Senior DevOps / Site Reliability Engineer
Kubernetes · Observability · FinOps | Nairobi, Kenya
I keep production systems up, cut cloud bills, and build the tooling that makes both repeatable. 8+ years across fintech, banking, blockchain, and SaaS on AWS, GCP, and Azure.
| 💰 ~$1M | verified annualized AWS savings |
| 📊 45 / 45 | SaaS customer orgs onboarded to Grafana observability (LGTM) in 7 days |
| ⚙️ ~200 runners | self-hosted CI fleet at ~1,800 jobs/hour |
| 🟢 99.99% | uptime on a 1M+ transactions/month payment platform |
| Focus | In production |
|---|---|
| Incident response | P1 / showstopper triage across US, EU, and Asia. Root-caused a silent alert-drop discarding real incidents on four clusters. |
| Observability | Multi-tenant Grafana / Mimir / Loki / Tempo for 45 customer orgs, shipped as Terraform. ~26,000 metric series at $182/mo vs a $3,100 baseline. |
| FinOps | ~$1M realized annualized savings across two enterprise AWS estates, each change validated against live billing before execution. |
| Platform & CI | Production Go on a self-hosted Actions runner platform: dispatch-race fix, vCPU-aware autoscaling, ephemeral instance per job. |
| AI for ops | Read-only diagnostic agents and MCP servers that cross-check firing alerts against live AWS and label each finding verified or contradicted. |
| Cloud | AWS (EKS, ECS Fargate, CloudWatch, Secrets Manager), GCP (GKE, Workload Identity), Azure (AKS, Key Vault) |
| Kubernetes | EKS / GKE / AKS, Helm, ArgoCD, GitOps, Docker |
| Observability | Prometheus, Grafana, Mimir, Loki, Tempo, Grafana Alloy, Thanos, AWS CloudWatch, Datadog, PromQL / LogQL |
| IaC & CI/CD | Terraform, Crossplane, Ansible, GitHub Actions, Azure DevOps |
| Security | Zero-trust, HashiCorp Vault, IAM, GCP Workload Identity Federation, DevSecOps |
| Languages | Python, Bash, Go, AI agent tooling (MCP, Claude API) |
Most of my production work lives in private and employer repositories. A few public pieces that show how I build:
| Project | What it is |
|---|---|
| oidc-gcp-integration-project | Keyless CI/CD via GCP Workload Identity Federation, GitHub Actions, Terraform. How I kill long-lived cloud credentials. |
| nethermind-network-manager | Helm deployment for Nethermind Ethereum nodes on Kubernetes: miners, bootnodes, configurable networks. |
| erc-20-geth-gcp | ERC-20 deployment on Ethereum Sepolia using Geth on GCP, provisioned with Terraform. |
| Role | Company | Period |
|---|---|---|
| Senior DevOps Engineer | Trilogy (remote) | Sep 2025 – present |
| Senior DevSecOps & Cloud Engineer | Diamond Trust Bank Africa | Jan 2025 – Aug 2025 |
| Senior DevOps Engineer | Fujitsu Uvance (remote) | Sep 2022 – Aug 2024 |
| Lead Cloud Engineer | Orteo Payment Systems | Mar 2020 – Feb 2022 |
Earlier: security analyst roles in penetration testing and SDLC audits across banking.
BSc Electronics & Computer Engineering (JKUAT) · GCP Professional Security Engineer · HashiCorp Terraform Associate · CCNA / CCNP

