Skip to main content
Open to Strategic Leadership Roles

Rakan Bakir

DevOps Architect | CKA | AWS Certified

I'm a DevOps architect with 17+ years building the platforms regulated banks, telcos, and broadcasters trust. I bridge bare-metal Linux to GitOps on AWS EKS, embed PCI-DSS, NIST & Well-Architected security into every pipeline, and grow engineering teams from zero — so security, speed, and audit-readiness ship together.

  • PCI-DSS & NIST Governance
  • 60× Deploy Speed
  • Platform Teams Built

Amman, Jordan

6 Measurable Impacts

Measurable Impact

Concrete outcomes from regulated platforms and the teams behind them.

  • Deployment Velocity

    60× Faster

    2h → 2min

    Kubernetes-based CI/CD at Orange Jordan — zero failure-related downtime.

  • Env Provisioning

    70% Faster Prep

    17d → 5d

    Repeatable, secure on-prem delivery patterns at Orange Jordan.

  • Engineering Leadership

    3× Teams Built

    ICS · Jordan Ahli · Orange

    DevOps practices founded from zero — security-first culture, day one.

  • Enterprise GitOps

    35+ Microservices

    Open Banking estate

    Monoliths → distributed at Jordan Ahli Bank; ArgoCD audit trails.

  • Operational Resilience

    65% Fewer Incidents

    99.99% Uptime

    IRSA · KMS · IMDSv2 · External Secrets + Trivy / Grype shift-left scans.

  • Cost Optimization

    $5M+ Saved

    500+ cloud resources

    AWS Well-Architected + Karpenter multi-tenancy across PCI-DSS estates.

Open to Strategic Leadership Roles

17+ years engineering cloud-native & on-premise platforms

From bare-metal Linux to GitOps on EKS — building the platforms that regulated banks, telcos, and broadcasters trust. Security-first. Audit-ready. Built to scale.

Years in tech
17+
Microservices on GitOps
35+
Banking compliance
PCI-DSS
Major security frameworks
3

My career began with Linux — administering servers, hardening systems, managing firewalls, and designing on-premise networks. I lived the full transformation: from bare-metal and VMware virtualization to cloud migration, then into DevOps and GitOps practices, and now embedding AI-assisted workflows into platform engineering. That journey gives me a layered understanding of infrastructure — I know what sits beneath the abstractions because I built and operated every layer along the way.

I'm a hands-on DevOps architect and team lead with experience across banking, telecom, broadcast media, and retail. In my last three roles, I built DevOps systems and teams from the ground up — hiring engineers, defining standards, and embedding security and GitOps best practices before the first deployment. I also guided organisations through the transition from monolithic architectures to microservices, introducing containerisation, Kubernetes, and the delivery patterns needed to operate distributed systems safely at scale. I specialize in cloud-native platforms, Kubernetes (EKS), GitOps with ArgoCD, infrastructure as code, and security-first CI/CD — especially in regulated environments.

In banking, I led security and cost programs mapped to AWS Well-Architected (Security pillar), the NIST Cybersecurity Framework, and PCI-DSS — including container hardening, secrets management, IAM federation, and Open Banking API security with Kong (OIDC/mTLS). On current platforms, I enforce IRSA, KMS encryption, IMDSv2, and External Secrets Operator as baseline controls.

DevSecOps is part of every pipeline: image scanning with Trivy and Grype, Kubernetes insights with K8sGPT, policy-aware delivery, and observability with Prometheus and Grafana. I'm passionate about infrastructure that helps teams move fast without trading off compliance or auditability.

Languages

  • Arabic — Native or bilingual
  • English — Full professional proficiency

Notable accomplishments

  • Led bank-wide security alignment to PCI-DSS, NIST, and AWS Well-Architected Security pillar
  • Deployed Kong Hybrid Gateway with OIDC/mTLS for regulated Open Banking API exposure
  • Built platform security baselines: IRSA, KMS, IMDSv2, External Secrets, and pipeline-integrated Trivy scanning
  • Created ContainerGuard — open-source Grype/Trivy scanning with PDF security reports for audit workflows
  • Attended AWS re:Invent 2018 and AWS Summit Dubai 2018; advocate for OPA, Wazuh, and policy-as-code in the community

Career journey

  1. DevOps Team Lead

    Integrated Computer Systems Jordan

    Built the DevOps practice from the ground up — establishing secure, compliant AWS EKS platforms with Terraform, GitOps CI/CD, and platform-wide security controls for developer self-service. Recruited and mentored the engineering team, embedding best practices from day one.

    • Founded the DevOps function: hired the team, defined standards, and built CI/CD, infrastructure, and security baselines from scratch
    • Enforced platform-wide security & compliance: IRSA, KMS encryption, IMDSv2, AWS Secrets Manager, External Secrets Operator
    • Deployed multi-environment EKS with VPC isolation, multi-AZ networking, and standardized secure Terraform modules
    • Implemented GitOps with ArgoCD and Jenkins — auditable, policy-aware deployment paths across environments
    • Built observability stack (Prometheus, Grafana, Loki, Tempo, OpenTelemetry) for security-relevant alerting and audit visibility
    • Optimized multi-tenant operations with Karpenter, runbooks, and security documentation for self-service teams
  2. DevOps Senior Manager

    Jordan Ahli Bank · Banking

    Established and led the DevOps function at a major Jordanian bank — building the team, toolchain, and security posture from scratch. Mapped infrastructure and delivery to PCI-DSS, NIST, and AWS Well-Architected across a multi-account Open Banking estate.

    • Built the DevOps team and practice from zero: hired engineers, defined the roadmap, and institutionalized GitOps and DevSecOps
    • Owned security program aligned to PCI-DSS, NIST Cybersecurity Framework, and AWS Well-Architected Security pillar
    • Embedded DevSecOps in CI/CD: Trivy image scanning, K8sGPT cluster insights, and Prometheus-backed detection
    • Secured Open Banking APIs with Kong Hybrid Gateway (OIDC, mTLS) and hybrid connectivity patterns
    • Implemented IAM federation, VPN, secrets hygiene, and Terraform IaC across segregated AWS accounts
    • Enabled GitOps with ArgoCD across 35+ microservices with traceable, compliance-friendly change management
  3. DevOps Consultant

    Orange Jordan · Telecommunications

    Built the DevOps practice from the ground up inside a telecommunications environment — introducing on-premise Kubernetes CI/CD, automation, and a security-first delivery culture where none existed before.

    • Established the DevOps capability from scratch: built the team, defined workflows, and introduced Kubernetes-based CI/CD
    • Built hardened on-premise CI/CD on Kubernetes with standardized, repeatable secure deployment patterns
    • Reduced environment prep from 17 days to 5 days while improving consistency and security baselines
    • Cut deployment time from 2 hours to 2 minutes; eliminated failure-related downtime through resilient automation
    • Championed DevOps and security best practices across development and operations teams
  4. Senior DevOps Engineer

    525K Global Solutions

    Collaborated on IaC, production operations, observability, and securing new systems against cybersecurity threats.

    • Implemented IaC with security and consistency built into environment provisioning
    • Enhanced observability and security monitoring across microservice estates
    • Trained engineers on secure cloud practices and IaC guardrails
  5. Senior DevOps Engineer

    Middle East Broadcasting Center (MBC) · Media & Entertainment

    Built CI/CD for shahid.net, migrated legacy systems to Docker on AWS VPCs, and automated operations at broadcast scale.

    • Developed shahid.net CI/CD model with Jenkins pipelines and Ansible automation
    • Automated MBC3 website build and deploy using Amazon CDK
    • Attended AWS re:Invent 2018 (Las Vegas) and AWS Summit Dubai 2018
    • Coached team members on new DevOps tools and practices
  6. Senior Linux System Administrator

    MarkaVIP · Retail

    Managed Linux servers, VMs, networking, patching, performance tuning, and platform documentation for MarkaVIP, a retail e-commerce company in the MENA region.

    • Administered Linux platforms with patching, access control, and security-focused performance tuning
    • Maintained secure retail e-commerce infrastructure and collaborated on hardened platform changes
  7. Linux Administrator

    Info2cell

    Telecom VAS platform administration: network design, Linux servers, DNS, VPN, firewalls, and technical support.

    • Designed network segmentation with Cisco ASA/PIX firewalls, VPN, and enforced perimeter security
    • Administered Linux and DNS infrastructure with continuous security monitoring and hardening
  8. System Administrator

    Virtecha Solutions

    IT infrastructure administration for web and mobile application delivery platforms.

  9. Network Engineer

    Texum Jordan

    Network engineering and IT services consulting.

Featured Projects

Platform programs and open-source work from banking, telecom, media, and personal projects.

Platform Engineering

Secure Multi-Environment AWS EKS Platform

Enterprise Kubernetes platform with built-in compliance controls: IRSA, KMS, IMDSv2, secrets management, and pipeline security for self-service teams.

  • EKS
  • Terraform
  • ArgoCD
  • IRSA
  • KMS
  • External Secrets
  • Encrypted by default (KMS)
  • IRSA workload identity
  • Multi-AZ self-healing
Banking · Compliance

Regulated Open Banking & DevSecOps

PCI-DSS and NIST-aligned banking platform: multi-account AWS, Well-Architected security reviews, Kong API security, and shift-left scanning across 35+ services.

  • PCI-DSS
  • NIST
  • Kong
  • Trivy
  • K8sGPT
  • ArgoCD
  • 35+ microservices on GitOps
  • PCI-DSS · NIST aligned
  • OIDC + mTLS APIs (Kong)
Telecom · CI/CD

On-Premise Cloud-Like CI/CD

Kubernetes-based delivery platform bringing cloud-native CI/CD to on-premise telecom infrastructure — hardened, repeatable, and developer-friendly.

  • Kubernetes
  • Jenkins
  • Ansible
  • GitOps
  • Linux
  • 60× faster deploys
  • 70% faster env prep
  • Zero failure downtime
Open Source · Security

ContainerGuard (opens in new tab)

Open-source unified web platform for container vulnerability scanning with Grype and Trivy — generating auditable PDF security reports.

  • Grype
  • Trivy
  • Docker
  • Python
  • Security
  • Unified Trivy + Grype
  • PDF audit reports
  • Open source · MIT

Technical expertise

Cloud & Platform

  • AWS
  • EKS
  • Kubernetes
  • Docker
  • Terraform
  • Multi-Account AWS
  • VPC & Networking

CI/CD & GitOps

  • ArgoCD
  • GitHub Actions
  • Jenkins
  • CodePipeline
  • CodeBuild
  • GitOps
  • Agile/Scrum

Observability & SRE

  • Prometheus
  • Grafana
  • Loki
  • OpenTelemetry
  • K8sGPT
  • SLAs
  • Automated Alerts

Security & Compliance

  • PCI-DSS
  • NIST CSF
  • AWS Well-Architected (Security)
  • DevSecOps
  • Trivy
  • Grype
  • K8sGPT
  • IRSA
  • KMS
  • IMDSv2
  • External Secrets
  • Kong (OIDC/mTLS)
  • Vault
  • Keycloak
  • IAM Federation

Data & Integration

  • Kafka
  • AWS Glue
  • Open Banking APIs
  • VPN
  • IAM Federation

Leadership

  • Team Lead
  • Mentoring
  • Stakeholder Management
  • Technical Leadership
  • Cost Optimization

Standards & frameworks

Security is embedded in platform design — from regulated banking workloads to multi-tenant Kubernetes. I align infrastructure and delivery pipelines with recognized frameworks and enforce controls through automation, not checklists alone.

PCI-DSS

Banking · Open Banking

Aligned AWS and Kubernetes platforms with PCI-DSS expectations for cardholder data environments — securing CI/CD, workloads, networking, and access paths for regulated financial services.

  • Segmentation
  • Secrets management
  • Audit trails
  • Vulnerability scanning

NIST Cybersecurity Framework

Banking · Enterprise

Applied NIST-aligned practices across identify, protect, detect, and respond — hardening multi-account AWS estates, access controls, monitoring, and incident-ready operations.

  • IAM federation
  • Multi-account AWS
  • Observability
  • Operational controls

AWS Well-Architected (Security Pillar)

Banking · Platform engineering

Led Well-Architected reviews focused on the Security pillar — identity, detection, infrastructure protection, data protection, and incident response — paired with cost optimization across production estates.

  • Identity & access
  • Data protection
  • Network security
  • Cost governance

Container & cloud-native security

EKS · DevSecOps

Platform-wide controls for Kubernetes: IRSA for workload identity, KMS encryption, IMDSv2, AWS Secrets Manager, External Secrets Operator, and pipeline-integrated image scanning.

  • IRSA
  • KMS
  • Trivy
  • K8sGPT
  • External Secrets

Open Banking API security

Financial APIs

Secured Open Banking traffic with Kong Hybrid Gateway — OIDC, mTLS, and hybrid deployment patterns for regulated API exposure and third-party connectivity.

  • Kong Gateway
  • OIDC
  • mTLS
  • API governance

Infrastructure & network security (foundations)

Telecom · Retail · Early career

Built security foundations through firewall administration (Cisco ASA/PIX), VPN, DNS hardening, Linux hardening, patching, and secure multi-tenant hosting long before cloud-native became the norm.

  • Firewalls
  • VPN
  • Linux hardening
  • Patch management

Security practices in delivery

  • Shift-left scanning in CI/CD with Trivy, Grype, and container image policies before production deploy
  • Secrets never in code — AWS Secrets Manager, External Secrets Operator, and Vault/Keycloak where required
  • Least-privilege IAM, IRSA for pods, and multi-account AWS boundaries for blast-radius reduction
  • GitOps audit trails with ArgoCD for who deployed what, when, and to which environment
  • Runtime and cluster hygiene: K8sGPT insights, Prometheus alerting, and documented incident runbooks
  • Open-source security tooling: ContainerGuard for unified Grype/Trivy scanning and PDF audit reports
12 Credentials

Certifications

Active credentials and foundational training across cloud, Linux, and infrastructure.

Active Credentials

CNCF Active

Certified Kubernetes Administrator (CKA)

CNCF

AWS Active

AWS Certified

Amazon Web Services

Foundational Credentials

  • LPI

    LPIC-2

    Linux Professional Institute

  • LPI

    LPIC-1

    Linux Professional Institute

  • NOV

    SUSE 11 Technical Specialist

    Novell

  • NOV

    Novell Certified Linux Administrator 11

    Novell

  • NOV

    Novell Data Center Technical Specialist

    Novell

  • MS

    Microsoft Certified Systems Engineer (MCSE)

    Microsoft

  • MS

    Microsoft Certified Systems Administrator (MCSA)

    Microsoft

  • MS

    Microsoft Certified Professional (MCP)

    Microsoft

  • MS

    Microsoft Certified Technology Specialist (MCTS)

    Microsoft

  • Cisco

    Cisco Certified Network Associate (CCNA)

    Cisco

Academic background

Bachelor of Science in Computer Science

Princess Sumaya University for Technology

Amman, Jordan

How I lead platform teams

Security by design

Map platforms to PCI-DSS, NIST, and AWS Well-Architected before production — identity, encryption, segmentation, scanning, and auditability are defaults, not afterthoughts.

DevSecOps in every pipeline

Shift-left with Trivy, Grype, and K8sGPT; enforce secrets management, IRSA, and policy-aware GitOps so compliance scales with deployment velocity.

Regulated delivery at speed

Balance Open Banking and banking-grade controls with GitOps traceability — secure APIs (OIDC/mTLS), multi-account AWS, and teams that understand both speed and audit requirements.

Send a message

Open to DevOps leadership roles, consulting, and collaborations in cloud-native platform engineering, GitOps, and DevSecOps. Use the form below and I will get back to you by email.

Prefer social? LinkedIn GitHub