Juan Tamariz, Developer in Guadalajara, Mexico
Juan is currently unavailable

Juan Tamariz

Bio

Juan is a DevOps tech lead with 15+ years of experience in fintech, eCommerce, and data engineering. He leads small senior DevOps teams as a hands-on coder, shipping platforms that let engineers self-serve infrastructure. Juan's recent wins include a Pulumi Python library powering 100% of microservices, a Jenkins-to-Argo CD GitOps migration that cut deploys from 4 hours to 15 minutes with zero incidents, and $11,000+ in monthly cloud savings via a Karpenter and Kafka rearchitecture.

Portfolio

A Series B Fintech
Python, Kubernetes, Terraform, Pulumi, Ansible, Jenkins, Argo CD, Flux...
Entos, Inc.
Terraform, Amazon EKS, Kubernetes, CloudOps, Docker, Amazon RDS, PostgreSQL...
Yields NV
Docker, Continuous Integration (CI), Kubernetes, YAML, Jenkins, Concourse CI...

Experience

  • Amazon Web Services (AWS) - 8 years
  • Kubernetes - 7 years
  • Terraform - 7 years
  • Python 3 - 6 years
  • Pulumi - 5 years
  • Prometheus - 5 years
  • Karpenter - 3 years
  • Argo CD - 2 years

Preferred Environment

Python 3, Kubernetes, Amazon Web Services (AWS), Google Cloud, Terraform, Azure, Karpenter, Pulumi, Argo CD, Datadog

The most amazing...

...thing I've built is a Pulumi Python library that turned weeks of DevOps tickets into a single import—now powering 100% of microservices across 28 environments.

Work Experience

DevOps Tech Lead

2023 - 2026
A Series B Fintech
  • Built a Pulumi Python platform library that wraps networking, IAM, observability, and Datadog automation, which now powers 100% of microservices (with 14 services and 28 environments) for an engineer self-service infrastructure.
  • Led the migration of 14 microservices across 28 environments from standalone Jenkins to GitOps with Argo CD, cutting deploy time from 4 hours to 15 minutes and eliminating deployment-related incidents.
  • Led a zero-disruption Karpenter migration across 3 EKS clusters (with around 50 nodes) with PDBs and topology spread. Saved around $4,000 monthly and made EKS upgrades non-disruptive (a 6-week project validated on the FinOps platform).
  • Replaced AWS DMS, Kinesis, and Glue with an in-house Kafka cluster for the data-movement layer, saving around $7,000 monthly and reducing the operational surface across the data platform.
  • Drove ongoing FinOps reviews and right-sizing. Reduced OpenSearch by $400 monthly at zero risk, rolled out S3 lifecycle tiering across the estate, and aligned Savings Plans and RIs with AWS quarterly.
  • Owned the data platform end-to-end, including Airbyte, Airflow, DMS, Redshift, multi-region RDS replicas configured for under 5-minute DR with automated backups and scheduled patching across EKS, RDS, and EC2.
  • Led the compliance initiative for SOC 2 and PCI infrastructure controls using Drata, Wiz, and Vanta, including a sub-4-hour remediation SLA for high-severity findings.
  • Built an on-call playbook system that keeps response to high-severity events at single-digit minutes. Personally restored RDS cross-region replication during a NYE P0.
Technologies: Python, Kubernetes, Terraform, Pulumi, Ansible, Jenkins, Argo CD, Flux, Amazon RDS, Redshift, AWS Bedrock AgentCore, Document Management Systems (DMS), Amazon Kinesis, Kafka Connect, GitHub Actions, Cloudflare, AWS WAF, AWS ALB, NGINX, Amazon OpenSearch, Bash, Claude, Cursor AI, n8n, Istio, Helm, Kustomize, Amazon Elastic Container Registry (ECR), Amazon S3 (AWS S3), Jupyter Notebook, Prometheus, Grafana, FinOps, Wiz Cloud Security Platform, Drata, Vanta, Loki, Apache Kafka, Karpenter, Databases

AWS EKS Expert

2023 - 2023
Entos, Inc.
  • Coded different Terraform modules with their implementation through Makefile wrappers to guarantee consistency and easy inclusion on a CI/CD tool.
  • Understood the existing code so I could contribute according to the internal guidelines and code style.
  • Fixed different situations detected in previous implementations daily.
Technologies: Terraform, Amazon EKS, Kubernetes, CloudOps, Docker, Amazon RDS, PostgreSQL, Ansible, Packer, Amazon EC2, Amazon Aurora, Amazon ElastiCache, GitHub Actions, Cloud Migration, Karpenter, Databases

AWS | DevOps

2021 - 2023
Yields NV
  • Worked on a migration from Jenkins-X to Concourse CI, which involved mastering the Concourse CI technology. The migration was completed by moving 29 projects from the old platform to the new one, resulting in more than 120 pipelines.
  • Coded a generator of pipelines for Concourse CI, which takes a YTT template and variables as input to then output a pipeline definition in a YAML format. This helps the development team to be self-sufficient in maintaining the concourse pipelines.
  • Maintained more than 120 different pipelines on Concourse CI. Managed the automation of pull requests and merged them into the release branch. Tested code, built artifacts, and published them in collaboration with the development team.
  • Collaborated on the IBM Cloud project to set up the security recommendations for a Yields NV project. Worked together with the Yields NV team and other external contractors. Used relevant technologies like Kubernetes.
  • Automated a way to perform smoke tests on ephemeral clusters. Used tools such as Kubernetes, Terraform, Concourse CI, Bash, Python, and Google Cloud.
  • Maintained the CI setup "in-house" by using technologies like Kubernetes, Google Cloud, Bash, and Python.
  • Automated the updates on the Concourse CI pipelines, which resulted in a product where developers need to push the pipeline changes to a specific repo for Concourse to update its own pipelines automatically.
Technologies: Docker, Continuous Integration (CI), Kubernetes, YAML, Jenkins, Concourse CI, Google Cloud, IBM Cloud, Google Cloud Platform (GCP), CI/CD Pipelines, Site Reliability Engineering (SRE), Leadership, GitHub, SSL Certificates, Python, Infrastructure as Code (IaC), Configuration Management, Microservices, Continuous Deployment, Infrastructure as a Service (IaaS), Go, Amazon EC2, Amazon Aurora, Amazon ElastiCache, GitHub Actions, Cloud Migration, Databases

Senior DevOps Engineer

2019 - 2021
Tacit Knowledge
  • Improved monitoring for a Google Cloud project with the setup of Prometheus Operator on Kubernetes.
  • Implemented CI/CD automation for “1-click” deployments with no downtime. Building custom AMIs as well as Docker images with AWS Code Build.
  • Defined an internal workflow to continuously test Helm charts for Kubernetes with an internal repository.
  • Defined and configured monitoring and alerting policies for site reliability engineering (SRE).
  • Upgraded Jenkins ​and Ansible to guarantee service availability and maintainability of deployment scripts.
  • Developed Python code to create lambda functions to automate firewall whitelisting and storage cleanup.
Technologies: Kubernetes, Google Kubernetes Engine (GKE), Azure Kubernetes Service (AKS), Amazon EKS, Terraform, AWS CloudFormation, Ansible, Python 3, Helm, EFK Stack, Prometheus, Jenkins, AWS Key Management Service (KMS), Solution Architecture, Java, Amazon RDS, AWS Command Line Interface (CLI), AWS IAM, Google Cloud Platform (GCP), Monitoring, CI/CD Pipelines, Site Reliability Engineering (SRE), GitHub, SSL Certificates, Node.js, Python, Infrastructure as Code (IaC), Configuration Management, Amazon DynamoDB, Microservices, Continuous Deployment, Infrastructure as a Service (IaaS), Amazon EC2, Amazon Aurora, GitHub Actions, FinOps

Senior DevOps Consultant

2018 - 2018
Levi Strauss & Co
  • Supported and improved an AWS serverless architecture.
  • Defined a model for support and escalations of user access requests.
  • Established a CloudFormation library to be used for infrastructure deployments.
Technologies: AWS Lambda, Redshift, AWS Glue, AWS CloudFormation, Terraform, Java, Amazon RDS, AWS Command Line Interface (CLI), AWS IAM, Monitoring, CI/CD Pipelines, Site Reliability Engineering (SRE), GitHub, SSL Certificates, Infrastructure as Code (IaC), Configuration Management, Microservices, Continuous Deployment, Infrastructure as a Service (IaaS), Serverless Architecture

DevOps Engineer Consultant​

2016 - 2018
Tacit Knowledge
  • Deployed ​a private Chef Supermarket​ to promote common practices with wrapper and community cookbooks.
  • Created​ custom Chef resources ​with Ruby scripts to automate backups with duplicity.
  • Designed and developed environments in​ Kubernetes to production​ with Helm in Google Cloud.
  • Designed and developed environments in ​AWS using Jenkins,​ Ansible, OpenVPN, OpenLDAP, and CloudFormation.
  • Establish​ed CI/CD ​workflows for clients with virtual machines and containers in Google Cloud.
  • Migrated a Kubernetes cluster from Google Cloud to Azure which provided service portability.
  • Performed log parsing tuning for Stackdriver in Google and CloudWatch in AWS.
  • Autoscaled a cluster of Java applications with CloudFormation in AWS, which provided highly available infrastructure.
Technologies: Chef, Ansible, Percona, Nagios, Terraform, AWS CloudFormation, Google Kubernetes Engine (GKE), Jenkins, OpenVPN, OpenLDAP, Ruby, APM, Google Stackdriver, Amazon CloudWatch, Java, Amazon RDS, AWS Command Line Interface (CLI), AWS IAM, Google Cloud Platform (GCP), Monitoring, CI/CD Pipelines, Site Reliability Engineering (SRE), Leadership, GitHub, SSL Certificates, Node.js, Infrastructure as Code (IaC), Configuration Management, Microservices, Continuous Deployment, Infrastructure as a Service (IaaS), Serverless Architecture

DevOps and SysAdmin Manager

2008 - 2016
PriceTravel
  • Managed projects with budgets of $2.5 million for a colocation setup expansion.
  • Scripted policies and procedures to establish configurations in compliance with the PCI for credit card management.
  • Developed an HA cluster with the SQL Server to provide an RTO of one minute in case of hardware failure.
  • Composed shell scripting for the management of 350 network routers.
  • Installed and built the configuration remotely, which resulted in a new record for the company, mounting 75 servers in one day.
  • Managed the infrastructure by monitoring more than 300 servers with Nagios, Cacti, MRTG, and Datadog.
  • Provided tier-three support in networking, VoIP, the email server, databases, and 3rd-party applications (server-side).
  • Deployed SQL Monitor, Nagios, and New Relic for monitoring and proactive planning.
  • Automated deployments of Java applications and implemented virtualization for production servers with Windows and Linux.
Technologies: Windows Server, DHCP, DNS, SQL Server 2015, Bash Script, Hyper-V, Fortinet Firewall Configuration, Active Directory Federation, Multiprotocol Label Switching (MPLS), Mail Servers, Nagios, Datadog, VoIP, IIS 7, Linux, APM, Ubiquiti Wireless Gear, Monitoring, Leadership, SSL Certificates, Configuration Management, Continuous Deployment

Experience

Zero-downtime Deployments

KEY CONTRIBUTIONS
• Set up the infrastructure for 4 different environments, including production. CI/CD, monitoring, backups, and security tools.
• Established the automation to continuously introduce security patches from lower environments to production.
• Set up AWS Inspector to validate possible new vulnerabilities in the code.
• Set up a CI/CD pipeline including code testing, security assessment, and a no-downtime deployment strategy that covers database upgrades. This reduced the application's downtime in production and increased the production release frequency.
• Implemented core component upgrades to reduce costs and maximize performance for the client.

A CI/CD Framework to Speed-up Project Setups

I built a framework to automate the bootstrapping of several tools for a CI/CD pipeline, which included the build, code promotion, static code testing, performance baselines, and continuous deployment.

The impact of my work was a significant reduction of implementation time for new pipelines from 30 days to 7 days.

JupyterHub Notebooks in Kubernetes

Using KubeSpawner, I developed an implementation of JupyterHub Notebooks. It provides a long-term solution for on-demand autoscaling of user instances alongside Kubernetes' allocated resources.

At a glance, for every user logged in, a new Kubernetes pod is created on-demand. When more resources are needed, the Kubernetes cluster will also auto-scale.

Terraform Modules to Speed-up Infrastructure Creation

A full project that involved analyzing requirements and defining dependencies and stakeholders.

I created an Agile project to track the creation of every Terraform module. We ended up on a set of authorized scripts that were instanced on several projects on Google Cloud.

As a result, project setup speed improved from a month to every 3 days with the scripts. The framework considered the usage of the latest available Terraform version, along with a shared back end/state to make collaboration easier.

Pulumi Python Platform Library – Self-service Infrastructure

A Python platform library that wraps Pulumi with company-specific standards for networking, IAM, secrets, observability, and Datadog monitor automation. Engineers self-serve their own infrastructure by instantiating a single class; DevOps owns the library and the guardrails behind it.

OUTCOME
• 100% adoption across 14 microservices and 28 environments.
• Removed DevOps from the critical path of new service onboarding.
• IAM scoping, tagging, and Datadog checks are now applied uniformly across the estate with no human review needed for standard cases.
• Production-grade today; actively extended as new services come online.

Jenkins to Argo CD GitOps Migration – 14 Services & 28 Environments

Migrated 14 microservices across 28 environments from standalone Jenkins pipelines to a GitOps model on Argo CD, with PR-based promotion, automated sync, and full visibility into deployment health.

OUTCOME
• Deploy time dropped from 4 hours to 15 minutes.
• Deployment-related incidents reduced to zero (100% reduction).
• CI cost reduced by retiring legacy Jenkins workers.
• Every release is now auditable through Git history rather than tickets, and rollbacks are a single revert.

Kafka Cluster Replacing AWS DMS, Kinesis, & Glue

Designed and rolled out a Kafka cluster to replace an AWS DMS, Kinesis, and Glue data-movement pipeline. The new architecture consolidated 3 managed services into a single operator-friendly platform, improved end-to-end latency, and simplified the data team's day-to-day operations.

OUTCOME
• Around $7,000 per month in cloud cost savings.
• Lower operational surface for the data platform team.
• Foundation is now in place for downstream stream-processing work—including change data capture, real-time analytics, and event-driven services.

Karpenter Migration – Zero-disruption Multi-cluster

Migrated 3 EKS clusters with around 50 nodes from overprovisioned static node groups to Karpenter without any production disruption. I introduced PodDisruptionBudgets, topology spread constraints, and per-workload validation before cutover, then drove a 6-week rollout, culminating in a final FinOps validation report.

OUTCOME
• Around $4,000 per month in cluster cost savings, validated by the FinOps platform.
• EKS version upgrades are now non-disruptive—a recurring source of toil was eliminated.
• The same runbook was reused on a second client engagement, replacing the AWS Cluster Autoscaler and avoiding a Cast AI license.

Education

2005 - 2013

Bachelor's Degree in Computer Systems

Universidad del Caribe - Cancun, Mexico

Skills

Libraries/APIs

OpenLDAP, Node.js

Tools

Helm, Ansible, Terraform, SAP Hybris, Google Kubernetes Engine (GKE), Azure Kubernetes Service (AKS), Amazon EKS, AWS CloudFormation, EFK Stack, Jenkins, AWS Key Management Service (KMS), Nagios, Bitbucket, Git, HashiCorp, Docker Hub, AWS Command Line Interface (CLI), AWS IAM, GitHub, Chef, Amazon ElastiCache, Loki, AWS Glue, OpenVPN, Google Stackdriver, Amazon CloudWatch, Hyper-V, Apache JMeter, SonarQube, HashiCorp Vault, Concourse CI, CloudOps, Packer, Kafka Connect, NGINX, Amazon OpenSearch, Claude, n8n, Istio, Kustomize, Amazon Elastic Container Registry (ECR), Grafana

Languages

Python, Python 3, Java, Go, Ruby, Bash Script, YAML, Bash

Frameworks

Flux

Paradigms

DevOps, Microservices, Continuous Deployment, Object-oriented Programming (OOP), Serverless Architecture, REST, Continuous Integration (CI)

Platforms

Kubernetes, Linux, Amazon Web Services (AWS), Docker, Google Cloud Platform (GCP), Amazon EC2, Vanta, Azure, AWS Lambda, Percona, Windows Server, AWS ALB, Jupyter Notebook, Apache Kafka

Storage

Google Cloud, Datadog, Amazon Aurora, Databases, Amazon DynamoDB, Redshift, Google Cloud Storage, PostgreSQL, Amazon S3 (AWS S3)

Other

Networking, Back-end Admin Systems, VoIP, Web Servers, Prometheus, DNS, Ubiquiti Wireless Gear, Groovy Scripting, Pulumi, Content Delivery Networks (CDN), Amazon RDS, Monitoring, CI/CD Pipelines, Site Reliability Engineering (SRE), Leadership, SSL Certificates, Infrastructure as Code (IaC), Configuration Management, Infrastructure as a Service (IaaS), GitHub Actions, Cloud Migration, Argo CD, GitOps, FinOps, Drata, Wiz Cloud Security Platform, Karpenter, Serverless, Amazon Inspector, Solution Architecture, Platform Engineering, APM, DHCP, SQL Server 2015, Fortinet Firewall Configuration, Active Directory Federation, Multiprotocol Label Switching (MPLS), Mail Servers, IIS 7, Agile DevOps, IBM Cloud, AWS Bedrock AgentCore, Document Management Systems (DMS), Amazon Kinesis, Cloudflare, AWS WAF, Cursor AI, AWS Database Migration Service (DMS), Data Engineering, spot instances

Collaboration That Works

How to Work with Toptal

Toptal matches you directly with global industry experts from our network in hours—not weeks or months.

1

Share your needs

Discuss your requirements and refine your scope in a call with a Toptal domain expert.
2

Choose your talent

Get a short list of expertly matched talent within 24 hours to review, interview, and choose from.
3

Start your risk-free talent trial

Work with your chosen talent on a trial basis for up to two weeks. Pay only if you decide to hire them.

Top talent is in high demand.

Start hiring