Manpreet Singh Nehra, Developer in Riga, Latvia
Manpreet is available for hire
Hire Manpreet

Manpreet Singh Nehra

Verified Expert  in Engineering

Cloud Security Developer

Location
Riga, Latvia
Toptal Member Since
May 22, 2019

Manpreet is a system administrator and DevOps engineer. Since 2002, he has worked at several startups and multinational corporations. The bulk of his work provided support for developers and infrastructures like bare-metal, public, and private clouds. He has designed and implemented cloud and infrastructure architectures in highly available, scalable, and cost-effective configurations.

Portfolio

SIA Nehra Consultancy
Terraform, OpenStack, Ansible, MySQL, Elasticsearch, Amazon Web Services (AWS)...
Yara International - DNU - Agoro
DevOps, Amazon Web Services (AWS), Terraform, Docker, Kubernetes, AWS DevOps...
Linedata
Python 3, Amazon Web Services (AWS), Debian Linux, Bash, Python, Jira, AWS HA...

Experience

Availability

Full-time

Preferred Environment

Open Source, Linux, Amazon Web Services (AWS), Ansible, Terraform

The most amazing...

...thing I’ve built was a CI/CD pipeline with AWS and Ansible, with no manual intervention, fully from end to end.

Work Experience

DevOps and Automation Engineer

2022 - PRESENT
SIA Nehra Consultancy
  • Implemented the AWS Cloud Networking and Security design.
  • Delivered infrastructure automation using the Terraform modules and templates code.
  • Deployed application automation using Ansible for the product.
  • Set up EKS and Created and maintained the Kubernetes application with helm packages.
  • Automated the pipelines using Bash and Python Scripting.
  • Set up an Elasticsearch cluster using Ansible and Ansible Galaxy.
  • Deployed a Jelastic application using Ansible and REST.
  • Completed the GitLab CI and GitHub Actions for CI/CD pipelines.
Technologies: Terraform, OpenStack, Ansible, MySQL, Elasticsearch, Amazon Web Services (AWS), Amazon EKS, GitHub, GitLab CI/CD, GitHub Actions, Python 3, Docker, Cloud Security, VPN, Bash, Continuous Integration (CI), Continuous Deployment, Kubernetes, OpenVPN, Amazon CloudWatch, AWS IAM, Amazon Route 53, Amazon Elastic Container Registry (ECR), AWS CloudTrail, Docker Hub, IT Security, Amazon Elastic Container Service (Amazon ECS), Git, Automation, Shell Scripting, Lambda Functions, DevOps Engineer, Identity & Access Management (IAM), Serverless, Containers, Cloud Architecture, Cloud Services, Helm, Load Balancers, Container Orchestration, Cloud Computing, Architecture, AWS Transit Gateway, Scripting, AWS Cloud Architecture, Serverless Architecture, Security, Cloud Infrastructure, Cloud Migration, SFTP, Microservices Architecture, Cloud, Amazon S3 (AWS S3), AWS Lambda, Amazon DynamoDB, AWS Certified Solution Architect, Containerization, Virtualization, GitOps, Hybrid Cloud Infrastructure, DNS, HAProxy, Kibana, TrueNAS, IaaS, AWS Fargate, Databases, Continuous Development (CD), AWS Cloud Computing Services, Network Monitoring, Infrastructure Monitoring, Amazon API, AWS NAT Gateway, Let's Encrypt, SSL Certificates, Google Workspace, Firewalls, Amazon ElastiCache, IT Operations Management (ITOM), On-premise, Amazon Machine Images (AMI), Microservices, Configuration Management, Amazon EC2, Linux Server Administration, SysOps, Server Administration, AWS Database Migration Service (DMS), SIEM, Linux, Control & Cost Analysis, File Servers, Network Administration, Amazon Aurora, Logging, Scripting Languages, Documentation

Senior DevOps Engineer for a Major Agronomy Project

2020 - 2021
Yara International - DNU - Agoro
  • Implemented the AWS Cloud Networking and Security design.
  • Delivered infrastructure automation using the Terraform modules and templates code.
  • Created and maintained the Kubernetes application with helm packages.
Technologies: DevOps, Amazon Web Services (AWS), Terraform, Docker, Kubernetes, AWS DevOps, AWS HA, Amazon CloudWatch, AWS IAM, Amazon Route 53, Amazon Elastic Container Registry (ECR), AWS CloudTrail, Docker Hub, IT Security, Git, Automation, Shell Scripting, Lambda Functions, DevOps Engineer, Identity & Access Management (IAM), Serverless, Containers, Cloud Architecture, Cloud Services, Helm, Load Balancers, Container Orchestration, Cloud Computing, Architecture, AWS Transit Gateway, Scripting, AWS Cloud Architecture, Serverless Architecture, Security, Cloud Infrastructure, Cloud Migration, Microservices Architecture, Cloud, Amazon S3 (AWS S3), AWS Lambda, Amazon DynamoDB, AWS Certified Solution Architect, Containerization, Virtualization, GitOps, DNS, Content Delivery Networks (CDN), IaaS, AWS Fargate, Databases, Continuous Development (CD), AWS Cloud Computing Services, Application Monitoring, Infrastructure Monitoring, Amazon API, AWS NAT Gateway, SSL Certificates, Firewalls, Amazon ElastiCache, Amazon Machine Images (AMI), Microservices, Amazon EC2, Linux Server Administration, Server Administration, AWS Database Migration Service (DMS), SIEM, Linux, Control & Cost Analysis, Network Administration, Amazon Aurora, Logging, Scripting Languages, Documentation

DevOps Engineer

2018 - 2020
Linedata
  • Implemented the AWS Cloud Networking and Security design.
  • Delivered infrastructure automation using the Terraform modules and templates code.
  • Set up EKS and Kubespray for deployment using the Kubernetes Cluster.
  • Automated the pipelines using Bash and Python Scripting.
Technologies: Python 3, Amazon Web Services (AWS), Debian Linux, Bash, Python, Jira, AWS HA, Terraform, Bash Script, Continuous Integration (CI), DevOps, DevSecOps, CI/CD Pipelines, Amazon RDS, Architecture, Continuous Delivery (CD), GitHub, Continuous Deployment, Infrastructure as Code (IaC), Monitoring, Networking, Cloud Security, Subnet, Infrastructure, Scalability, Kubernetes, Amazon CloudWatch, AWS IAM, Amazon Route 53, AWS CloudTrail, Docker Hub, IT Security, Server Security, Git, Automation, Shell Scripting, Lambda Functions, DevOps Engineer, Identity & Access Management (IAM), Serverless, Containers, Cloud Architecture, Cloud Services, Helm, Load Balancers, Container Orchestration, Cloud Computing, AWS Transit Gateway, Scripting, AWS Cloud Architecture, Serverless Architecture, Security, Cloud Infrastructure, Cloud Migration, SFTP, Microservices Architecture, Redis, Cloud, Amazon S3 (AWS S3), AWS Lambda, Amazon DynamoDB, AWS Certified Solution Architect, Containerization, Virtualization, GitOps, Hybrid Cloud Infrastructure, DNS, Content Delivery Networks (CDN), IaaS, AWS Fargate, Databases, Continuous Development (CD), AWS Cloud Computing Services, Application Monitoring, Network Monitoring, Infrastructure Monitoring, Amazon API, AWS NAT Gateway, SSL Certificates, Firewalls, Amazon Machine Images (AMI), Microservices, Configuration Management, Amazon EC2, Linux Server Administration, SysOps, Server Administration, SIEM, Linux, Control & Cost Analysis, Network Administration, Amazon Aurora, Logging, Scripting Languages, Documentation

Senior Infrastructure Engineer

2017 - 2018
Belzabar Software Pvt. Ltd
  • Implemented OpenVPN (routed) to connect all managed locations with failovers using Corosync/Pacemaker.
  • Performed a GitLab continuous integration using Docker.
  • Completed a GitLab continuous integration using the AWS Platform.
  • Set up authentication with Samba 4 for AD-based auth.
  • Established an Ansible set up for CI/CD for the app and infra.
Technologies: Python 3, GitLab CI/CD, Amazon Web Services (AWS), Debian Linux, Bash, GitLab, OpenVPN, Python, Docker, Ansible, AWS HA, Bash Script, Continuous Integration (CI), Amazon Route 53, DevOps, DevSecOps, CI/CD Pipelines, AWS NLB, Amazon RDS, Architecture, Continuous Delivery (CD), GitHub, Continuous Deployment, Infrastructure as Code (IaC), Monitoring, Networking, Cloud Security, Subnet, VPN, Infrastructure, Docker Hub, IT Security, Server Security, Git, Automation, Shell Scripting, DevOps Engineer, Identity & Access Management (IAM), Containers, Load Balancers, Container Orchestration, Cloud Computing, Scripting, Security, Cloud Infrastructure, SFTP, Redis, Cloud, Amazon S3 (AWS S3), AWS Certified Solution Architect, Containerization, Virtualization, GitOps, Hybrid Cloud Infrastructure, DNS, IaaS, Databases, Continuous Development (CD), AWS Cloud Computing Services, Application Monitoring, Network Monitoring, Infrastructure Monitoring, Amazon API, AWS NAT Gateway, Let's Encrypt, SSL Certificates, Firewalls, Amazon Machine Images (AMI), Configuration Management, Amazon EC2, Linux Server Administration, Server Administration, Linux, Control & Cost Analysis, Logging, Scripting Languages, Documentation

Chief Architect

2016 - 2017
Nehra Consultancy Services
  • Created an auto-scaling product and designed high availability.
  • Scaled a new product using the OpenNebula auto-scaling tool and built the set up from scratch.
  • Implemented Tally on a cloud set up for OpenNebula.
Technologies: Python 3, Amazon Web Services (AWS), Debian Linux, Bash, GitLab, SaltStack, GitHub, Continuous Deployment, Infrastructure as Code (IaC), Monitoring, Networking, Cloud Security, Subnet, VPN, Infrastructure, Server Security, Git, Automation, Shell Scripting, DevOps Engineer, Identity & Access Management (IAM), Containers, Load Balancers, Cloud Computing, Scripting, Amazon Elastic Container Service (Amazon ECS), SFTP, Redis, Cloud, Amazon S3 (AWS S3), Containerization, GitOps, Hybrid Cloud Infrastructure, DNS, HAProxy, IaaS, Databases, Continuous Development (CD), AWS Cloud Computing Services, Network Monitoring, Infrastructure Monitoring, Amazon API, AWS NAT Gateway, NGINX, Let's Encrypt, SSL Certificates, Google Workspace, Firewalls, IT Operations Management (ITOM), On-premise, Amazon EC2, Linux Server Administration, Server Administration, Linux, Logging, Documentation

Manager – Systems (Server Support)

2015 - 2016
Tolexo Online Pvt. Ltd
  • Provided server support for a Linux operating system.
  • Supported an application (Nginx, PHP, FPM, Go, and Node.js).
  • Provided database support for applications using Magento.
  • Implemented Zabbix to monitor all of the servers along with Grafana and Datadog.
  • Used Samba 4 for central authentication with LDAP/Kerberos.
  • Implemented SaltStack for configuration management.
  • Built an environment and cloud-based internal storage using ownCloud.
  • Wrote scripts to manage LDAP (Perl) and integrated Zabbix and LDAP; also created deployment scripts (Bash) for live/QA deployments.
  • Created a VPN network to integrate all production environments and make single-point monitoring possible.
  • Administered trouble ticketing, using a request tracker and a documentation program called Foswiki (Markdown).
Technologies: Amazon Web Services (AWS), Debian Linux, Bash, Zabbix, Python, OpenVPN, SaltStack, Samba, Bash Script, ELK (Elastic Stack), CI/CD Pipelines, Continuous Deployment, Monitoring, Networking, Subnet, VPN, Infrastructure, Server Security, Git, Automation, Shell Scripting, DevOps Engineer, Containers, Load Balancers, Cloud Computing, Scripting, MongoDB, SFTP, Redis, CentOS, DNS, HAProxy, IaaS, Databases, Application Monitoring, Network Monitoring, Infrastructure Monitoring, NGINX, Let's Encrypt, SSL Certificates, Firewalls, IT Operations Management (ITOM), On-premise, Linux Server Administration, SysOps, Server Administration, Linux, Logging, Documentation

Senior Systems Administrator

2014 - 2015
Lazada.com
  • Supported a Linux operating system on servers; also provided Nginx and database support for applications.
  • Monitored all of the servers and various custom parameters using Zabbix.
  • Implemented an LDAP central directory for authentication and authorization.
  • Composed scripts to manage LDAP (Perl) and integrate Zabbix and LDAP.
  • Implemented Mcrouter and conducted testing for various setups.
  • Used Puppet for configuration management and development environment set up scripts.
  • Developed a VPN network to integrate all production environments and make single-point monitoring possible.
Technologies: Debian Linux, Bash, Zabbix, OpenVPN, Perl, LDAP, NGINX, Bash Script, Monitoring, Networking, Subnet, VPN, Infrastructure, Server Security, Git, Shell Scripting, DevOps Engineer, Containers, Load Balancers, Scripting, SFTP, Redis, DNS, Databases, Application Monitoring, Infrastructure Monitoring, SSL Certificates, Firewalls, IT Operations Management (ITOM), On-premise, Configuration Management, Linux Server Administration, SysOps, Server Administration, Linux, Logging, Documentation

Systems Administrator

2011 - 2014
Freelance Work
  • Chose and implemented Bacula for central authentication and the streamlining of backups.
  • Set up single sign-on testing using OpenLDAP and Kerberos.
  • Enabled single sign-on by using Samba 4 as AD and LDAP/Kerberos.
  • Enabled master-master replication between MySQL servers (active-passive).
  • Set up LDAP and Kerberos for clients (Linux) with samba4 as a server.
  • Implemented Cacti and Nagios monitoring with dashboards and alerts.
  • Set up Bind and DHCPD with automatic updates and bind replication and a DHCP peer.
Technologies: Debian Linux, Nagios, BIND, Corosync, Pacemaker, MySQL, Samba, Kerberos, OpenLDAP, Apache2, MySQL/MariaDB, Bash Script, Keepalived, Grafana, ELK (Elastic Stack), Monitoring, Networking, Subnet, VPN, Infrastructure, OpenBSD, Git, Shell Scripting, DevOps Engineer, Containers, Load Balancers, Scripting, SFTP, LAMP, DNS, Databases, Application Monitoring, Network Monitoring, Infrastructure Monitoring, NGINX, SSL Certificates, Firewalls, IT Operations Management (ITOM), On-premise, Linux Server Administration, SysOps, Server Administration, Linux, File Servers, Logging, Documentation

Senior Systems Engineer

2008 - 2011
Yahoo R&D Centre India Pvt. Ltd
  • Resolved tickets related to Yahoo media delivery within TAT.
  • Worked with team members in defining requirements of tools developed by operations.
  • Facilitated and coordinated tasks between different teams (development, QA, and operations); focused on operating-system-related issues.
  • Coordinated with developers for application-related issues in production hosts.
  • Implemented change management procedures for configuration changes.
  • Monitored servers/groups for errors and preemptively checked errors and fixed problems.
  • Used Nagios/MRTG to monitor hosts and set up/maintain application jails.
Technologies: Linux, Nagios, System Administration, Networking, NFS, OpenSSL, Shell Scripting, DevOps Engineer, Load Balancers, Scripting, SFTP, LAMP, CentOS, Databases, Application Monitoring, Infrastructure Monitoring, SSL Certificates, IT Operations Management (ITOM), Linux Server Administration, SysOps, Server Administration

Systems Administrator

2007 - 2008
Freelance Work
  • Provided infrastructure support for local and remote servers; worked with Apache/MySQL servers.
  • Implemented load balancing over multiple ISPs (three) using OpenBSD.
  • Replaced the firewall for Linux on OpenBSD to allow LB outgoing connections.
  • Used Cacti for monitoring along with Zabbix for data collection.
Technologies: Debian Linux, Azure Active Directory, OpenBSD, LDAP, NFS, MySQL/MariaDB, Bash Script, Grafana, ELK (Elastic Stack), System Administration, Networking, Subnet, Apache2, OpenSSL, DevOps Engineer, Load Balancers, Scripting, LAMP, CentOS, DNS, Databases, Infrastructure Monitoring, SSL Certificates, Firewalls, IT Operations Management (ITOM), On-premise, Linux Server Administration, SysOps, Server Administration, Linux, File Servers, Documentation

System and Network Manager

2007 - 2007
eSolutions R&D Lab Pvt. Ltd.
  • Built and managed a team of information systems personnel to administer computers, networks, and information systems and provide infrastructure support for local and remote servers; also recruited computer engineers and monitored their training.
  • Monitored the budget and department expenditures.
  • Planned and executed network security policies for the use of electronic and other infrastructure within the organization.
  • Developed software policies for data movement within the organization concerning the code.
  • Managed vendors relations sales and purchase of hardware.
  • Set up the firewall (iptables) and mail server (Postfix) and remotely hosted mail.
  • Successfully set up and maintained TRAC for project management, a wiki for collaboration, and RT for client issues.
  • Imparted training to users on the employment of TRAC; also created and managed Perl scripts to modify TRAC configuration and subversion.
Technologies: Azure Active Directory, BIND, MySQL, Iptables, MySQL/MariaDB, Bash Script, System Administration, Networking, Subnet, Infrastructure, Apache2, NFS, OpenSSL, DevOps Engineer, LAMP, Databases, SSL Certificates, Firewalls, IT Operations Management (ITOM), On-premise, Linux Server Administration, SysOps, Server Administration, Linux, File Servers, Documentation

Docker Image for DevOps

https://github.com/iaacautomation/devops-tools
A generic Docker image to be used in pipelines. Contains tools and apps used for pipelines, Terraform, Ansible, Helm, kubectl, and more. The image is released in Docker Hub and regularly updated, albeit manually.

Kubernetes Cluster

https://gitlab.com/nehraconsultancy/k8s/cluster
A basic Kubernetes on-prem cluster built using Kubespray. The repo only contains the inventory required to make the cluster and the GitLab CI file to redeploy in case of changes.

Grafana Dashboard for OPNSense

https://grafana.com/grafana/dashboards/19366-opnsense/
A Grafana dashboard for multi-WAN/multi-LAN OPNsense firewall. It allows configurable Prometheus scarpe job, changing names for all interfaces according to requirement, and the default OPNsense monitoring.

Kubernetes Services

https://gitlab.com/nehraconsultancy/k8s/core
Terraform and Helmfile to add applications and utilities.

RESULT
• MetalLB
• NGINX Ingress
• cert-manager
• Storage CSI (Truenas)
• Kubernetes Prometheus stack
• Grafana
• Redis cache
• MariaDB/Galera Cluster
• Graphite (for Truenas monitoring)

All deployments are done using GitLab CI/CD.

https://gitlab.com/nehraconsultancy/k8s/core
https://gitlab.com/nehraconsultancy/k8s/utilities

Grafana Dashboard Truenas

https://grafana.com/grafana/dashboards/19580-truenas/
A Truenas SCALE dashboard to monitor all aspects of the NAS, including virtualization and hardware stats:

1. Memory
2. CPU
3. ZFS stats
4. Disk IO
5. Networking IO
6. IPMI hardware temperature and power usage
7. Libvirt for virtualization monitoring

Frameworks

AWS HA

Libraries/APIs

Amazon EC2 API, Amazon API, OpenLDAP, OpenSSL

Tools

Terraform, GitLab, Ansible, AWS CLI, OpenVPN, Amazon CloudWatch, AWS CloudTrail, AWS IAM, NGINX, GitLab CI/CD, Amazon EBS, AWS ELB, AWS Key Management Service (KMS), VPN, Amazon EKS, Git, Let's Encrypt, Amazon Virtual Private Cloud (VPC), Amazon Simple Queue Service (SQS), Amazon Simple Notification Service (Amazon SNS), Pacemaker, Keepalived, Zabbix, Nagios, Grafana, ELK (Elastic Stack), Amazon Simple Email Service (SES), SaltStack, Jira, GitHub, Docker Hub, AWS CodeCommit, AWS CodeDeploy, AWS CodeBuild, AWS CloudFormation, Amazon Elastic Container Service (Amazon ECS), Helm, Kibana, AWS Fargate, Amazon ElastiCache, Logging, Corosync, Amazon Elastic Container Registry (ECR), Amazon CloudFront CDN, Beanstalk, Azure App Service, OPNsense

Paradigms

Continuous Integration (CI), Continuous Delivery (CD), DevOps, DevSecOps, Continuous Deployment, Automation, Continuous Development (CD), Samba, Serverless Architecture, Microservices Architecture, Microservices

Platforms

Linux, Amazon EC2, Debian Linux, Docker, Kubernetes, Amazon Web Services (AWS), AWS ALB, AWS STS, AWS NLB, CentOS, AWS Cloud Computing Services, AWS Lambda, OpenBSD, Apache2, LAMP, AWS Elastic Beanstalk, OpenStack, Azure

Storage

Amazon S3 (AWS S3), MySQL/MariaDB, Elasticsearch, Redis, Amazon DynamoDB, Databases, On-premise, Amazon Aurora, MySQL, MongoDB, Azure Active Directory, NAS Servers, Redshift

Other

AWS Certificate Manager, AWS Security Hub, AWS Secrets Manager, CI/CD Pipelines, Infrastructure as Code (IaC), System Administration, Networking, Cloud Security, Subnet, Infrastructure, AWS DevOps, GitHub Actions, AWS Certified DevOps Engineer, Lambda Functions, DevOps Engineer, Identity & Access Management (IAM), Containers, Cloud Architecture, Cloud Computing, AWS Transit Gateway, AWS Cloud Architecture, Security, Cloud Migration, SFTP, Cloud, AWS Certified Solution Architect, GitOps, Hybrid Cloud Infrastructure, DNS, IaaS, AWS NAT Gateway, SSL Certificates, Amazon Machine Images (AMI), File Servers, Documentation, BIND, Amazon Route 53, Iptables, LDAP, Kerberos, NFS, Architecture, Amazon RDS, Monitoring, IT Security, Server Security, Scalability, AWS CodePipeline, Shell Scripting, Serverless, Cloud Services, Load Balancers, Container Orchestration, Scripting, Cloud Infrastructure, Containerization, Virtualization, Content Delivery Networks (CDN), HAProxy, TrueNAS, Application Monitoring, Network Monitoring, Infrastructure Monitoring, AWS Certified Developer, Firewalls, IT Operations Management (ITOM), Configuration Management, Linux Server Administration, SysOps, Server Administration, AWS Database Migration Service (DMS), SIEM, Control & Cost Analysis, Network Administration, Scripting Languages, Amazon API Gateway, API Gateways, Shield, Azure Administrator, Azure Storage, Azure Virtual Machines, Authentication, PIM, Azure Virtual Networks, Kubespray, Prometheus, Galera Cluster, Container Storage Interface (CSI), Google Workspace, Grafana 2, Redis Clusters, Transport Layer Security (TLS), Amazon Kinesis, Dashboards, Dashboard Development

Languages

Bash, Python 3, Perl, Bash Script, Python

1998 - 2002

Bachelor of Engineering Degree in Chemical Engineering

Thapar Institute of Engineering and Technology - Patiala, India

JANUARY 2023 - JANUARY 2026

AWS Certified Database – Specialty

AWS

DECEMBER 2022 - PRESENT

Microsoft Certified: Azure Administrator Associate

Microsoft

AUGUST 2022 - AUGUST 2025

AWS Certified DevOps Engineer Professional

AWS

JUNE 2022 - JUNE 2025

AWS Certified Solutions Architect - Professional

AWS

JUNE 2022 - JUNE 2025

AWS Certified Advanced Networking - Specialty

AWS

JUNE 2022 - JUNE 2025

AWS Certified Security - Specialty

AWS

JUNE 2022 - JUNE 2025

AWS Certified Solutions Architect Associate

AWS

SEPTEMBER 2021 - AUGUST 2025

AWS Certified SysOps Administrator

AWS

APRIL 2021 - AUGUST 2025

AWS Certified Developer Associate

AWS

Collaboration That Works

How to Work with Toptal

Toptal matches you directly with global industry experts from our network in hours—not weeks or months.

1

Share your needs

Discuss your requirements and refine your scope in a call with a Toptal domain expert.
2

Choose your talent

Get a short list of expertly matched talent within 24 hours to review, interview, and choose from.
3

Start your risk-free talent trial

Work with your chosen talent on a trial basis for up to two weeks. Pay only if you decide to hire them.

Top talent is in high demand.

Start hiring