Competitive observability win
ProductionLarge enterprise
Sole technical lead, every success criterion met.
Peak ingestion supported and scaled
Fortune 500 observability workloads
Big data managed
Cloudera Hadoop, 300 nodes
Hardened overnight
Chef to Ansible, vulnerabilities removed
Bare-metal Confluent Kafka
Terraform-imported, Ansible-managed
Aerospike cross-DC replication
Data replicated between data centers
Compute cost reduction vs Elastic
At equivalent workloads
Competitive win to production
From POC kickoff, every criterion met
Monthly cloud spend reduction
ClickOps to Terraform at Securonix
Cloudera Hadoop cluster operated
Kerberos, TLS, Vault dynamic secrets
Active certifications
AWS, Azure, Kubernetes, HashiCorp
Routine operations automated
Big data platform at Early Warning
Business scale supported
Compliant cloud infrastructure at ONEngine
Product built on Google ADK
Shipped and monetized
Context engine for cloud operations
Grounded in live infrastructure state
LLM systems in production
AI SRE, gateway, triage, and more
AI gateways in production
Envoy and Portkey, Claude and GPT routing
>How the platforms I ship fit together: telemetry in through OpenTelemetry, OpenObserve as the hub, production systems built on top.
>Every production deployment pattern I have shipped. Filter by platform or technology. Customers, partners, and competing vendors are anonymized on purpose.
Large enterprise
Sole technical lead, every success criterion met.
Fortune 500
30-40% less compute than incumbent Elastic.
One of the world's largest retailers
Alert storms consolidated into single incidents.
Platform layer
Model routing with per-provider cost telemetry.
Security engineering
OCSF normalization with Sigma-to-VRL detections.
Security engineering
Repeatable triage over incidents and findings.
Cross-industry
EKS/AKS/OKE/DOKS/bare metal, SSO, BYO bucket.
Cross-industry
Collectors across Windows, Linux, VMware, K8s.
Federal and defense
Compliant federal and Azure telemetry ingestion.
Security vendor
ClickOps to Terraform, 25% monthly spend cut.
Regulated banking
Confluent Kafka on 25 bare-metal servers, imported into Terraform.
Regulated banking · big data
300-node Cloudera Hadoop cluster managing 5PiB of big data.
Regulated data (GDPR)
Aerospike with cross-data-center replication.
Regulated data
Deployed Elasticsearch and migrated search off Solr.
Regulated infrastructure
Converted 1200+ servers from Chef to Ansible overnight, removing vulnerabilities.
On-prem security
Kerberos on-prem plus mTLS server-to-server, machine identity at scale.
Platform engineering
Built a Jenkins mini cloud manager, eliminated most ClickOps.
>The technologies I work with across the stack, grouped by domain.
>The flagship engagements, each with an architecture diagram, the problem, my role, and the outcome. Read any of them end to end.
A large enterprise evaluated OpenObserve against a leading observability vendor. I was the sole technical lead and took it from discovery to production in two months.
Fortune 500 POC engagements scaling to 150TB+/day ingestion, with a 30-40% compute cost reduction versus incumbent Elastic stacks at equivalent workloads.
A production system that consolidates correlated alerts into a single incident, generates a root-cause summary, and produces a virtual runbook grounded in the customer telemetry.
Envoy deployed as both general ingress and AI gateway, with model routing across Claude and GPT providers and all AI traffic telemetry flowing back into OpenObserve.
A detection pipeline on OpenObserve with OCSF normalization, risk scoring, and Sigma rules converted to VRL, running internally with an enterprise design partner engaged, ahead of planned productization.
Repeatable Claude-based triage automation for security incidents and discovery findings at OpenObserve.
Confluent Kafka on 25 bare-metal servers, with the live physical servers imported into Terraform and every service managed by Ansible.
A 300-node Cloudera Hadoop cluster managing 5PiB of banking big data, secured with Kerberos, TLS, and Vault dynamic secrets, with 70% of routine operations automated.
Aerospike with replication across data centers, and a search platform migrated from Solr to Elasticsearch, in a regulated GDPR-scoped data environment.
Kerberos implemented on premises and mTLS for server-to-server communication, establishing machine identity at large scale across a regulated on-prem fleet.
>Production LLM systems, shown as architecture with the guardrails made explicit. Status language is precise on purpose.
Alert storms into one grounded incident.
Routing and rate limiting with cost telemetry.
Repeatable first-pass triage automation.
Grounded remediation with strict validation.
LLM converts Sigma rules to VRL.
>Production incidents, told straight: symptom, diagnosis, fix, and the lesson that stuck.
>I turn one-off customer work into reusable assets. The loop runs from a pattern I hit in delivery to a product PR to something the next customer inherits.
Built and maintain the Terraform provider and Kubernetes modules, published to the Terraform Registry.
Authored product PRs enabling dashboards and alerts to export as observability-as-code.
Dashboard migration tooling to move off Datadog.
A library of dashboards for common infrastructure and application monitoring.
CloudFormation templates for AWS GovCloud compliant ingestion, and ARM templates for Azure telemetry.
A Lambda extension project for telemetry from serverless workloads.
UX changes, trace pipeline improvements, usage dashboards, and permission fixes driven by delivery feedback.
>Selected projects I built, plus the certifications behind the depth. ops0 is a founder and shareholder role, non-operational, described in past tense.
Founder and shareholder, non-operational
An AI-native preventive cloud security platform. The positioning was fix and govern, not find and alert. What I built:
+ 3 more
Creator
An open-source Rust-based parallel infrastructure-as-code execution engine.
Creator
An open-source CLI, launched on Product Hunt.
Author and maintainer
The Terraform provider and Kubernetes modules for OpenObserve, published to the Terraform Registry.
>Book a call directly, or reach out on LinkedIn or GitHub.
No phone, no address: reach me through the channels above.