Alexey Gain
Platform & Cloud Infrastructure Engineer · Architect-level scope, hands-on IC
Prague, Czechia
alex@alexkri.net | +420-778-449-879
linkedin.com/in/alex-gain | github.com/aleksgain | alexkri.net
Summary
Hands-on platform and infrastructure engineer with 14+ years across AWS, Azure and Google Cloud, working at architect scope as an individual contributor: sets the technical direction, then builds it. Deep in Kubernetes (EKS, AKS, GKE, on-prem, GPU nodes), Terraform, CI/CD, identity and observability. At HX, owns the cloud estate end to end: ~30% lower cloud bill, production crashes fixed by reclaiming over-committed cluster capacity, and an architecture review process that holds vendors to IaC and monitoring standards. Before that, platform owner for up to 20 client estates at an AWS/Google Cloud MSP. Built a shared monitoring platform that cut time-to-detect to 5 minutes, reduced spend ~20%, and stood up GPU inference infrastructure for ML workloads.
Core Competencies
Platform Engineering · Kubernetes incl. GPU Workloads · Infrastructure as Code & CI/CD · Multi-Cloud Architecture (AWS, Azure, GCP) · FinOps · Identity & Zero-Trust Access · Observability & Reliability · Technical Direction & Architecture Review
Experience
HX Expeditions | Technical Architect
June 2025 – Present | Prague, Czechia
- Led the fleet-wide rollout of the Otalio ship-management platform: stood up the Kubernetes clusters, ran sizing and performance audits with the vendor, and spent a month aboard MS Fram on hands-on shipboard implementation
- Audited the Kubernetes estate and brought resource requests down from 180% to 80% of available compute, resolving recurring production crashes and avoiding a cluster scale-up
- Took ownership of Azure and AWS FinOps (rightsizing, reservations, savings commitments), lowering the monthly cloud bill by ~30% on average
- Unblocked a stalled Exchange migration from on-prem to the cloud, saving nearly $60k in hosting costs
- Delivered a second Amazon Connect tenant with the Salesforce team, cutting contact-centre latency for the ANZ region from up to 4 seconds to under 20 ms
- Replaced a convoluted multi-file legacy partner integration with a single-document flat-file spec for live API queries, shortening partner onboarding from 3–4 months to weeks
- Designed security-first access: Entra ID federation for AWS, GitHub, Grafana, Cloudflare, NinjaOne and other systems, plus vendor-agnostic privileged access via NinjaOne and bastion hosts
- Established and run the Architecture Review Board for tooling and vendor decisions; hold vendors to HX standards on IaC, right-sized infrastructure and monitoring coverage
Revolgy | Cloud Architect / Senior Cloud Engineer
March 2019 – May 2025 | Prague, Czechia
- Built a one-click monitoring platform (Prometheus, Grafana, deployed via Argo CD) rolled out to every client, bringing time-to-detect down to 5 minutes and time-to-resolve under 3 hours for most incidents
- Built self-hosted ML inference infrastructure on EKS with NVIDIA GPU nodes for a mental-health platform's post-session clinical analysis, including autoscaling and GPU slicing
- Platform owner for up to 20 client estates across fintech, healthcare and cloud-native companies; owned each engagement from onboarding to operational excellence with Terraform and CI/CD
- Reduced client cloud spend by ~20% on average through rightsizing, burstable and spot compute, and reservations
- Stood up the cloud platform for one of Africa's largest digital payment providers (under NDA), solving unusual constraints such as government interference and DNS blocking
- Delivered lift-and-shift migrations and modernisations, including on-prem Kubernetes to EKS; planned and ran Kubernetes upgrade cycles to avoid end-of-life support charges
- Built infrastructure for a real-time industrial IoT sensor logging and analytics provider
Lacework | Delivery Architect (contract)
October 2023 – March 2024 | Remote, alongside Revolgy
- Took the hardest customer onboardings, including environments without NAT gateways and air-gapped deployments
- Wrote custom queries for customer-specific threat-detection patterns
- Ran cloud security workshops and coached customers on CVE detection and remediation priorities
Alex&Kri Consulting | IT Solutions Consultant
September 2012 – April 2021 | Greater Boston Area; part-time and remote from 2019
- Moved 100+ small businesses to the cloud, mostly lift-and-shift (e.g. WordPress to AWS Lightsail), with performance tuning and security hardening
- Kept hosting affordable: typical bills in the low hundreds of dollars a month, down to $15–20 on Hetzner or Contabo for cost-sensitive clients
- Implemented automated backup and disaster recovery, and provided ongoing infrastructure support
Certifications
- Google Cloud Professional Cloud Architect
- AWS Certified Solutions Architect – Professional
- AWS Certified Database – Specialty
- Certified Kubernetes Administrator (CKA)
- Wiz Partner Technical Accreditation
- Lacework Shield Delivery Associate
Technical Skills
- Cloud: AWS, Azure, Google Cloud
- Containers: Kubernetes (EKS, AKS, GKE, on-prem), GPU workloads, Docker, ECS, Argo CD, Helm
- IaC & CI/CD: Terraform, CloudFormation, GitLab CI, GitHub Actions, Jenkins
- Serverless & Integration: Lambda, API Gateway, Amazon Connect, SFTP
- Identity & Security: Entra ID, Auth0, NinjaOne, Lacework, Wiz
- Observability: Prometheus, Grafana, CloudWatch, ELK Stack
- Databases: PostgreSQL, Redis, Elasticsearch
- Languages: Python, Bash, HCL
Education
Bunker Hill Community College — Associate of Science, Network and System Administration
2007 – 2010