Manip Poudel — Resume
DevOps Team Lead & Cloud Infrastructure Engineer (DevOps / SRE / Platform)
Summary
DevOps Team Lead with 4+ years designing, automating, and securing production cloud infrastructure on AWS and GCP. Lead DevOps across 10+ concurrent production AWS environments for a Tokyo-based software company. Cut manual provisioning effort ~70% with a reusable Terraform module library, CI spend ~60% with reusable GitHub Actions workflows, OIDC federation, and self-hosted runners, and AWS bills 20-40% across 10+ client accounts with zero downtime. Drove an organisation-wide DevSecOps transformation and migrated production delivery to GitOps on Amazon EKS with ArgoCD and Helm. AWS Certified Solutions Architect - Associate; HashiCorp Certified: Terraform Associate (003).
Technical skills
- Cloud
- AWS (EC2, ECS Fargate, EKS, Lambda, RDS, S3, VPC, IAM, Route 53, CloudWatch, SES, KMS), Google Cloud Platform, Linux
- Infrastructure as Code
- Terraform (HashiCorp Certified), CloudFormation, Ansible
- Containers & Orchestration
- Kubernetes (EKS), Docker, Helm, ArgoCD, GitOps, IRSA, HPA / cluster-autoscaler
- CI/CD
- GitHub Actions (reusable workflows, OIDC, self-hosted runners), GitLab CI, Jenkins
- DevSecOps
- Secret scanning (detect-secrets, truffleHog), tflint, OPA/conftest, SOPS + KMS, IAM least privilege, TLS/PKI, mTLS
- Observability
- Prometheus, Grafana, Loki, ELK, kube-prometheus-stack, Alertmanager, incident response & RCA
- Languages & Tools
- Python, Bash, Nginx, Git, PostgreSQL
Experience
DevOps Team Lead — wesionaryTEAM
Jan 2022 - Present · Remote (Tokyo, Japan)
- Lead DevOps for 10+ concurrent production AWS environments across separate client accounts; own CI/CD architecture, Kubernetes operations, and incident response.
- Reduced manual provisioning effort ~70% by designing a layered Terraform module library (networking, compute, database, IAM baseline, observability) with S3/DynamoDB remote state and plan-review-apply through CI; new-environment bootstrap went from days of console work to a reviewed pull request.
- Cut CI spend ~60% (typical build 12 min to 7 min) by building a versioned reusable GitHub Actions workflow library (workflow_call) shared by 10+ repositories and moving Docker-heavy builds to self-hosted EC2 runners with persistent caches.
- Eliminated long-lived AWS access keys from every repository by migrating CI authentication to GitHub OIDC federation with repo/branch-scoped IAM trust policies.
- Reduced AWS bills 20-40% per environment across 10+ client accounts with zero downtime (one mid-size client: ~$3,800/mo to ~$2,300/mo) via tagging and cost visibility, gp2-to-gp3 migration, data-driven right-sizing, non-prod scheduling (-65% runtime hours), and NAT/VPC-endpoint fixes - then locked the savings in as Terraform module defaults.
- Migrated production deployments from kubectl-in-CI to GitOps on Amazon EKS with ArgoCD (app-of-apps) and Helm: rollback became a ~2-minute git revert, cluster credentials were removed from CI entirely, drift self-heals, and right-sizing/autoscaling cut node costs ~30%.
- Drove an organisation-wide DevSecOps transformation: secret-scanning gates in every pipeline, tflint + OPA/conftest IaC compliance checks (blocked 12+ misconfigured Terraform resources in the first quarter), an IAM least-privilege audit that cut permission surface ~60%, and SOPS + AWS KMS secret management - zero pipeline-attributable security incidents since rollout.
- Implemented production email authentication (SPF, DKIM, DMARC) on AWS SES across client domains, with bounce-rate monitoring and suppression-list runbooks keeping accounts under AWS thresholds.
- Built a two-tier private PKI (offline root CA, online subordinate CA) with CRL revocation and Nginx mutual TLS enforcement for internal services.
- Run observability with kube-prometheus-stack, Grafana golden-signal dashboards, Loki logs, and Alertmanager paging; mentor junior DevOps engineers on the team.
DevOps Engineer Intern — Leapfrog Technology
Oct 2021 - Dec 2021 · Kathmandu, Nepal
- Deployed AWS infrastructure (EC2, Lambda, S3, Route 53, VPC, IAM, load balancers), configured Nginx web servers, and implemented CI/CD pipelines.
- Linux system administration on CentOS and Ubuntu: disk/log/resource management, firewall rules, DNS, NAT, and OpenVPN configuration.
Backend Developer — NAXA
May 2021 - Oct 2021 · Chitwan, Nepal
- Built geospatial REST APIs with Python, Django, and PostGIS, optimised for query performance as data volume grew.
- Automated configuration of Cisco and MikroTik routers using Python, netmiko, and paramiko.
Certifications
- AWS Certified Solutions Architect - Associate (Amazon Web Services)
- HashiCorp Certified: Terraform Associate (003) (HashiCorp)
- Verification: credly.com/users/manip-poudel
Education
Bachelor's degree, Computer Science and Information Technology (B.Sc. CSIT)
Selected case studies
More detail on how I work is on the about page, and every project write-up lives under case studies.