Matvey Aleksandrov

DevOps Engineer (Kubernetes, Cloud, SRE)

Saint Petersburg
Full-time • Remote / Hybrid • Ready to relocate
Copied!

Summary

DevOps Engineer with 2+ years of concentrated experience across various companies. Striving to continuously improve my skills and expand my domain expertise.

Work Experience

Leading Fiscal Data Operator |DevOps Engineer (Fintech • Moscow)

Mar 2026 – Present

Brought in as an expert (DevOps buddy) to resolve complex infrastructure challenges, eliminate technical debt, and develop team competencies in a highly loaded FinTech company.

  • Planned and executed a tight-deadline zero-downtime migration of Kubernetes clusters' network stack from Flannel to Cilium (eBPF), boosting network performance and security.
  • Initiated a transition to the GitOps paradigm: deployed ArgoCD, designed new GitLab CI/CD pipelines, and onboarded the team, successfully phasing out legacy scripts.
  • Performed deep troubleshooting and profiling of K8s infrastructure: isolated and resolved anomalous node degradation (spikes up to 12k+ forks).
  • Conducted major upgrades for critical enterprise systems and tools (Artifactory, Elma365, n8n), mitigating security vulnerabilities of outdated versions.
  • Implemented a fault-tolerant traffic balancing scheme (HAProxy + Keepalived/VRRP).

Human Help |DevOps Engineer (EdTech • Yerevan, Armenia)

Mar 2025 – Mar 2026

Built DevOps processes and the startup's cloud architecture from scratch in close collaboration with the development team.

  • Designed a highly available multi-cloud architecture (Selectel, Hetzner, Cloudflare) using Terraform.
  • Reduced monthly infrastructure costs by 2.5x through autoscaling (HPA+Karpenter) and Spot instances.
  • Deployed Cilium and Service Mesh to ensure secure and observable communication between microservices.
  • Automated CI/CD processes using GitLab CI and implemented a GitOps approach for application deployment via ArgoCD.

MTS |DevOps Engineer (BigTech • Moscow)

Sep 2024 – Mar 2025

IT subsidiary of the largest telecom operator in Russia.

  • Implemented proactive server defense against brute-force attacks by configuring fail2ban and nftables integration.
  • Configured centralized authentication (SSO) for internal Git hosting (Forgejo) via Keycloak, simplifying access management for development teams.

Projects

Zytro |R&D Project

2023 – 2024

Designing and developing a private mesh network architecture based on WireGuard. The project won 2nd place at the SUAI scientific and technical conference (2023).

  • Deployed and configured a WireGuard-based VPN server, set up basic network routing (iptables) in Linux.
  • Wrote a managing Python Telegram bot: the bot generated encryption key pairs for new network devices.
  • Restricted SSH access to server infrastructure, allowing connections exclusively inside the private perimeter (WG -> SSH).

Technical Skills

Infrastructure:
KubernetesDockerLinux
IaC & CI/CD:
GitLab CIArgoCD (GitOps)HelmTerraformAnsible
Network & Security:
Gateway APICiliumService MesheBPFEnvoyKeycloakVault
Databases & Brokers:
PostgreSQLRedisNATS
Monitoring:
VictoriaMetrics StackPrometheusGrafana
Development:
PythonBashGolang

Education

TOP Academy, Moscow

Software Development and Management, Vocational Education

Languages

  • Russian — Native
  • English — B2