Hi, I'm Aleh
20+ years architecting secure, scalable, and highly available infrastructure. From zero-trust security frameworks to GitOps-driven Kubernetes platforms.

What I Deliver
Four core pillars of expertise — each engineered for enterprise reliability, security, and scale.
Infrastructure Management
Design and operate enterprise-grade infrastructure with focus on scalability, high availability, and disaster recovery.
- High-Availability Clustering (99.99% SLA)
- Load Balancing & Traffic Management
- Storage Architecture (SAN, NFS, Ceph)
- Disaster Recovery & BCP Planning
- Capacity Planning & Cost Optimization
- Network Architecture & Segmentation
System Administration
End-to-end Linux and Windows server management with hardening, automation, and performance tuning.
- Linux/Windows Hardening (CIS Benchmark)
- Configuration Management (Ansible)
- Performance Tuning & Optimization
- Patch Management & Compliance
- Shell Scripting & Automation
- Active Directory & LDAP Management
DevSecOps Engineering
Security-first CI/CD pipelines, container orchestration, and GitOps workflows for modern cloud-native applications.
- CI/CD Pipeline Design (GitLab, Jenkins)
- Kubernetes & Container Orchestration
- GitOps with ArgoCD / Flux
- Infrastructure as Code (Terraform)
- SAST/DAST Security Integration
- Secret Management (Vault, Sealed Secrets)
Cyber Security
Proactive threat defense, vulnerability management, and security compliance for enterprise environments.
- WAF Deployment & Custom Rule Tuning
- Penetration Testing & Red Teaming
- SIEM / SOC Implementation (Wazuh)
- Zero-Trust Architecture Design
- Compliance (ISO 27001, NIST, PCI-DSS)
- Incident Response & Forensics
Featured Projects
Real-world infrastructure and security projects — architected, built, and operated at scale.
Zero-Trust Network Architecture
productionDesigned and implemented a comprehensive zero-trust security architecture for a 500+ node enterprise network, replacing legacy perimeter-based security.
98% reduction in lateral movement attack surface. Zero breaches in 18 months.
Kubernetes Multi-Cluster GitOps Platform
productionBuilt a production-grade GitOps platform managing 12 Kubernetes clusters across 3 regions with full GitOps workflow, secret management, and policy enforcement.
Deployment frequency increased 400%. MTTR reduced from 4h to 12min.
High-Availability Database Cluster
productionArchitected a Percona XtraDB Cluster with Pgpool-II load balancing, automated failover, and point-in-time recovery across 5 nodes.
99.99% uptime SLA. RTO < 30 seconds, RPO < 5 seconds.
CI/CD Security Pipeline (DevSecOps)
productionIntegrated security scanning into a 50+ microservice CI/CD pipeline using SAST, DAST, container scanning, and dependency auditing.
73% reduction in vulnerabilities reaching production. Build time maintained < 8min.
Linux Server Hardening Automation
productionDeveloped Ansible playbooks implementing CIS Benchmark Level 2 hardening across 200+ Linux servers (RHEL, Ubuntu, Debian) with automated compliance reporting.
CIS compliance score improved from 42% to 97%. Full audit trail established.
WAF & DDoS Mitigation Platform
productionDeployed and tuned ModSecurity WAF with custom OWASP Core Rule Set rules, integrated with Cloudflare for DDoS protection across 30+ web applications.
Blocked 2.3M+ malicious requests/month. Zero successful SQL injection or XSS attacks.
Work Experience
A timeline of roles, achievements, and impact across enterprise infrastructure and security.
Infrastructure Manager
PT. Mediatama Kreasi Informatika
Leading infrastructure strategy and security operations for enterprise systems, specializing in cloud-native transitions and high-availability architecture.
Senior Web Apps Developer & Infrastructure Engineer
PT. Mediatama Kreasi Informatika
Managed full-spectrum IT infrastructure while developing enterprise-grade web applications across multiple technology stacks.
Web Application Developer
PT. Vertical Digital Indonesia
Developed high-performance portal applications and improved business processes through technical excellence.
IT Support Technician
SMA Negeri 3 Bandung
Provided full IT operational support and network management for a leading educational institution.
Junior Network Administrator
PT. SIMS (JABAR-BANTEN MEDIANET)
Managed and maintained regional network systems for a service provider.
Network Engineer
SMK Negeri 4 Bandung
Managed school-wide networking infrastructure and provided technical support.
Tool Man
Dept. Informatika ITB
Technical maintenance and troubleshooting in the informatics department.
Skills & Certifications
Core technical competencies built through 20+ years of hands-on infrastructure and security engineering.
PROFICIENCY MATRIX
CERTIFICATIONS
Cybersecurity Career Starter
Hack & Fix
Info Security Intro
Cyber Academy
GCP Reliable Infra
Google Cloud
Learn DevOps: K8s/TF
Udemy
Azure DevOps Fundamentals
Udemy
Cisco CCNA
Cisco Systems
Latest Articles
Insights and technical write-ups on infrastructure, security, and DevSecOps.
Get In Touch
Open to consulting, fractional CTO roles, and senior infrastructure partnerships. Let's build something secure.
20+ years architecting secure, scalable, and highly available infrastructure. From zero-trust security frameworks to GitOps-driven Kubernetes platforms.