DevOps Engineer

Wangoi Mwangi.

Infrastructure  ·  Automation  ·  Reliability

Wangoi Mwangi - DevOps Engineer

I'm Wangoi Mwangi, a DevOps Engineer who builds infrastructure that teams rely on.

I've always believed the best infrastructure is the kind you don't have to think about. Secure, scalable, quietly doing its job - and getting there is exactly the kind of work I enjoy.

I've worked with startups moving fast, enterprises that can't afford downtime, and remote teams spread across time zones. The context changes, the standards don't.

If something here resonates with you, let's talk.

Let's Talk

Tech Stack

The tools I use in production.

Cloud Platforms

AWS AWS
Azure Azure

Containerization & Orchestration

Kubernetes Kubernetes
Docker Docker
Helm Helm
ArgoCD ArgoCD (GitOps)

Infrastructure as Code

Terraform Terraform
Ansible Ansible

CI/CD & Automation

GitHub Actions GitHub Actions
Jenkins Jenkins
Azure DevOps Azure DevOps

Observability & Monitoring

Prometheus Prometheus
Grafana Grafana
ELK Stack ELK Stack

DevSecOps

SonarQube SonarQube
Snyk Snyk
Trivy Trivy
HashiCorp Vault HashiCorp Vault

Programming & Systems

Python Python
Bash Bash
Linux Linux
Git Git

Projects

Work that shipped.

AWS cloud Azure cloud tf
01

Multi-Cloud Infrastructure with Terraform

Designed and deployed modular cloud infrastructure across AWS and Azure using Terraform. Remote state, environment isolation and reusable modules - built for teams, not just individuals.

pod pod pod pod pod pod K8s
02

Production Kubernetes Platform

Provisioned and managed a production-grade EKS cluster with autoscaling node groups, Helm-based deployments and namespace isolation. Zero manual intervention after setup.

BUILD TEST SCAN 🛡 DEPLOY commit prod
03

Automated CI/CD Pipeline

Built an automated pipeline from commit to production. Covers build, test, security scan and rollback. Teams deploy multiple times a day without the fear.

threshold Prometheus Grafana ELK CloudWatch
04

Enterprise Observability Stack

Deployed a full observability platform - Prometheus, Grafana, ELK Stack and CloudWatch. Real-time alerts, log aggregation and dashboards. Issues caught before users notice.

λ cost reduction -40% runs on schedule - hands-off cleanup
05

Cloud Cost Optimisation Engine

Built a serverless automation using Python and Lambda that identifies and removes orphaned AWS resources on a schedule. Hands-off cost management that runs itself.

IAM least-privilege secrets management security scanning RBAC · SAST · DAST
06

DevSecOps Pipeline Integration

Hardened CI/CD pipelines with security scanning, IAM least-privilege policies and secrets management. Security baked in from day one, not bolted on after.

My Services

What I can do for your team.

01

Cloud Infrastructure Design

Cloud environments built on AWS and Azure that scale with your product. Secure, efficient, and right the first time.

02

Automation & Infrastructure as Code

I replace manual infrastructure with Terraform and Ansible. Version-controlled, repeatable, and safe for any engineer to run.

03

CI/CD Pipeline Engineering

Automated pipelines from commit to production with testing, security scanning, and rollback built in. Your team ships faster, without the fear.

04

Container Orchestration

Production-grade Kubernetes environments that are self-healing, observable, and ready for real traffic.

05

Monitoring & Observability

Full visibility across metrics, logs, and alerts so your team catches problems before anyone notices.

06

Cloud Cost Optimisation

I audit your AWS environment, identify waste, and automate cleanup without touching performance.

07

Security & Compliance

I harden infrastructure from the ground up - IAM policies, RBAC, secrets management and automated security scanning built into every pipeline.

I write about what I build.

Active on Medium

Real walkthroughs from real infrastructure work. If you want to see how I think and how I solve problems, my Medium is the best place to start.

View My Writing on Medium

Let's work together.

Whether you have a project in mind, a role to fill, or just want to talk infrastructure, my inbox is open. I typically respond within 24 hours.