Skip to main content
Rakan Bakir
Open to Strategic Leadership & Technical Roles

Rakan Bakir

DevOps Architect | CKA | AWS Certified

I'm a DevOps architect with 17+ years building the platforms regulated banks, telcos, broadcasters, and retailers trust. I bridge bare-metal Linux to GitOps on AWS EKS, embed PCI-DSS, NIST & Well-Architected security into every pipeline, and grow engineering teams from zero — so security, speed, and audit-readiness ship together.

  • PCI-DSS & NIST Governance
  • 60× Deploy Speed
  • Platform Teams Built

Amman, Jordan

6 Measurable Impacts

Measurable Impact

Concrete outcomes from regulated platforms and the teams behind them.

  • Deployment Velocity

    60× Faster

    2h → 2min

    Kubernetes-based CI/CD at Orange Jordan — zero failure-related downtime.

  • Env Provisioning

    70% Faster Prep

    17d → 5d

    Repeatable, secure on-prem delivery patterns at Orange Jordan.

  • Engineering Leadership

    3× Teams Built

    ICS · Jordan Ahli · Orange

    DevOps practices founded from zero — security-first culture, day one.

  • Enterprise GitOps

    35+ Microservices

    Open Banking estate

    Monoliths → distributed at Jordan Ahli Bank; ArgoCD audit trails.

  • Operational Resilience

    65% Fewer Incidents

    99.99% Uptime

    IRSA · KMS · IMDSv2 · External Secrets + Trivy / Grype shift-left scans.

  • Cost Optimization

    40% Compute Waste Cut

    500+ cloud resources

    Karpenter spot instances, bin-packing & Well-Architected rightsizing across PCI-DSS estate.

Open to Strategic Leadership & Technical Roles

17+ years engineering cloud-native & on-premise platforms

From bare-metal Linux to GitOps on EKS — building the platforms that regulated banks, telcos, and broadcasters trust. Security-first. Audit-ready. Built to scale.

Years in tech
17+
Microservices on GitOps
35+
Workflow approach
AI-First
Banking compliance
PCI-DSS

My career began with Linux — administering servers, hardening systems, managing firewalls, and designing on-premise networks. I lived the full transformation: from bare-metal and VMware virtualization to cloud migration, then into DevOps and GitOps practices, and now embedding AI-assisted workflows into platform engineering. That journey gives me a layered understanding of infrastructure — I know what sits beneath the abstractions because I built and operated every layer along the way.

I'm a hands-on DevOps architect and team lead with experience across banking, telecom, broadcast media, and retail. In my last three roles, I built DevOps systems and teams from the ground up — hiring engineers, defining standards, and embedding security and GitOps best practices before the first deployment. I also guided organisations through the transition from monolithic architectures to microservices, introducing containerisation, Kubernetes, and the delivery patterns needed to operate distributed systems safely at scale. I specialize in cloud-native platforms, Kubernetes (EKS), GitOps with ArgoCD, infrastructure as code, and security-first CI/CD — especially in regulated environments.

AI is now core to how I work. I see it as a copilot — not a replacement — that helps professionals focus on solving problems instead of repetitive mechanics. I've integrated AI agents heavily into my workflow: Claude for architecture reviews and code generation, GitHub Copilot for day-to-day development, K8sGPT for Kubernetes diagnostics, HolmesGPT for incident analysis, and Stakpak for platform scaffolding. These tools accelerate delivery, surface insights faster, and let teams spend energy on design and strategy, not boilerplate.

In banking, I led security and cost programs mapped to AWS Well-Architected (Security pillar), the NIST Cybersecurity Framework, and PCI-DSS — including container hardening, secrets management, IAM federation, and Open Banking API security with Kong (OIDC/mTLS). On current platforms, I enforce IRSA, KMS encryption, IMDSv2, and External Secrets Operator as baseline controls.

DevSecOps is part of every pipeline: image scanning with Trivy and Grype, Kubernetes insights with K8sGPT, policy-aware delivery, and observability with Prometheus and Grafana. I'm passionate about infrastructure that helps teams move fast without trading off compliance or auditability.

Languages

  • Arabic — Native or bilingual
  • English — Fluent (IELTS Certified)

Notable accomplishments

  • Led bank-wide security alignment to PCI-DSS, NIST, and AWS Well-Architected Security pillar
  • Deployed Kong Hybrid Gateway with OIDC/mTLS for regulated Open Banking API exposure
  • Built platform security baselines: IRSA, KMS, IMDSv2, External Secrets, and pipeline-integrated Trivy scanning
  • Created ContainerGuard — open-source Grype/Trivy scanning with PDF security reports for audit workflows
  • Attended AWS re:Invent 2018 and AWS Summit Dubai 2018; advocate for OPA, Wazuh, and policy-as-code in the community

Career journey

  1. DevOps Team Lead

    Integrated Computer Systems (ICS), Jordan · IT Services & Consulting

    Built the DevOps practice from the ground up — establishing secure, compliant AWS EKS platforms with Terraform, GitOps CI/CD, and platform-wide security controls for developer self-service. Recruited and mentored the engineering team, embedding best practices from day one.

    • Founded the DevOps function: hired engineers, defined standards, and built CI/CD, infrastructure, and security baselines from scratch
    • Architected multi-environment AWS EKS with Terraform IaC, VPC isolation, and multi-AZ networking across 3 availability zones
    • Enforced platform-wide security & compliance: IRSA, KMS encryption, IMDSv2, AWS Secrets Manager, External Secrets Operator
    • Rolled out GitOps with ArgoCD and Jenkins across 3 environments — auditable, policy-aware deployment paths
    • Deployed observability stack (Prometheus, Grafana, Loki, Tempo, Pyroscope, OpenTelemetry) — reduced MTTR by 45%
    • Implemented Karpenter autoscaling, reducing idle compute waste by 30%
  2. DevOps Senior Manager

    Jordan Ahli Bank (Qawn — Innovation) · Banking

    Established and led the DevOps function through the Qawn innovation department at a major Jordanian bank — building the team, toolchain, and security posture from scratch. Mapped infrastructure and delivery to PCI-DSS, NIST, and AWS Well-Architected across a multi-account Open Banking estate.

    • Founded the DevOps team and practice from zero: hired engineers, defined the roadmap, and institutionalized GitOps and DevSecOps
    • Directed security program aligned to PCI-DSS, NIST Cybersecurity Framework, and AWS Well-Architected Security pillar across 7 segregated AWS accounts
    • Hardened Open Banking APIs with Kong Hybrid Gateway (OIDC, mTLS) for 20+ financial partners
    • Governed ArgoCD across 35+ microservices with compliance-grade audit trails and automated rollback
    • Embedded DevSecOps in CI/CD: Trivy image scanning, K8sGPT cluster insights, and Prometheus-backed detection
    • Provisioned IAM federation, VPN, secrets hygiene, and Terraform IaC across 7 segregated AWS accounts for blast-radius reduction
    • Designed AWS Step Functions to intelligently start/stop non-production ECS, RDS, and Redshift — yielding 40% off-hours cloud savings
  3. DevOps Consultant

    Orange Jordan · Telecommunications

    Spearheaded cloud-native CI/CD platform on on-premise Kubernetes from zero, creating DevOps culture and practices where none existed.

    • Engineered hardened on-premise Kubernetes CI/CD with IaC (ArgoCD, Terraform) and GitOps, supporting 4 squads
    • Reduced environment prep from 17 days to 5 days while improving consistency and security baselines
    • Accelerated deployment from 2 hours to 2 minutes; eliminated failure-related downtime through resilient automation
    • Integrated Trivy container scanning into pipelines; led DevOps and security sessions for 4 squads
  4. Senior DevOps Engineer

    525K Global Solutions · Technology

    Managed AWS infrastructure as code using Terraform and CDK, instrumenting observability and integrating security automation.

    • Instrumented observability with Prometheus, FluentD, and Grafana, reducing MTTD by 60%
    • Integrated shift-left security scanning and compliance automation into CI/CD pipelines across 8+ code repositories
  5. Senior DevOps Engineer

    MBC Group (Shahid.net) · Media & Entertainment

    Orchestrated CI/CD for shahid.net, containerizing legacy services to Docker on AWS at broadcast scale.

    • Engineered Jenkins and Ansible CI/CD pipelines supporting broadcast-scale traffic for millions of viewers
    • Containerized 15+ legacy services to Docker on AWS, cutting deployment failures by 80%
    • Developed automated build and deploy workflows via AWS CDK; represented engineering at AWS re:Invent 2018
  6. Senior Linux System Administrator

    MarkaVIP · Retail

    Managed Linux servers, VMs, networking, patching, performance tuning, and platform documentation for MarkaVIP, a retail e-commerce company in the MENA region.

    • Engineered high-availability systems and internal monitoring solutions, achieving 99.9% uptime
    • Maintained secure retail e-commerce infrastructure and collaborated on 10+ platform change rollouts
  7. Linux Administrator

    Info2cell · Telecommunications

    Telecom VAS platform administration: network design, Linux servers, DNS, VPN, firewalls, and technical support.

    • Designed network segmentation with Cisco ASA/PIX firewalls, VPN, and enforced perimeter security
    • Administered Linux and DNS infrastructure with continuous security monitoring and hardening
  8. System Administrator

    Virtecha Solutions · IT Services

    IT infrastructure administration for web and mobile application delivery platforms.

  9. Network Engineer

    Texum Jordan · IT Services & Consulting

    Network engineering and IT services consulting.

What I'm looking for

Open to roles that move platforms, security, and teams forward

Roles

  • DevOps Architect / Platform Engineering Lead
  • Staff / Senior DevOps Engineer
  • Cloud-Native Infrastructure Consultant
  • DevSecOps Transformation Lead

Work Style

  • Remote
  • Hybrid
  • On-site (able to relocate — Gulf)

Industries

Open to all industries

Availability

Available for immediate start

Featured Projects

Platform programs and open-source work from banking, telecom, media, and personal projects.

Platform Engineering

Secure Multi-Environment AWS EKS Platform

Enterprise Kubernetes platform with built-in compliance controls: IRSA, KMS, IMDSv2, secrets management, and pipeline security for self-service teams.

  • EKS
  • Terraform
  • ArgoCD
  • IRSA
  • KMS
  • External Secrets
  • Encrypted by default (KMS)
  • IRSA workload identity
  • Multi-AZ self-healing
Banking · Compliance

Regulated Open Banking & DevSecOps

PCI-DSS and NIST-aligned banking platform: multi-account AWS, Well-Architected security reviews, Kong API security, and shift-left scanning across 35+ services.

  • PCI-DSS
  • NIST
  • Kong
  • Trivy
  • K8sGPT
  • ArgoCD
  • 35+ microservices on GitOps
  • PCI-DSS · NIST aligned
  • OIDC + mTLS APIs (Kong)
Telecom · CI/CD

On-Premise Cloud-Like CI/CD

Kubernetes-based delivery platform bringing cloud-native CI/CD to on-premise telecom infrastructure — hardened, repeatable, and developer-friendly.

  • Kubernetes
  • Jenkins
  • Ansible
  • GitOps
  • Linux
  • 60× faster deploys
  • 70% faster env prep
  • Zero failure downtime
Open Source · Security

ContainerGuard (opens in new tab)

Open-source unified web platform for container vulnerability scanning with Grype and Trivy — generating auditable PDF security reports.

  • Grype
  • Trivy
  • Docker
  • Python
  • Security
  • Unified Trivy + Grype
  • PDF audit reports
  • Open source · MIT

Technical expertise

AI & Developer Tools

  • Claude
  • GitHub Copilot
  • K8sGPT
  • HolmesGPT
  • Stakpak
  • Python
  • AI-Assisted Workflows

Cloud & Platform

  • AWS
  • EKS
  • Kubernetes
  • Docker
  • Terraform
  • Terraform Cloud
  • Backstage
  • Cilium (Service Mesh)
  • Multi-Account AWS
  • VPC & Networking

Infrastructure as Code

  • Terraform
  • Terraform Cloud
  • AWS CDK
  • Ansible
  • Helm
  • Crossplane

Continuous Integration & Delivery

  • ArgoCD
  • GitHub Actions
  • Jenkins
  • CodePipeline
  • CodeBuild
  • GitOps
  • Agile/Scrum

Microservices & Architecture

  • Microservices Architecture
  • Kong (API Gateway)
  • Kafka
  • Event-Driven Patterns
  • Scalability
  • Multi-Account AWS
  • VPC Design

Observability & SRE

  • Prometheus
  • Grafana
  • Loki
  • Tempo
  • Pyroscope
  • OpenTelemetry
  • K8sGPT
  • Site Reliability Engineering
  • Incident Management
  • Monitoring
  • Alerting
  • SLIs/SLOs
  • Automated Alerts
  • Runbooks

Security & Compliance

  • PCI-DSS
  • NIST CSF
  • AWS Well-Architected (Security)
  • DevSecOps
  • Kube-Argus
  • Trivy
  • Grype
  • SonarQube
  • K8sGPT
  • IRSA
  • KMS
  • IMDSv2
  • External Secrets
  • Kong (OIDC/mTLS)
  • Vault
  • Keycloak
  • IAM Federation

Data & Integration

  • Kafka
  • AWS Glue
  • Open Banking APIs
  • VPN
  • IAM Federation

Leadership

  • Team Lead
  • Mentoring
  • Stakeholder Management
  • Technical Leadership
  • Cost Optimization

Standards & frameworks

Security is embedded in platform design — from regulated banking workloads to multi-tenant Kubernetes. I align infrastructure and delivery pipelines with recognized frameworks and enforce controls through automation, not checklists alone.

PCI-DSS

Banking · Open Banking

Aligned AWS and Kubernetes platforms with PCI-DSS expectations for cardholder data environments — securing CI/CD, workloads, networking, and access paths for regulated financial services.

  • Segmentation
  • Secrets management
  • Audit trails
  • Vulnerability scanning

NIST Cybersecurity Framework

Banking · Enterprise

Applied NIST-aligned practices across identify, protect, detect, and respond — hardening multi-account AWS estates, access controls, monitoring, and incident-ready operations.

  • IAM federation
  • Multi-account AWS
  • Observability
  • Operational controls

AWS Well-Architected (Security Pillar)

Banking · Platform engineering

Led Well-Architected reviews focused on the Security pillar — identity, detection, infrastructure protection, data protection, and incident response — paired with cost optimization across production estates.

  • Identity & access
  • Data protection
  • Network security
  • Cost governance

Container & cloud-native security

EKS · DevSecOps

Platform-wide controls for Kubernetes: IRSA for workload identity, KMS encryption, IMDSv2, AWS Secrets Manager, External Secrets Operator, and pipeline-integrated image scanning.

  • IRSA
  • KMS
  • Trivy
  • K8sGPT
  • External Secrets

Open Banking API security

Financial APIs

Secured Open Banking traffic with Kong Hybrid Gateway — OIDC, mTLS, and hybrid deployment patterns for regulated API exposure and third-party connectivity.

  • Kong Gateway
  • OIDC
  • mTLS
  • API governance

Infrastructure & network security (foundations)

Telecom · Retail · Early career

Built security foundations through firewall administration (Cisco ASA/PIX), VPN, DNS hardening, Linux hardening, patching, and secure multi-tenant hosting long before cloud-native became the norm.

  • Firewalls
  • VPN
  • Linux hardening
  • Patch management

Security practices in delivery

  • Shift-left scanning in CI/CD with Trivy, Grype, and container image policies before production deploy
  • Secrets never in code — AWS Secrets Manager, External Secrets Operator, and Vault/Keycloak where required
  • Least-privilege IAM, IRSA for pods, and multi-account AWS boundaries for blast-radius reduction
  • GitOps audit trails with ArgoCD for who deployed what, when, and to which environment
  • Runtime and cluster hygiene: K8sGPT insights, Prometheus alerting, and documented incident runbooks
  • Open-source security tooling: ContainerGuard for unified Grype/Trivy scanning and PDF audit reports
15 Credentials

Certifications

Key certifications and foundational training across cloud, Linux, and infrastructure.

Key Certifications

CNCF certification badge

Certified Kubernetes Administrator (CKA)

CNCF

Amazon Web Services certification badge

AWS Certified Solutions Architect - Associate

Amazon Web Services

Amazon Web Services certification badge

AWS Certified Developer - Associate

Amazon Web Services

Amazon Web Services certification badge

AWS Certified SysOps Administrator - Associate

Amazon Web Services

Foundational Credentials

  • Linux Professional Institute badge

    LPIC-2

    Linux Professional Institute

  • Linux Professional Institute badge

    LPIC-1

    Linux Professional Institute

  • Novell badge

    SUSE 11 Technical Specialist

    Novell

  • Novell badge

    Novell Certified Linux Administrator 11

    Novell

  • Novell badge

    Novell Data Center Technical Specialist

    Novell

  • Microsoft badge

    Microsoft Certified Systems Engineer (MCSE)

    Microsoft

  • Microsoft badge

    Microsoft Certified Systems Administrator (MCSA)

    Microsoft

  • Microsoft badge

    Microsoft Certified Professional (MCP)

    Microsoft

  • Microsoft badge

    Microsoft Certified Technology Specialist (MCTS)

    Microsoft

  • Cisco badge

    Cisco Certified Network Associate (CCNA)

    Cisco

  • British Council badge

    IELTS

    British Council

Academic background

Princess Sumaya University for Technology logo

Bachelor of Science in Computer Science

Princess Sumaya University for Technology

Amman, Jordan

Graduated 2008

How I lead platform teams

Security by design

Map platforms to PCI-DSS, NIST, and AWS Well-Architected before production — identity, encryption, segmentation, scanning, and auditability are defaults, not afterthoughts.

DevSecOps in every pipeline

Shift-left with Trivy, Grype, and K8sGPT; enforce secrets management, IRSA, and policy-aware GitOps so compliance scales with deployment velocity.

Regulated delivery at speed

Balance Open Banking and banking-grade controls with GitOps traceability — secure APIs (OIDC/mTLS), multi-account AWS, and teams that understand both speed and audit requirements.

Send a message

Open to DevOps leadership roles, consulting, and collaborations in cloud-native platform engineering, GitOps, and DevSecOps. Use the form below and I will get back to you by email.

Prefer social? LinkedIn GitHub