uptime you can actually measure.
Reviewing IAM, network exposure, secrets handling and supply chain. Finding the cracks before someone else does.
Building or operationalising vulnerability management — from scanner deployment to triage workflows and SLAs that don't drown teams.
1:1 mentoring for engineers moving into DevOps, SRE or security. Technical and the human side — career, interviews, on-call.
30-min intro call, then a short paid discovery (1–3 days) to map the system, risks and goals. You get a written brief either way.
Scoped proposal: outcomes, milestones, who does what. Fixed-price or daily rate, your call. No retainers you can't cancel.
Embedded with your team. Code, IaC and runbooks live in your repos from day one. Weekly written updates.
Documentation, training and a clean exit. The goal is your team running things confidently without me.
A few anonymised projects. Details on request under NDA.
Inherited a single-account AWS environment, no SCPs, IAM Users for humans, shared root credentials. Rebuilt as multi-account Organization with SSO, Control Tower guardrails, IAM Identity Center and a baseline that survives audits.
Pipelines were "passing" with secrets in repos and outdated base images. Designed a GitHub Actions pipeline with SAST (Semgrep), DAST (ZAP), container scanning (Trivy), SBOM (Syft) and OIDC-based deploys. Gates fail builds with clear, actionable output.
Scanner data lived in a dashboard nobody opened. Wired findings into the team's existing tracker with risk-based SLAs, owner routing and weekly digest. Built a small Python service to deduplicate and prioritise.
Michal joined for what we thought was a 4-week cleanup and ended up rewriting our whole AWS landing zone. The boring stuff finally works.— Engineering Manager · SaaS, Stockholm
Pragmatic, calm, asks the right questions. We have a security posture our auditors stop arguing with.— CTO · FinTech, EU
Best 1:1 mentor I had moving from sysadmin to SRE. Direct, no fluff, and actually checks in.— SRE · ex-mentee, now at scale-up
Open to interesting work, collaborations and mentoring. The fastest way to reach me is a 30-min intro call — or just email.