Talha Imtiaz

Open to the right fully remote DevOps role·Based in Lahore, Pakistan · working US/EU hours

DevOps engineer for production systems that have to hold.

Talha Imtiaz

Took a real-time multiplayer backend from crashing at ~80 players to holding 400+ on GKE, took a regulated US lending platform's Kubernetes API and databases off the public internet, and closed the public admin paths on a healthcare AWS estate under SOC 2 Type 1 and HIPAA obligations — and I read the application code underneath.

I read the codebase, not just the infra

I’m Talha a DevOps engineer who came up as a software engineer first. I work across Kubernetes, GKE, KEDA autoscaling, Dockerized services, GitLab and GitHub CI/CD, observability, incident response, and hardened Linux deployments.

Based in Lahore, Pakistan · working US/EU hours. Open to the right fully remote DevOps role.

Production systems, and the decisions behind them

Real-time multiplayer scaling on GKE, sized from load tests instead of CPU

A host-led game failed exactly when the room joined. I found that more collaboration pods increased broadcast overhead, split the API from sockets, sized fewer larger pods from load tests, and scaled the frontend before the lobby moved into play.

Client details stay private. I can share the architecture, the constraints, and the reasoning.

Architecture diagram of a multiplayer game on GKE: players reach Next.js frontend pods scaled by KEDA against a custom player-threshold metric API, with the API service and the Hocuspocus collaboration server split into separate single-container pods; kube-prometheus-stack scrapes all three for the metrics that drive scaling.

The teams and systems behind these numbers

  • Rebuilt platform access on GKE as a zero-trust WireGuard overlay: took every database off public IPs — three were exposed, the estate is four now, none reachable from outside — with per-environment CI identities and two human access tiers.
  • Closed all four public administrative paths on a healthcare AWS estate carrying SOC 2 Type 1 and HIPAA obligations: EKS API and nodes made private, both bastions' ingress emptied, verified by connection timeout rather than policy review.
  • Replaced two static IAM keys, one of them cluster-admin, with GitHub OIDC per-run identity and namespaced EKS access entries across seven repositories.
  • Built cross-region backup for the same estate and published the measured 40–50 minute copy lag as the recovery point, rather than the hourly target the design was scoped against.

Employment references

I'd confidently recommend Talha to any team looking for a reliable, autonomous DevOps or Platform Engineer.

Saad Abdullah

Saad Abdullah

Cloud, DevOps, & Solutions Architecture · Toptal

Direct Manager

I would trust Talha with an ambiguous production issue and expect him to return not just with a fix, but with a clear understanding of the root cause.

Abdullah Tarar

Abdullah Tarar

Cloud Infrastructure & DevOps Engineer

Senior Teammate

Stack

  • Kubernetes
  • GKE
  • Docker
  • Terraform
  • Pulumi
  • GitHub Actions
  • GitLab CI
  • AWS
  • Cloudflare
  • Datadog
  • Prometheus
  • Linux
  • Next.js
  • TypeScript
Reference architecture · source public

Built in public, so you can read every line.

Platform Engineering

AWS EKS Paved Road: GitOps Delivery with Zero Static Cloud Credentials

Designed and published a reference AWS EKS platform using Terraform and GitOps. Eliminated static cloud credentials using IRSA and automated secret delivery with External Secrets Operator, enabling fully declarative infrastructure and application delivery.

No users, no traffic — built to demonstrate the architecture.

AWS EKSTerraformArgoCDExternal Secrets OperatorAWS Secrets Manager

Consulting

I also take a small number of fixed-scope reviews for early-stage teams — a written read on what breaks first under load, ranked by blast radius. The sample report is public and ungated.

Hiring, or need a read on your infrastructure?

If you are hiring for production infrastructure, send the role — email is fastest, and the résumé is one click. If you are not hiring but your deploy path, CI/CD, or AI-built app needs a serious review, the consulting pages have the scope and the pricing.

Remote setup: EOR or B2B contractor — both are straightforward from Pakistan, and I can be onboarded either way. (Direct local employment is the one route that doesn't work from here.)

Or book a 30-minute call →

© 2026 TALHA IMTIAZ