Available for DevOps Lead & SRE Roles
Hi, I'm Roman Ekimov
DevOps Lead & Senior SRE / Infrastructure Engineer
15+ years designing, automating, and operating mission-critical multi-cloud infrastructure for fintech, high-frequency trading, and high-load banking platforms. Specialized in Kubernetes, Infrastructure as Code, CI/CD GitOps, FinOps cost reduction, and SRE reliability engineering.
roman.ekimov@gmail.com
@toywar
LinkedIn
Belgrade, Serbia
Serbian permanent residence • Russian citizen
Prefer a web page? Read the CV in your browser.
DevOps Lead
15+
Years of Experience
-30%
Infrastructure Cost
99.99%
Production SLA/SLO
MultiCloud
GCP • AWS • On-Prem
Tech Stack & Skills
Technical Specialties
Operating Systems & Linux
Cloud Platforms & Bare-Metal
Containerization & Orchestration
Infrastructure as Code & CI/CD
Security & Secret Management
Observability & SRE
Databases, Proxies & Brokers
Development & Scripting
Career History
Professional Experience
DevOps Lead
FinharborFintech company providing global payment and financial infrastructure
- Function Ownership & Technical Leadership: End-to-end owner of the DevOps & infrastructure function — technical roadmap, sprint planning, and prioritization — leading infrastructure workstreams together with the backend, security, and product teams; onboarded and mentored a DevOps engineer and codified runbooks, on-call, and IaC standards so practices outlive individuals.
- Infrastructure Strategy & Architecture: Driving infrastructure architecture for fintech microservices, ensuring high availability, disaster recovery, and compliance readiness.
- Flagship Delivery — Asterium (Uzbekistan): Led the infrastructure workstream behind the hybrid neobank & digital-asset platform delivered for Asterium: environment topology, regional hosting and data residency, capacity planning, and production go-live readiness across the platform’s full IT estate — core banking, card issuing, the exchange, and KYC/AML services — under Uzbekistan’s NAPP-regulated framework.
- PCI DSS & Security Governance: Owning the infrastructure side of PCI DSS compliance — maintaining certified scope and network segmentation, secret & key management (HashiCorp Vault / OpenBao), centralized audit logging, periodic access reviews, and evidence collection for annual re-certification audits.
- FinOps & Cost Reduction: Cut monthly cloud spend by ~30% — imported every pre-existing cloud resource into Terraform state to get complete spend visibility, then decommissioned orphaned resources, right-sized Kubernetes node pools, and trimmed log ingestion and retention.
- Client & Partner Engagement: Directly communicating with enterprise clients and partners regarding infrastructure integrations, security requirements, disaster recovery, and SLA guarantees.
- AI-Assisted Delivery: Adopted AI coding agents into day-to-day infrastructure work — IaC changes, pipeline scaffolding, runbook and documentation drafts — to shorten delivery cycles on routine tasks; contributing to an internal initiative building a fleet of agents wired into the task tracker to pick up tickets and prepare changes for human review.
- Process Standardization: Standardizing GitOps, CI/CD, and IaC practices across engineering squads to accelerate product release velocity and ensure deployment consistency.
- Incident & SRE Governance: Establishing on-call schedules, incident response protocols, and postmortem workflows to maintain high reliability.
DevOps Engineer
FinharborFintech company providing global payment and financial infrastructure
- Multi-Cloud & Hybrid Infrastructure: Designed, deployed, and scaled multi-cloud infrastructure across Google Cloud Platform (GCP), Servercore, and DigitalOcean, alongside bare-metal and VM environments.
- Infrastructure as Code: Implemented and managed IaC using Terraform, OpenTofu, Helm, ArgoCD, Ansible, and Packer for fintech microservices.
- CI/CD & GitOps: Built automated CI/CD pipelines in GitLab CI and GitOps workflows via ArgoCD, creating Helm charts to deploy polyglot microservices (Java, Kotlin, JavaScript/TypeScript, Rust, Go) into cloud Kubernetes (GKE) clusters.
- Asterium Platform Build-Out (Uzbekistan): Delivered the cloud infrastructure for the Asterium hybrid neobank & digital-asset platform — provisioned multi-environment Kubernetes landing zones with Terraform, Helm, and ArgoCD, plus CI/CD pipelines, secret management, and observability for the platform’s entire service estate — core banking, card issuing, exchange, and KYC/AML/KYT microservices.
- PCI DSS Compliance: Participated in the PCI DSS audit and certification process: enforced infrastructure security controls, network isolation, audit logging, and secret management using HashiCorp Vault / OpenBao.
- Observability & SRE: Designed and maintained comprehensive observability and monitoring stacks (Prometheus, VictoriaMetrics, Grafana), implementing SRE practices to ensure 99.99% uptime for core financial services.
- Data Stores & Streaming: Managed and tuned data stores and streaming platforms including PostgreSQL, Redis, and Apache Kafka for low-latency transaction processing.
DevOps Engineer (Fintech Team)
Blockchain FamilyBlockchain integrations and decentralized fintech infrastructure
- Cloud & Container Infrastructure: Managed and scaled GCP cloud infrastructure and Docker Compose environments across bare-metal and VM platforms.
- IaC & Automation: Developed and maintained IaC for fintech and blockchain projects in GCP using Terraform, Ansible, and Packer.
- CI/CD Pipelines: Engineered GitLab CI pipelines and Helm charts to deploy Java, Rust, and Go microservices to cloud Kubernetes (GKE) clusters.
- Decentralized Messaging: Implemented DevOps practices, containerization, and deployment automation for a secure messaging platform based on the Matrix protocol.
- Reliability & SRE: Established infrastructure observability and SRE practices to ensure service stability, fault tolerance, and high availability.
DevOps Engineer / SRE
Tinkoff BankTOP-10 Bank & Fintech Ecosystem (Processing Systems Infrastructure Team)
- Core Banking Infrastructure: Maintained and optimized enterprise Linux (RHEL, CentOS, Ubuntu) infrastructure supporting mission-critical 24/7 payment processing.
- Anti-Fraud Tooling in Go: Developed custom monitoring, diagnostic, and automation utilities in Go (Golang) for the bank’s anti-fraud unit — exporting processing-system metrics and alerting signals that helped analysts spot and block fraudulent activity earlier, alongside general banking infrastructure operations.
- Observability as Code: Implemented IaC for enterprise observability and logging stacks (Prometheus, ELK Stack, Zabbix).
- CI/CD & Orchestration: Built CI/CD pipelines (GitLab CI, Jenkins) and deployment manifests (Kustomize, Helm) for Java, Rust, and Go applications across on-premise and cloud Kubernetes / Docker Swarm clusters (bare-metal, VMs, AWS).
- Acting Team Lead & Mentoring: Deputized for the team lead of the processing-systems infrastructure team during absences — running daily priorities and task assignment, coordinating on-call coverage and incident escalation, and representing the team in cross-department change reviews; onboarding mentor for a newly joined engineer (environment ramp-up, runbooks, first on-call rotations).
- SRE & 24/7 Operations: Served as an SRE ensuring 24/7 reliability and uptime of high-load transaction processing systems (on-call rotations, SLA/SLO tracking, incident troubleshooting, and root cause postmortems).
Infrastructure Engineer
EXANTEGlobal Investment Company (OPS Team)
- Centralized Logging: Designed and deployed a high-availability centralized logging platform (Elasticsearch + Graylog + Fluentd) with HAProxy load balancing across all company services and servers.
- Bare-Metal Kubernetes: Built and managed an on-premise Kubernetes cluster on bare-metal hardware for core trading and internal systems.
- CI/CD Modernization: Migrated legacy pipelines from Jenkins to GitLab CI, improving build efficiency and deployment consistency.
- Configuration as Code: Automated server provisioning and maintenance across Debian/Ubuntu fleets using Chef.
- HR Automation: Automated HR onboarding and offboarding workflows with custom integrations between BambooHR and Google Workspace.
- Exchange Connectivity: Supported low-latency market connectivity tools and trading infrastructure (FIX protocol, trading terminals) connected to major global exchanges (NYSE, NASDAQ, LSE).
- Acting Team Lead: Stood in as acting lead of the Operations (OPS) team during the team lead’s absences — owning sprint priorities, task distribution, incident response, and infrastructure maintenance for the duration.
IT Support & Network Engineer
Center for Pedagogical ExcellenceIT & Network Operations Team
- Systems & Workstations: Administered Linux and Windows servers along with all organizational workstations (Windows, macOS).
- Campus Network (NOC): Configured and maintained Cisco, MikroTik, Extreme Networks, and HP networking hardware; established site-to-site connectivity across three campus buildings in Moscow.
- Automated Provisioning: Built an automated mass-provisioning system for rapid OS deployment and software configuration across hundreds of laptops for academic olympiads and training sessions.
- Monitoring Stack: Implemented infrastructure-wide monitoring and dashboards using Observium, InfluxDB, Telegraf, and Grafana.
Academic Background
Education & Languages
Moscow University for Industry and Finance
Specialist / Master's Degree in Applied Informatics in Economics (Faculty of Information Technologies)
2007 – 2012
Languages
Russian
Native
English
Advanced (C1)
Working language — daily written and spoken use with international teams
Serbian
Conversational
Everyday conversation; living in Belgrade since 2022
Let's Connect & Build Together
Interested in discussing DevOps architecture, SRE best practices, infrastructure optimization, or leadership opportunities? Feel free to reach out directly.