Download PDF

Executive Profile

Platform Architect & Automation Consultant

Architectural ownership backed by 15+ years of hands-on experience delivering secure, production-ready platforms for complex and regulated environments. Translates infrastructure, security, and operational requirements into maintainable solutions—with automation, repeatability, and reliable Day-2 operations built in from the start.

Red Hat Certified Architect with broad expertise across Linux and container infrastructure, automation, virtualization, cloud integration, networking, identity, security, observability, and lifecycle management. Works with technology partners such as Red Hat, JFrog, and HashiCorp while remaining vendor-neutral, choosing supported solutions or open-source and community alternatives according to each customer's support model, risk, and operating requirements.

Automation is the central design principle across deployment, configuration, security controls, lifecycle processes, and operations. Tracks emerging technologies, open-source developments, and AI-assisted engineering, adopting them where they improve delivery without compromising security, auditability, maintainability, or operational resilience.

Combines deep technical execution with customer-facing architecture leadership: leads workshops, defends design decisions, translates business, regulatory, and security requirements into actionable architectures, and guides cross-functional teams through implementation and handover. Aligns solutions with BSI IT-Grundschutz, CIS Benchmarks, and customer-specific governance requirements.

Career Highlights

Designed and operated Red Hat OpenShift 4 platforms on VMware vSphere for regulated environments. Applied Red Hat Advanced Cluster Management (ACM) governance and Red Hat Advanced Cluster Security (ACS) vulnerability, compliance, and runtime controls aligned with BSI IT-Grundschutz.

Implemented multiple Red Hat OpenShift 4 platforms on bare-metal infrastructure. Automated installation with Ansible and Python, integrated Cumulus Linux networking, established Argo CD GitOps workflows, and deployed Prometheus and Grafana monitoring.

Built containerized Red Hat Ansible Automation Platform deployments for disconnected RHEL 9 and 10 environments. Implemented Automation Controller, Private Automation Hub, zone-based Execution Nodes, and offline repositories; validated services before handover.

Converted CIS Level 2 and BSI IT-Grundschutz requirements into repeatable RHEL hardening. Automated assessment, categorization, remediation, and tracking with Python and Ansible; validated controls with OpenSCAP and reference hosts, then staged rollout by system role, criticality, and risk.

Extended Red Hat Satellite 6 across data centers, AWS, and restricted networks. Implemented Capsule-based content distribution, registration, provisioning, and patching; validated connectivity and package flows, and documented handover.

Integrated platform delivery services into auditable workflows. Connected GitLab and GitLab Runner with Argo CD for version-controlled deployment, Red Hat Build of Keycloak for OAuth 2.0/OpenID Connect authentication, HashiCorp Vault for secrets, and JFrog Artifactory with JFrog Xray for artifact distribution and vulnerability scanning.

Turned project implementations into reusable architecture and operating assets. Produced security and governance concepts, platform blueprints, automation workflows, runbooks, and handover documentation; reused them through ModuLix, AIO, and PGE.

Selected Certifications

Red Hat Certified Architect (RHCA) · Certification ID: 140-083-502

  • Automation & Configuration — EX447 · EX407 · EX405
  • OpenShift & Containers — EX288 · EX280 · EX180
  • Security & Diagnostics — EX413 · EX342
  • Infrastructure & Virtualization — EX403 · EX401 · EX318
  • Core RHEL — EX300 (RHCE) · EX200 (RHCSA)

Further certifications are listed in the Certifications section at the end of this CV.

Selected Project Highlights

01/2026Present

Enterprise OpenShift Security & Container Platform Operations

Federal Institute in Bonn, Germany

Technical Role: Architect & DevOps Engineer

Scope: Secure production operations, multi-cluster governance, platform security, GitOps, and lifecycle management.

Result: Transitioned an enterprise OpenShift platform into stable, security-focused production operations.

Key Contributions:
• Advanced multi-cluster governance, compliance, vulnerability management, and runtime security with ACS and ACM.
• Established controlled GitOps, CI/CD, Identity and Access Management (IAM), secrets, artifact, lifecycle, and Day-2 operational workflows.

Technologies: OpenShift 4, ACS, ACM, Argo CD, GitLab, GitLab Runner, Keycloak, Vault, Satellite, Cisco ACI

01/2026Present

ModuLix & AIO 2.0

Lightning IT GmbH & Co. KG in Zossen, Germany

Technical Role: Product Architect – Platform Automation & Delivery

Scope: Product architecture, reusable platform blueprints, automation governance, and self-service operations.

Result: Productized field-proven platform and automation patterns into reusable delivery blueprints and governed workflows.

Key Contributions:
• Defined modular building blocks across infrastructure, security, GitOps, Identity and Access Management (IAM), observability, storage, and operations.
• Established repeatable, audit-ready delivery models and governed self-service workflows for regulated environments.

Technologies: OpenShift, Ansible Automation Platform, Satellite, RHEL, GitLab, Vault, GitOps, Identity and Access Management (IAM), monitoring, DevSecOps

06/202606/2026

Containerized Ansible Automation Platform on RHEL

Government Administration in Bonn, Germany

Technical Role: Architect & DevOps Engineer

Scope: Air-gapped platform architecture, automated deployment, Execution Node design, and operational enablement.

Result: Delivered a repeatable containerized automation platform for a disconnected environment.

Key Contributions:
• Designed Automation Controller, Private Automation Hub, and a distributed, zone-based Execution Node architecture.
• Automated platform deployment and validated offline dependencies, service availability, and operational readiness.

Technologies: Ansible Automation Platform, RHEL 9, Ansible, Automation Controller, Private Automation Hub, Execution Nodes, air-gapped operations

06/202606/2026

Enterprise RHEL CIS Hardening & Remediation Automation

Finance Company in Munich, Germany

Technical Role: Cybersecurity Hardening Specialist

Scope: Security architecture, CIS Level 2 hardening across RHEL 8, 9, and 10, remediation automation, and rollout management.

Result: Established a controlled, repeatable hardening and remediation model across multiple RHEL generations.

Key Contributions:
• Built Python- and Ansible-based assessment, system categorization, remediation, and tracking workflows.
• Validated measures on reference hosts and defined risk-based rollout waves by role, criticality, and OS version.

Technologies: RHEL 8, RHEL 9, RHEL 10, CIS Benchmarks, Python, Ansible, OpenSCAP, security baselines, remediation automation

01/202501/2026

Enterprise OpenShift Security & Container Platform

Federal Institute in Bonn, Germany

Technical Role: Architect & DevOps Engineer

Scope: Secure multi-cluster architecture, governance, GitOps delivery, identity, secrets, and platform services.

Result: Designed and implemented a secure OpenShift foundation for production application delivery.

Key Contributions:
• Integrated ACS and ACM for centralized security, compliance, vulnerability management, and governance.
• Established Argo CD and GitLab delivery workflows with Keycloak, Vault, and Artifactory platform services.

Technologies: OpenShift 4, VMware vSphere, ACS, ACM, Argo CD, GitLab, GitLab Runner, Keycloak, Vault, Artifactory, GitOps, Identity and Access Management (IAM)

12/202412/2024

Red Hat Satellite 6 Capsule Extension on AWS

Finance Company in Munich, Germany

Technical Role: Architect & DevOps Engineer

Scope: Distributed lifecycle management, cloud-connected content delivery, patching, and host administration.

Result: Extended enterprise lifecycle management to distributed AWS-connected infrastructure.

Key Contributions:
• Designed and implemented Satellite Capsule Servers with distributed content synchronization on AWS.
• Enabled registration, patching, and host management, then validated connectivity and documented operational handover.

Technologies: Red Hat Satellite 6, Satellite Capsule Server, RHEL, AWS, Ansible, patch management, content distribution, lifecycle management

Appendix — Detailed Project Portfolio & Career History

01/2026Present

Enterprise OpenShift Security & Container Platform Operations

Federal Institute in Bonn, Germany

Technical Role: Architect & DevOps Engineer
Scope: Secure platform operations, Day-2 enablement, automation, governance and lifecycle management
Result: Transitioned an enterprise OpenShift 4 platform from project implementation into stable production operations.
Key Contributions:
• Operated and further developed multiple OpenShift 4 clusters on VMware vSphere.
• Integrated Red Hat Advanced Cluster Security for Kubernetes to support vulnerability management, compliance checks and runtime security.
• Implemented centralized multi-cluster governance and operational control with ACM.
• Established GitOps-based delivery and controlled application deployment workflows with Argo CD.
• Integrated GitLab and GitLab Runner on OpenShift to support secure CI/CD processes.
• Established Red Hat Build of Keycloak as a central identity and access management service for platform and application authentication.
Technologies: OpenShift 4, Red Hat Advanced Cluster Security for Kubernetes, ACM, Argo CD, GitLab, GitLab Runner, Ansible Automation Platform, Red Hat Satellite, HashiCorp Vault, JFrog Artifactory, Red Hat Build of Keycloak, OAuth 2.0, OpenID Connect, Identity and Access Management (IAM), Cisco ACI, Python, GitOps, CI/CD, Day-2 operations

01/2026Present

ModuLix & AIO 2.0 — Platform Automation Products

Lightning IT GmbH & Co. KG in Zossen, Germany

Technical Role: Product Architect – Platform Automation & Delivery
Responsible for the product architecture and technical strategy of ModuLix and AIO 2.0, two platform automation products designed to standardize, automate and secure enterprise IT delivery. Focused on transforming field-proven architecture and implementation patterns into reusable components, automation workflows, blueprints and customer-deployable platform solutions for regulated IT environments.

ModuLix - Modular Platform Delivery Product
Scope: Product architecture, modular platform design, blueprint-based delivery and automation standardization
Result: Designed ModuLix as a modular product for standardized enterprise platform delivery.
Key Contributions:
• Defined the modular product architecture for platform delivery across infrastructure, automation, security and operations domains.
• Designed reusable building blocks for GitOps, Identity and Access Management (IAM), observability, storage, automation, security and platform operations.
• Created blueprint-based delivery models to support standardized customer implementations and project variants.
• Aligned the product structure with regulated IT requirements, including security, auditability, repeatability and operational consistency.
Technologies: Red Hat OpenShift, Ansible Automation Platform, Red Hat Satellite, RHEL, GitLab, Vault, GitOps, Identity and Access Management (IAM), monitoring, DevSecOps, platform automation

AIO 2.0 - Enterprise Automation & Operations Platform
Scope: Product architecture, automation governance, self-service operations and platform lifecycle automation
Result: Designed AIO 2.0 as an enterprise automation and operations platform for secure infrastructure delivery.
Key Contributions:
• Defined the product architecture for a secure enterprise automation and operations platform.
• Designed reusable automation modules for provisioning, lifecycle management, patching, compliance hardening and platform operations.
• Introduced governed self-service workflows with RBAC, approval flows, execution permissions and audit logging.
• Aligned the platform with enterprise requirements for RHEL, OpenShift, Satellite, Ansible Automation Platform, GitOps and regulated infrastructure operations.
Technologies: Semaphore, Ansible, Ansible Collections, Ansible Execution Environments UI, RHEL, OpenShift, Red Hat Satellite, Ansible Automation Platform, GitOps, RBAC, DevSecOps, compliance automation

06/202606/2026

Containerized Ansible Automation Platform on RHEL 9

Government Administration in Bonn, Germany

Technical Role: Architect & DevOps Engineer
Scope: Air-gapped platform architecture, containerized implementation, execution node design and operational enablement
Result: Designed and implemented a containerized Red Hat Ansible Automation Platform deployment for an air-gapped environment on Red Hat Enterprise Linux 9.
Key Contributions:
• Planned the target architecture for a containerized AAP deployment in a disconnected environment.
• Designed the Execution Node layout with multiple nodes per zone to support distributed automation execution.
• Automated installation and configuration activities using Ansible to ensure repeatable deployments.
• Implemented core AAP components including Automation Controller and Private Automation Hub for internal content distribution.
• Integrated offline installation sources, repositories and platform dependencies required for air-gapped operations.
• Configured Execution Nodes for zoned infrastructure access and controlled automation execution.
Technologies: Red Hat Ansible Automation Platform, Red Hat Enterprise Linux 9, Ansible, Private Automation Hub, Execution Nodes, platform automation

06/202606/2026

Enterprise RHEL CIS Hardening & Remediation Automation

Finance Company in Munich, Germany

Technical Role: Cybersecurity Hardening Specialist
Scope: Security architecture, CIS hardening, Python-based automation framework and rollout management
Result: Designed a CIS Level 2 Server hardening approach for Red Hat Enterprise Linux 8 and 9 systems.
Key Contributions:
• Defined the target hardening approach based on CIS Level 2 Server requirements for RHEL 8 and RHEL 9.
• Developed Python-based automation to support system categorization, hardening assessment and remediation tracking.
• Automated the collection and processing of system data to identify deviations from the required security baseline.
• Planned and implemented remediation measures on selected reference hosts.
• Validated hardening impact on system functionality, operational stability and maintainability.
• Developed a rollout concept based on operating system version, system role, criticality and remediation complexity.
Technologies: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, CIS Benchmarks, CIS Level 2 Server, Python, Ansible, OpenSCAP, remediation automation, security baselines

05/202606/2026

Containerized Ansible Automation Platform on RHEL 9

Federal Institute in Bonn, Germany

Technical Role: Architect & DevOps Engineer
Scope: Air-gapped platform architecture, containerized implementation, Ansible automation and operational enablement
Result: Designed and implemented a containerized Red Hat Ansible Automation Platform deployment for an air-gapped environment on Red Hat Enterprise Linux 9.
Key Contributions:
• Planned the target architecture for a containerized AAP deployment in a disconnected environment.
• Automated installation and configuration activities using Ansible to ensure repeatable deployments.
• Implemented core AAP components including Automation Controller and Private Automation Hub for internal content distribution.
• Integrated offline installation sources, repositories and platform dependencies required for air-gapped operations.
• Validated deployment consistency, service availability and operational readiness in a disconnected environment.
Technologies: Red Hat Ansible Automation Platform, Red Hat Enterprise Linux 9, Ansible, Private Automation Hub, platform automation

05/202605/2026

Containerized Ansible Automation Platform on RHEL 10

Government Administration in Bonn, Germany

Technical Role: Architect & DevOps Engineer
Scope: Air-gapped platform architecture, containerized implementation, Ansible automation and operational enablement
Result: Designed and implemented a containerized Red Hat Ansible Automation Platform deployment for an air-gapped environment on Red Hat Enterprise Linux 10.
Key Contributions:
• Planned the target architecture for a containerized AAP deployment in a disconnected environment.
• Automated installation and configuration activities using Ansible to ensure repeatable deployments.
• Implemented core AAP components including Automation Controller and Private Automation Hub for internal content distribution.
• Integrated offline installation sources, repositories and platform dependencies required for air-gapped operations.
• Validated deployment consistency, service availability and operational readiness in a disconnected environment.
Technologies: Red Hat Ansible Automation Platform, Red Hat Enterprise Linux 10, Ansible, Private Automation Hub, platform automation

02/202604/2026

Containerized Ansible Automation Platform on RHEL 10

Supply Chain Management Company in Bonn, Germany

Technical Role: Architect & DevOps Engineer
Scope: Air-gapped platform architecture, containerized implementation, Ansible automation and operational enablement
Result: Designed and implemented a containerized Red Hat Ansible Automation Platform deployment for an air-gapped environment on Red Hat Enterprise Linux 10.
Key Contributions:
• Planned the target architecture for a containerized AAP deployment in a disconnected environment.
• Automated installation and configuration activities using Ansible to ensure repeatable deployments.
• Implemented core AAP components including Automation Controller and Private Automation Hub for internal content distribution.
• Integrated offline installation sources, repositories and platform dependencies required for air-gapped operations.
• Validated deployment consistency, service availability and operational readiness in a disconnected environment.
Technologies: Red Hat Ansible Automation Platform, Red Hat Enterprise Linux 10, Ansible, Private Automation Hub, Linux, platform automation

01/202604/2026

Rancher Kubernetes Platform on OVH Cloud

IT Security Service Provider Company in Essen, Germany

Technical Role: Architect & DevOps Engineer
Scope: Kubernetes platform implementation, cloud infrastructure setup, GitOps automation and operational enablement
Result: Designed and implemented a Kubernetes platform on OVH Cloud managed through Rancher.
Key Contributions:
• Deployed and configured Rancher for centralized Kubernetes cluster management.
• Integrated Argo CD to enable GitOps-based application deployment and configuration management.
• Used Ansible to automate infrastructure setup, platform configuration and recurring operational tasks.
• Set up an Ubuntu workbench system with graphical access via XRDP for Kubernetes administration.
• Configured management access paths, operational tooling and basic handover documentation.
Technologies: OVH Cloud, Kubernetes, Rancher, Argo CD, Ansible, GitOps, Ubuntu, XRDP, platform automation

01/202501/2026

Enterprise OpenShift Security & Container Platform

Federal Institute in Bonn, Germany

Technical Role: Architect & DevOps Engineer
Scope: Secure platform architecture, implementation, automation, governance and production enablement
Result: Designed and implemented an enterprise container platform based on Red Hat OpenShift 4 on VMware vSphere.
Key Contributions:
• Architected and implemented multiple OpenShift 4 clusters on VMware vSphere.
• Integrated Red Hat Advanced Cluster Security for Kubernetes to support vulnerability management, compliance checks and runtime security.
• Implemented centralized multi-cluster governance and operational control with ACM.
• Established GitOps-based delivery and controlled application deployment workflows with Argo CD.
• Integrated GitLab and GitLab Runner on OpenShift to support CI/CD processes with a stronger focus on secure delivery workflows.
• Established Red Hat Build of Keycloak as a central identity and access management service for platform and application authentication.
Technologies: OpenShift 4, VMware vSphere, Red Hat Advanced Cluster Security for Kubernetes (ACS), ACM, Argo CD, GitLab, GitLab Runner, Ansible Automation Platform, HashiCorp Vault, JFrog Artifactory, Red Hat Build of Keycloak, OAuth 2.0, OpenID Connect, Identity and Access Management (IAM), Cisco ACI, Python, GitOps, CI/CD, container security

09/202512/2025

OVH Cloud Secure VPN Integration

IT Security Service Provider Company in Essen, Germany

Technical Role: Cybersecurity Specialist and Architect
Scope: Security architecture, network design, VPN integration and cloud connectivity planning
Result: Designed the secure connectivity concept between an OVH Cloud environment and private IT infrastructure.
Key Contributions:
• Designed the target architecture for VPN-based connectivity between OVH Cloud and private IT environments.
• Planned the network layout, routing approach and segmentation model for a high-security environment.
• Translated proprietary VPN client requirements into infrastructure and Kubernetes integration concepts.
• Documented the security architecture, network design assumptions and implementation recommendations.
Technologies: OVH Cloud, Kubernetes, VPN, proprietary VPN client, cloud networking, network segmentation, routing, security architecture, secure connectivity

09/202509/2025

Keycloak Workshop & Training Environment

IT Service Provider in Siegburg, Germany

Technical Role: Corporate Trainer
Scope: Workshop delivery, training material creation and self-service lab enablement
Result: Delivered a compact Keycloak workshop based on a pre-provisioned lab environment.
Key Contributions:
• Prepared a self-contained Keycloak lab environment with Docker Compose.
• Created workshop materials, examples and guided exercise documentation.
• Delivered hands-on training covering realms, clients, users, roles and authentication basics.
• Supported participants during practical exercises and basic troubleshooting.
Technologies: Keycloak, Docker Compose, Identity and Access Management (IAM), OAuth 2.0, OpenID Connect, technical training

09/202406/2025

Implementation of Several Container Platforms

Supply Chain Management Company in Bonn, Germany

Technical Role: Architect & DevOps Engineer
Scope: Platform architecture, implementation, automation and operational enablement
Result: Designed and implemented multiple Red Hat OpenShift 4 container platforms.
Key Contributions:
• Architected and implemented multiple OpenShift clusters for enterprise container workloads.
• Designed and implemented platform and application monitoring with Prometheus, Grafana and the OpenShift Monitoring Stack.
• Integrated Ansible Automation Platform to support automated implementation and repeatable platform configuration.
• Established GitOps-based deployment and operational workflows with Argo CD.
• Developed supporting automation and operational scripts using Python.
• Collaborated with infrastructure, application and operations teams to ensure successful platform implementation.
Technologies: OpenShift 4, Ansible Automation Platform, Argo CD, Prometheus, Grafana, OpenShift Monitoring Stack, Python, GitOps, container platforms

05/202505/2025

Nexus Repository PoC on Red Hat Enterprise Linux

Finance Company in Munich, Germany

Technical Role: Architect & DevOps Engineer
Scope: PoC planning, containerized implementation, automation and technical handover
Result: Planned and implemented a Nexus Repository PoC on Red Hat Enterprise Linux 9.
Key Contributions:
• Designed the basic PoC architecture for running Nexus Repository on RHEL 9 with Podman.
• Implemented the containerized Nexus deployment using Ansible for repeatable setup.
• Configured required host, container and service parameters for the PoC environment.
• Validated basic repository availability and operational behavior.
• Documented the implementation and handed over the PoC status, setup details and next-step recommendations.
Technologies: Red Hat Enterprise Linux 9, Nexus Repository, Podman, Ansible, artifact management

04/202504/2025

GitLab Runner Integration on Red Hat Enterprise Linux

Finance Company in Munich, Germany

Technical Role: Architect & DevOps Engineer
Scope: CI/CD runner integration, containerized deployment and operational enablement
Result: Implemented a containerized GitLab Runner deployment on Red Hat Enterprise Linux 9.
Key Contributions:
• Registered and integrated the runner with the existing GitLab environment.
• Configured runner execution parameters for CI/CD workload processing.
• Validated successful pipeline execution and documented the basic operational setup.
Technologies: Red Hat Enterprise Linux 9, GitLab, GitLab Runner, Podman, CI/CD

12/202412/2024

Red Hat Satellite 6 Capsule Extension on AWS

Finance Company in Munich, Germany

Technical Role: Architect & DevOps Engineer
Scope: Architecture concept, implementation, infrastructure integration and lifecycle management enablement
Result: Designed and implemented an extension of an existing Red Hat Satellite 6 environment with Capsule Servers on AWS.
Key Contributions:
• Planned the integration of Satellite Capsules into the existing infrastructure, network and lifecycle management model.
• Implemented and configured Satellite Capsule Servers for distributed content synchronization and host management.
• Validated connectivity, registration workflows and package distribution between Satellite, Capsules and managed hosts.
• Supported automation and standardization of deployment and configuration activities.
• Documented the architecture concept, implementation steps and operational handover details.
Technologies: Red Hat Satellite 6, Satellite Capsule Server, Red Hat Enterprise Linux, AWS, Ansible,  patch management

07/202412/2024

Enterprise OpenShift Container Platform

Federal Institute in Bonn, Germany

Technical Role: Architect & DevOps Engineer / Platform Hosting Owner
Scope: Platform architecture, implementation, automation, integration and production enablement
Result: Designed and implemented an enterprise container platform based on Red Hat OpenShift 4 on VMware vSphere.
Key Contributions:
• Architected and implemented multiple OpenShift 4 clusters on VMware vSphere.
• Designed and operated the underlying VMware vSphere infrastructure on Dell server hardware.
• Designed and implemented platform and application monitoring with Prometheus, Grafana and the OpenShift Monitoring Stack.
• Implemented centralized multi-cluster governance and operational control with ACM.
• Established GitOps-based delivery and application deployment workflows with Argo CD.
• Integrated GitLab and GitLab Runner on OpenShift to support CI/CD processes.
Technologies: OpenShift 4, VMware vSphere, VMware ESXi, Dell Server Infrastructure, Ansible Automation Platform, GitLab, GitLab Runner, Argo CD, ACM, Prometheus, Grafana, OpenShift Monitoring Stack, JFrog Artifactory, HashiCorp Vault, RHBK, Python, GitOps, CI/CD

09/202409/2024

Enterprise RHEL CIS Hardening & Remediation Rollout

Finance Company in Munich, Germany

Technical Role: Cybersecurity Specialist and Architect
Scope: Security architecture, CIS hardening, remediation planning and rollout management
Result: Designed a CIS Level 2 Server hardening approach for Red Hat Enterprise Linux 8 and 9 systems.
Key Contributions:
• Defined the target hardening approach based on CIS Level 2 Server requirements for RHEL 8 and RHEL 9.
• Assessed existing system configurations and identified deviations from the required security baseline.
• Planned and implemented remediation measures on selected reference hosts.
• Validated hardening impact on system functionality, operations and maintainability.
• Developed a rollout concept for categorizing systems by operating system version, role, criticality and remediation complexity.
• Supported the definition of rollout waves to reduce operational risk during hardening implementation.
Technologies: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, CIS Benchmarks, CIS Level 2 Server, Linux hardening, remediation, security baselines, Ansible, OpenSCAP, Python, systemd

09/202409/2024

AAP Infrastructure Upgrade

Finance Company in Munich, Germany

Technical Role: Consultant
Scope: Consulting, upgrade planning, implementation automation and technical validation
Result: Supported the infrastructure upgrade of a Red Hat Ansible Automation Platform environment on RHEL 9.
Key Contributions:
• Planned and supported the upgrade approach for a RHEL-hosted, non-containerized AAP  deployment.
• Designed and implemented Ansible automation to standardize recurring infrastructure update tasks.
• Reviewed inventories, variables and configuration parameters required for the upgrade process.
• Validated platform availability, service status and configuration consistency after the update.
Technologies: Red Hat Ansible Automation Platform, Red Hat Enterprise Linux 9, Ansible

11/202307/2024

Enterprise OpenShift Container Platform

Federal Institute in Bonn, Germany

Technical Role: Architect & DevOps Engineer
Scope: Platform architecture, implementation, automation, integration and production enablement
Result: Designed and implemented an enterprise container platform based on Red Hat OpenShift 4 on VMware ESXi.
Key Contributions:
• Architected and implemented multiple OpenShift 4 clusters on VMware ESXi.
• Designed and implemented platform and application monitoring with Prometheus, Grafana and the OpenShift Monitoring Stack.
• Implemented centralized multi-cluster governance and operational control with ACM.
• Established GitOps-based delivery and application deployment workflows with Argo CD.
• Integrated GitLab and GitLab Runner on OpenShift to support CI/CD processes.
• Integrated Ansible Automation Platform for automated platform operations and repeatable implementation routines.
Technologies: OpenShift 4, VMware ESXi, Ansible Automation Platform, GitLab, GitLab Runner, Argo CD, ACM, Prometheus, Grafana, JFrog Artifactory, HashiCorp Vault, RHBK, Cisco ACI, SAP Data Intelligence, Python, GitOps, CI/CD

01/201912/2023

AIO - Satellite 6 Administration & Automation Product

Lightning IT GmbH & Co. KG in Zossen, Germany

Technical Role: Product Architect & Developer – AIO
Scope: Product architecture, software development, patch automation and lifecycle management enablement
Result: Designed and developed an internal automation product for managing Red Hat Satellite 6 environments.
Key Contributions:
• Led the in-house development of AIO as an independent automation product for Satellite 6 administration.
• Designed and implemented one-click patch management to reduce manual effort and standardize recurring operations.
• Implemented one-click host provisioning to streamline system deployment and lifecycle workflows.
• Developed and maintained the software architecture with a focus on scalability, reliability and operational consistency.
• Integrated automation workflows for Satellite 6, Ansible, Jenkins and supporting platform services.
Technologies: Red Hat Satellite 6, Ansible, Python, Django, Kubernetes, Docker, Jenkins, Groovy, Anaconda, patch management, provisioning automation

11/202211/2023

Implementation of Several Container Platforms

IT Consulting Company in Nuremberg, Germany

Technical Role: Architect & DevOps Engineer
Scope: Platform architecture, OpenShift implementation, automation and operational enablement
Result: Designed and implemented multiple Red Hat OpenShift 4 container platforms on physical hardware and OpenStack.
Key Contributions:
• Architected and implemented multiple OpenShift clusters for enterprise container workloads.
• Planned and implemented platform and application monitoring with Prometheus, Grafana and the OpenShift Monitoring Stack.
• Integrated Ansible Automation Platform to support automated implementation and repeatable platform configuration.
• Established GitOps-based deployment and operational workflows with Argo CD.
• Developed supporting automation and operational scripts using Python.
Technologies: OpenShift 4, OpenStack, physical infrastructure, Ansible Automation Platform, Argo CD, Prometheus, Grafana, OpenShift Monitoring Stack, Python, GitOps, container platforms

02/202204/2023

Implementation of Several Container Platforms

Supply Chain Management Company in Bonn, Germany

Technical Role: Architect & DevOps Engineer
Scope: Platform architecture, implementation, automation and operational enablement
Result: Designed and implemented multiple Red Hat OpenShift 4 container platforms.
Key Contributions:
• Architected and implemented multiple OpenShift clusters for enterprise container workloads.
• Designed and implemented platform and application monitoring with Prometheus, Grafana and the OpenShift Monitoring Stack.
• Integrated Ansible Automation Platform to support automated implementation and repeatable platform configuration.
• Established GitOps-based deployment and operational workflows with Argo CD.
• Developed supporting automation and operational scripts using Python.
Technologies: OpenShift 4, Ansible Automation Platform, Argo CD, Prometheus, Grafana, OpenShift Monitoring Stack, Python, GitOps, container platforms

02/202112/2022

Implementation of Bare-Metal OpenShift Container Platforms

IT Consulting Company in Eschborn, Germany

Technical Role: DevOps Engineer
Scope: Platform architecture, bare-metal implementation, automation and operational enablement
Result: Designed and implemented multiple Red Hat OpenShift 4 container platforms on bare-metal infrastructure.
Key Contributions:
• Designed and implemented platform and application monitoring with Prometheus and Grafana.
• Developed automated installation routines using Ansible and supporting Python scripts.
• Established GitOps-based deployment and operational workflows with Argo CD.
• Integrated Cumulus Linux based networking concepts into the bare-metal platform design.
• Created clear technical documentation to support knowledge transfer and stakeholder communication.
Technologies: OpenShift 4, bare-metal infrastructure, Cumulus Linux, Ansible, Argo CD, Prometheus, Grafana, Python, GitOps, container platforms

09/202210/2022

Site-to-Site VPN PoC with WireGuard

IT Security Service Provider Company in Berlin, Germany

Technical Role: Solution Architect & DevOps Engineer
Scope: VPN PoC implementation, secure connectivity testing and technical validation
Result: Implemented a WireGuard-based site-to-site VPN PoC on Ubuntu.
Key Contributions:
• Installed and configured WireGuard directly on Ubuntu hosts.
• Defined basic routing and peer configuration for site-to-site connectivity.
• Validated tunnel establishment, network reachability and basic operational behavior.
• Documented the PoC setup and technical findings.
Technologies: Ubuntu, WireGuard, VPN, network security

05/202209/2022

SAP HANA Automation on Red Hat Enterprise Linux

IT Security Service Provider Company in Berlin, Germany

Technical Role: DevOps Engineer
Scope: Ansible automation, RHEL-based implementation, SAP HANA deployment support and technical validation
Result: Automated SAP HANA related setup and configuration tasks on Red Hat Enterprise Linux.
Key Contributions:
• Designed and implemented Ansible-based automation for SAP HANA related tasks on RHEL.
• Automated host preparation, configuration steps and repeatable operational activities.
• Validated automation execution, configuration consistency and system readiness.
• Documented the automation approach, required parameters and technical implementation details.
Technologies: Red Hat Enterprise Linux, SAP HANA, Ansible, infrastructure automation

12/202002/2021

Implementation of Several Container Platforms

IT Security Service Provider Company in Berlin, Germany

Technical Role: DevOps Engineer
Scope: Platform architecture, Kubernetes implementation, automation and operational enablement
Result: Designed and implemented multiple Kubernetes-based container platforms.
Key Contributions:
• Architected and implemented multiple container platform environments for application workloads.
• Planned and implemented platform and application monitoring with Prometheus and Grafana.
• Integrated Ansible Tower to support automated implementation and repeatable platform configuration.
• Established deployment and operational workflows with Flux.
• Integrated Longhorn to provide Kubernetes-native storage capabilities.
Technologies: Kubernetes, Ansible Tower, Flux, Longhorn, Prometheus, Grafana, Python, container platforms

01/201901/2021

Linux Infrastructure as Code Environment

Finance Company in Munich, Germany

Technical Role: Technical Team Lead
Scope: Architecture planning, infrastructure automation, Satellite implementation and technical project delivery
Result: Planned and implemented a Linux Infrastructure as Code environment for standardized system management and automation.
Key Contributions:
• Designed and implemented the target architecture for a Linux Infrastructure as Code environment.
• Implemented Red Hat Satellite 6 for scalable infrastructure management, provisioning and lifecycle operations.
• Developed automated patch management processes using Python and Docker.
• Integrated Git, Jenkins, Puppet and Ansible Automation Platform into the automation and delivery workflow.
• Managed architecture planning, implementation activities and technical project delivery.
Technologies: Red Hat Satellite 6, Red Hat Enterprise Linux, Ansible Automation Platform, Puppet, Docker, Git, Jenkins, Python, infrastructure automation, patch management

11/201911/2020

Linux Infrastructure as Code Environment

Automotive Company in Stuttgart, Germany

Technical Role: Solution Architect
Scope: Architecture planning, Satellite implementation, automation design and installation standardization
Result: Planned and implemented a Linux Infrastructure as Code environment for standardized system provisioning and management.
Key Contributions:
• Designed the target architecture for a Satellite 6 based Linux infrastructure management environment.
• Planned the integration of Ansible Tower into the automation and operational model.
• Implemented automated installation routines for Linux systems.
• Supported standardized provisioning and lifecycle management for RHEL and SLES environments.
• Integrated Bitbucket and Docker into the supporting automation and delivery workflow.
Technologies: Red Hat Satellite 6, Red Hat Enterprise Linux, SUSE Linux Enterprise Server, Ansible Tower, Bitbucket, Docker, infrastructure automation

09/201911/2019

Implementation of Several OpenShift Container Platforms

Finance Company in Stuttgart, Germany

Technical Role: DevOps Engineer
Scope: OpenShift implementation, monitoring architecture, automation design and platform standardization
Result: Implemented several Red Hat OpenShift 4 clusters for containerized application workloads.
Key Contributions:
• Designed and implemented multiple OpenShift 4 cluster environments.
• Planned the monitoring architecture for platform and application workloads.
• Implemented monitoring capabilities using Prometheus and Grafana.
• Designed automated installation routines for repeatable OpenShift deployments.
• Developed supporting automation scripts using Ansible and Python.
Technologies: OpenShift 4, Ansible, Prometheus, Grafana, Python, container platforms, platform automation

11/201809/2019

Implementation of Several OpenShift Container Platforms

Finance Company in Bonn, Germany

Technical Role: DevOps Engineer
Scope: OpenShift architecture, implementation, monitoring design and installation automation
Result: Implemented several OpenShift container platforms for standardized containerized application environments.
Key Contributions:
• Designed and implemented multiple OpenShift cluster environments.
• Planned the monitoring architecture for platform and application workloads.
• Implemented Prometheus and Grafana based monitoring capabilities.
• Designed automated installation routines for repeatable platform deployments.
• Developed supporting automation using Ansible, Python and Groovy.
Technologies: OpenShift, Ansible, Prometheus, Grafana, Python, Groovy, container platforms, platform automation

10/201811/2018

Linux Infrastructure as Code Environment

Finance Company in Munich, Germany

Technical Role: Technical Team Lead
Scope: Architecture planning, Satellite implementation, Puppet integration and patch automation
Result: Planned and implemented a Linux Infrastructure as Code environment based on Red Hat Satellite 6.
Key Contributions:
• Designed and implemented the target architecture for a Satellite 6 based infrastructure management platform.
• Planned and integrated Puppet within Satellite 6 for configuration management and system standardization.
• Developed automated patch management workflows using Python and Docker.
• Integrated Git and Jenkins into the automation and delivery process.
• Managed architecture planning, implementation activities and technical project delivery.
Technologies: Red Hat Satellite 6, Puppet, Docker, Git, Jenkins, Python, infrastructure automation, patch management

04/201709/2018

Linux Infrastructure as Code Environment

Insurance Company in Düsseldorf, Germany

Technical Role: Technical Team Lead
Scope: Architecture planning, Satellite implementation, Puppet integration and technical project management
Result: Planned and implemented a Linux Infrastructure as Code environment based on Red Hat Satellite 6.
Key Contributions:
• Designed and implemented the target architecture for a Satellite 6 based infrastructure management platform.
• Planned and integrated Puppet within Satellite 6 for configuration management and system standardization.
• Designed and implemented Infrastructure as Code workflows using GitLab and Jenkins.
• Integrated Red Hat Identity Management into the infrastructure architecture.
• Managed architecture planning, implementation activities and technical project coordination.
Technologies: Red Hat Satellite 6, Puppet, GitLab, Jenkins, Red Hat Identity Management, infrastructure automation, Linux, technical project management

04/201705/2017

OpenShift Platform for Infrastructure as Code Environment

Industry Company in Düsseldorf, Germany

Technical Role: DevOps Engineer
Scope: OpenShift implementation, application containerization and infrastructure automation enablement
Result: Implemented an OpenShift cluster as the platform foundation for Infrastructure as Code workflows.
Key Contributions:
• Implemented the OpenShift platform environment for containerized application and automation workloads.
• Supported the containerization of customer software for deployment on OpenShift.
• Implemented Infrastructure as Code environments using Ansible, Git and Jenkins.
• Deployed monitoring and supporting operational tools as containers.
• Supported integration with cloud-native platform concepts, including Azure AKS.
Technologies: OpenShift, Ansible, Git, Jenkins, Azure AKS, containers, Infrastructure as Code, platform automation

03/201704/2017

Red Hat Satellite 6 Environment

Wholesale Trade Company in Hamburg, Germany

Technical Role: Solution Architect
Scope: Architecture planning, Satellite implementation, Puppet integration and automated provisioning
Result: Planned and implemented a Red Hat Satellite 6 environment for standardized infrastructure management.
Key Contributions:
• Designed and implemented the target architecture for a Red Hat Satellite 6 based management platform.
• Planned and implemented Puppet integration within Satellite 6.
• Developed automated provisioning routines for physical and virtual systems.
• Integrated Jenkins and Python into the automated installation workflow.
• Supported standardized system deployment, configuration management and lifecycle operations.
Technologies: Red Hat Satellite 6, Puppet, Jenkins, Python, automated provisioning, infrastructure automation, Linux

03/201703/2017

Red Hat Enterprise Virtualization Environment

Insurance Company in Neuss, Germany

Technical Role: Consultant
Scope: Virtualization implementation, cluster setup and environment migration
Result: Implemented a Red Hat Enterprise Virtualization 4 cluster.
Key Contributions:
• Planned and executed the import of the existing environment into the new platform.
• Validated cluster functionality, workload availability and basic operational readiness.
• Supported handover of the implemented virtualization environment.
Technologies: Red Hat Enterprise Virtualization 4, RHEV, virtualization, cluster implementation, infrastructure migration

11/201611/2016

Puppet Environment Analysis & Redesign

Automotive Industry Company in Stuttgart, Germany

Technical Role: Solution Architect
Scope: Puppet architecture review, remediation, r10k implementation and module standardization
Result: Analyzed an existing Puppet environment and identified root causes for defective cases.
Key Contributions:
• Assessed the existing Puppet environment and documented technical issues.
• Designed remediation measures for defective configuration management cases.
• Implemented r10k in combination with Hiera for structured Puppet code management.
• Developed reusable Puppet modules independent of specific platform assumptions.
• Supported architecture improvements for maintainable and standardized configuration management.
Technologies: Puppet, r10k, Hiera, configuration management, Linux, infrastructure automation

11/201611/2016

Red Hat Satellite 6 Migration Workshop

Insurance Company in Bern, Switzerland

Technical Role: Author & Trainer
Scope: Workshop planning, customer-specific training material creation and migration enablement
Result: Planned and delivered a Red Hat Satellite 6 migration workshop.
Key Contributions:
• Planned the workshop structure and migration-related training agenda.
• Created customer-specific documentation and training materials.
• Delivered the Satellite 6 migration workshop to technical stakeholders.
• Supported discussion of migration concepts, implementation approach and operational requirements.
Technologies: Red Hat Satellite 6, migration planning, technical training, workshop delivery, infrastructure management

10/201611/2016

Satellite 5 to Satellite 6 Migration

Food Industry Company in Cologne, Germany

Technical Role: Solution Architect
Scope: Migration architecture, automated provisioning, configuration management and patch automation
Result: Planned the migration from Satellite 5 to Red Hat Satellite 6.
Key Contributions:
• Designed the target architecture for the Satellite 5 to Satellite 6 migration.
• Planned and implemented automated PXE-based installation for physical and virtual systems.
• Automated existing installation procedures to improve consistency and reduce manual effort.
• Planned and implemented Puppet-based configuration management.
• Developed Python scripts to communicate with the Satellite API for host management.
Technologies: Red Hat Satellite 5, Red Hat Satellite 6, Puppet, Python, Satellite API, PXE, automated provisioning, patch management

05/201607/2016

JBoss Installation Process Harmonization

Automotive Industry Company in Stuttgart, Germany

Technical Role: Consultant
Scope: Installation process optimization, Puppet automation and application provisioning standardization
Result: Harmonized and optimized existing JBoss installation processes.
Key Contributions:
• Analyzed existing JBoss installation procedures and identified optimization potential.
• Implemented a configurable Puppet-based setup process for JBoss deployments.
• Developed Puppet recipes for fully automated JBoss provisioning.
• Improved consistency, repeatability and maintainability of the application installation process.
Technologies: Puppet, JBoss, application provisioning, configuration management, automation

03/201604/2016

Satellite 5 to Satellite 6 Migration

Wholesale Trade Company in Düsseldorf, Germany

Technical Role: Solution Architect
Scope: Migration architecture, automated provisioning, configuration management and identity integration
Result: Planned and implemented the migration from Satellite 5 to Red Hat Satellite 6.
Key Contributions:
• Designed and implemented the target architecture for the Satellite 5 to Satellite 6 migration.
• Planned and implemented automated PXE-based installation for physical and virtual systems.
• Automated existing installation procedures to improve consistency and reduce manual deployment effort.
• Planned and implemented Puppet-based configuration management.
• Integrated FreeIPA into the fully automated installation and provisioning workflow.
Technologies: Red Hat Satellite 5, Red Hat Satellite 6, FreeIPA, Puppet, Python, Satellite API, PXE, automated provisioning, configuration management

03/201603/2016

Fully Automated Deployment Processes

Public Sector Company in Vienna, Austria

Technical Role: Solution Architect
Scope: Deployment architecture, RPM packaging, Puppet module delivery and Jenkins automation
Result: Planned and implemented fully automated deployment processes for Linux infrastructure environments.
Key Contributions:
• Designed the architecture for automated deployment and software distribution workflows.
• Implemented Mock-based RPM packaging for controlled and repeatable package builds.
• Created Puppet modules for standardized configuration and deployment processes.
• Distributed Puppet modules through lifecycle environments across the infrastructure.
• Automated recurring deployment and operational tasks using Jenkins.
Technologies: Red Hat Satellite 6, Jenkins, Mock, RPM packaging, Puppet, lifecycle environments, deployment automation

02/201603/2016

SAP NetWeaver High Availability Platform

Electronic Engineering Company in Stuttgart, Germany

Technical Role: Consultant
Scope: HA architecture implementation, cluster setup and business application platform enablement
Result: Implemented several SAP NetWeaver high availability clusters on Red Hat Enterprise Linux 7.
Key Contributions:
• Configured Pacemaker-based cluster resources and failover logic.
• Supported high availability requirements for business-critical SAP application workloads.
• Validated cluster behavior, service availability and basic operational readiness.
Technologies: SAP NetWeaver, Red Hat Enterprise Linux 7, Pacemaker, high availability, Linux clustering, business application platforms

10/201511/2015

Satellite 5 to Satellite 6 Migration

Information Technology Company in Hanover, Germany

Technical Role: Consultant
Scope: Migration implementation, automated provisioning, configuration management and API automation
Result: Implemented the migration from Satellite 5 to Red Hat Satellite 6.
Key Contributions:
• Implemented automated PXE-based provisioning for physical IBM POWER7 systems and virtual machines.
• Automated existing installation workflows to improve consistency and reduce manual effort.
• Planned and implemented configuration management for managed systems.
• Developed Python scripts to simplify Satellite API responses and host management tasks.
Technologies: Red Hat Satellite 5, Red Hat Satellite 6, IBM POWER7, Python, Satellite API, PXE, automated provisioning, configuration management

10/201510/2015

Red Hat Satellite 6 System Management Platform Extension

Public Sector Company in Vienna, Austria

Technical Role: Junior Consultant
Scope: Satellite implementation, platform extension and Puppet-based configuration management
Result: Extended an existing Red Hat Satellite 6 system management platform.
Key Contributions:
• Implemented and extended the existing Red Hat Satellite 6 server environment.
• Planned the configuration management approach based on Puppet.
• Integrated Puppet-based configuration management into the Satellite 6 platform.
• Supported standardized system management, configuration consistency and operational maintainability.
Technologies: Red Hat Satellite 6, Puppet, configuration management, Linux, system management

09/201510/2015

Automated Provisioning Environment Review

Insurance Company in Hamburg, Germany

Technical Role: Junior Consultant
Scope: Provisioning review, Satellite optimization and patch management extension
Result: Reviewed an existing automated provisioning environment based on Red Hat Satellite.
Key Contributions:
• Reviewed the existing Satellite-based provisioning workflow and identified optimization potential.
• Implemented improvements to the automated provisioning environment.
• Extended patch management logic using clone-by-date functionality.
• Developed supporting Bash scripts for automation and operational tasks.
Technologies: Red Hat Satellite, Bash, automated provisioning, patch management, infrastructure automation

02/201509/2015

Automated JBoss Installation Process

Finance Company in Stuttgart, Germany

Technical Role: Junior Consultant
Scope: Installation architecture, decentralized deployment automation and application server provisioning
Result: Planned and implemented an automated installation process for JBoss application servers.
Key Contributions:
• Designed the installation process for JBoss application server environments.
• Implemented decentralized setup routines for JBoss servers and instances.
• Developed supporting Bash and Java based automation components.
• Improved repeatability and consistency of JBoss application server provisioning.
Technologies: JBoss, Bash, Java, application server provisioning, installation automation

07/201508/2015

OpenSCAP Implementation & Audit Log Analysis

Food Industry Company in Cologne, Germany

Technical Role: Junior Consultant
Scope: OpenSCAP implementation, security assessment enablement and audit log analysis automation
Result: Consulted on and implemented OpenSCAP for Linux security assessment and compliance validation.
Key Contributions:
• Supported configuration review and validation of Linux systems.
• Developed Bash-based auditd log analysis tools.
• Documented implementation details and basic operational usage.
Technologies: OpenSCAP, auditd, Bash, Linux security, compliance assessment

06/201507/2015

SSL VPN Cluster Update & Review

Insurance Company in Stuttgart, Germany

Technical Role: Junior Consultant
Scope: SSL VPN cluster update, architecture review and improvement consulting
Result: Updated an existing Juniper SSL VPN cluster environment.
Key Contributions:
• Performed the SSL VPN cluster update.
• Reviewed the existing SSL VPN architecture and configuration logic.
• Identified potential improvements for stability, maintainability and operational handling.
• Advised the client on technical optimization options.
Technologies: Juniper SSL VPN, SSL VPN, remote access, VPN cluster, network security

06/201306/2015

Check Point Firewall Cluster Administration

Automotive Industry Company in Paris, France

Technical Role: Administrator
Scope: Firewall cluster installation, troubleshooting and operational administration
Result: Installed and administered Check Point R75 firewall cluster environments.
Key Contributions:
• Performed cluster debugging and issue analysis.
• Supported operational administration of multiple firewall cluster environments.
• Maintained stable firewall operations across a larger Check Point cluster landscape.
Technologies: Check Point Firewall, Check Point R75, firewall clustering, network security, cluster administration

Certifications

  • Red Hat Certified Architect (Certification ID: 140-083-502)
    • EX447 Red Hat Certified Specialist in Ansible Best Practices
    • EX413 Red Hat Certified Specialist in Server Security and Hardening
    • EX407 Red Hat Certified Specialist in Ansible Automation
    • EX405 Red Hat Certified Specialist in Configuration Management
    • EX403 Red Hat Certified Specialist in Deployment and Systems Management
    • EX401 Red Hat Enterprise Deployment and Systems Management
    • EX342 Red Hat Certified Specialist in Linux Diagnostics and Troubleshooting
    • EX318 Red Hat Certified Specialist in Virtualization
    • EX300 Red Hat Certified Engineer
    • EX288 Red Hat Certified Specialist in OpenShift Application Development
    • EX280 Red Hat Certified Specialist in OpenShift Administration
    • EX200 Red Hat Certified System Administrator
    • EX180 Red Hat Certified Specialist in Containers and Kubernetes
  • Red Hat Certified Instructor
  • Additional certifications available upon request.