Hoppa till innehållet
Marcus Kjellin, Devops Engineer/Plattform Engineer

9 år i yrketEgenföretagare

Marcus Kjellin

Devops Engineer/Plattform Engineer

  • Kvadrat Tech Stockholm

DevOps and Platform Engineer with 6+ years of building, configuring and automating cloud platforms end to end. Works across AWS, GCP and Azure with Terraform, CI/CD, Git and Kubernetes, with security built in from the start — and enjoys setting up the PoC that proves a solution before it scales.

  • IAM
  • Python
  • Telemetry
  • AWS
  • Azure
  • Cloud
  • Automated
  • Docker
  • FortiGate
  • Bash
  • Git
  • Go
  • Agile
  • Automation
  • CI/CD
  • Security
  • Advise
  • Cisco Meraki
  • Banking
  • Audit Logging
  • AzureAD
  • Continuous monitoring

Uppdrag

  • ICA Gruppen

    jan. 2026 – nu

    Platform Engineer

    ICA Gruppen is a parent company to ICA Banken, ICA Fastigheter, Apoteket Hjärtat and has since been merged with ICA Sverige as well, which is the company handling all the stores around the country.

    Marcus worked within the Data & Analytics department, supporting multiple business units. He was tasked with helping migrate on-prem implementations to Google Cloud using Infrastructure as Code, ensuring secure, compliant, and scalable foundations.

    Maintain and evolve a secure, stable GCP platform with strong governance and change management.
    Implement GCP infrastructure via Terraform.
    Set up and maintain CI/CD pipelines with strong test suites and quality gates.
    Enforce platform security baselines and guardrails.
    Lead and execute change management processes.
    Collaborate with security stakeholders to ensure cloud environments meet bankinggrade reliability and compliance.
    Set up and maintained Google Kubernetes Engine (GKE) for hosting Gitlab runners.
    Set up and maintained Artifact Registry with Container Scanning.
    Verified Security Vulnerabilities in Security Command Center and took action if deemed a risk.

    Result: Delivered a standardized, hardened GCP platform with reproducible IaC workflows, improved deployment reliability, and compliant guardrails, enabling multiple business units to migrate from on-prem to cloud with reduced operational risk and faster delivery.

    Method/Tech: GCP: IAM, Buckets, BigQuery, BigTable, Firestore, Dataflow, GKE,
    Cloud Build, Cloud Functions, Dataproc, Pub/Sub, Workflows, Scheduler, VPC, Compute Engine, App Engine, Artifact Registry, Container Scanning (Artifact analysis and vulnerability scanning), VPC Service Controls (VPC SC), Security Command Center, Secret Manager, Key Management, Certificate Manager.
    Terraform, Gitlab Workflows, Github Actions, CI/CD, Networking, Kubernetes, Observability, Git, Agile.

    Visa mer
    • Linux
    • Git
    • AWS
    • Azure
    • Bash
    • Docker
    • DevOps
    • PowerShell
    • Go
    • Puppet
    • Kubernetes
    • Python
    • Terraform
    • Windows Server Administration
    • GCP
    • DevSecOps
    • GitHub
    • Github Copilot CLI
    • GitHub Copilot / Claude Code
    • CI/CD
    • Sonatype Nexus
    • GitHub Enterprise
    • GitHub Actions
    • GitHub Copilot
    • GitHub Advanced Security
    • Grafana
    • AKS (Azure Kubernetes Service)
    • Aikido
  • Modoyo AB

    jan. 2025 – jan. 2026

    DevOps Engineer

    Modoyo is a small gaming company. Marcus engineered the end-to-end AWS platform for an online game, focusing on secure, scalable, and automated foundations. He combined platform engineering with security operations to harden services, standardize deployments, and enable fast, safe delivery for backend and game server workloads.

    Design, secure, and operate AWS infrastructure with strong guardrails and IaC/CI/CD; manage game server operations and developer workflows.

    Implement AWS IaC with Terraform, enforcing least-privilege IAM, KMS encryption, VPC segmentation, tagging, and policy controls.
    Build CI/CD with GitHub Actions/CodeBuild/CodePipeline, adding quality gates, image scanning (ECR), and automated validations.
    Manage ASG-based game servers with CloudWatch metrics and alarms; instrument EKS services with Prometheus and dashboards in Grafana.
    Operate and maintain ASG-based game servers in AWS, with metrics and alarms in CloudWatch.
    Set up and manage EKS for backend services, with observability being Prometheus scraping with Grafana dashboards.
    Provision and harden EKS for backend services (matchmaking, scaling, telemetry), applying RBAC, network policies, secrets management, and audit logging. - Automate Docker ArgoCD deployments so backend repos continuously deliver to EKS.
    Manage secrets and configuration with Secrets Manager and Parameter Store; standardize operations via SSM.
    Integrate identity and access for player/admin flows with Cognito; improve resilience with Route 53, CloudFront, and Global Accelerator.

    Result: Delivered a hardened, reproducible AWS platform with built-in security controls and automated deployments. Release friction decreased, scalability and reliability improved for game servers and backend services, and operational risk was reduced through encryption, least-privilege access, image scanning, and continuous monitoring.

    Method/Tech: AWS: IAM, EC2, S3, EKS, ECS, ASG, CodeBuild, CodePipeline, SSM, CloudWatch, Cognito, Route 53, ECR, KMS, IAM, Lambda, Secrets Manager, Parameter Store, Global Accelerator, CloudFront, VPC. GCP: IAM, OAuth/Branding
    Terraform, Python, Golang, Git, Github Actions, ArgoCD, Docker, Kubernetes, Karpenter, Grafana, Prometheus, Linux/Windows.

    Visa mer
    • Linux
    • Git
    • EC2
    • AWS
    • CI/CD
    • Azure
    • VPC
    • Nginx
    • Docker
    • DevOps
    • S3
    • OAuth
    • Go
    • Encryption
    • IAM
    • RBAC
    • CloudWatch
    • Grafana
    • Kubernetes
    • Python
    • Terraform
    • CloudFront
    • Prometheus
    • Telemetry
    • GitHub Actions
    • ArgoCD
    • AzureAD
    • AWS Infrastructure
    • IAM (Identity and Access Management)
    • CI/CD with GitHub Actions
  • Playground Tech AB

    jan. 2023 – dec. 2024

    Cloud Engineer

    Playground is a consultant company focusing on Cloud excellence. They are partnered with AWS and are working towards partnering with Google and Microsoft. Marcus came in as a GCP expert.

    Deliver cloud architecture, automation, and platform enablement tailored to customer contexts.
    Design IaC patterns and modules.
    Implement CI/CD and DevOps workflows.
    Advise on security, networking, and cost optimization.
    Build automation tooling and scripts.

    Method/Tech: AWS/GCP/Azure, Terraform, Python, Golang, Bash, PowerShell, Git, Kubernetes, Docker.

    Visa mer
    • Security
    • Workflows
    • AWS
    • CI/CD
    • DevOps
    • Cloud Architecture
    • Azure
    • Docker
    • Kubernetes
    • Python
    • Terraform
    • Google Cloud Platform (GCP)
  • Fall Damage Studio AB

    jan. 2021 – dec. 2023

    Senior IT Administrator/DevOps Engineer

    Fall Damage Studio was a mid-to-small gaming company. Marcus operated across the full stack—cloud, on-prem servers, endpoints, and network/security appliances—to deliver a resilient, secure, and well-governed IT environment for a game studio. He combined platform engineering with security operations to standardize infrastructure, harden services, and enable faster, safer delivery.

    Secure, automate, and operate network, server, and cloud platforms with strong guardrails; build internal tooling to reduce toil and improve developer productivity.
    Design and maintain network/server infrastructure with zero-trust principles and least-privilege access.
    Implement IaC for GCP/AWS and enforce security baselines, secrets management, and policy controls.
    Build CI/CD workflows with quality gates, and automated compliance checks. - Develop internal apps and automation in Golang/Python to streamline operations and reduce manual work.
    Operate GKE for internal services (including Kafka), with hardened images, RBAC, and audit logging.
    Monitor and remediate vulnerabilities; integrate telemetry and alerting for proactive incident response.
    Manage firewalls and network security (Fortigate, HP Aruba, Ruckus) with segmentation and secure configurations.

    Result: Delivered a hardened, automated platform with reproducible deployments and built-in security controls, reducing operational risk and incident volume while accelerating delivery. Standardized IaC and CI/CD practices improved reliability, while continuous monitoring and vulnerability remediation strengthened overall security posture.

    Method/Tech: GCP: IAM, BigQuery, Firestore, GKE, Cloud Build, Cloud Functions,
    Pub/Sub, Workflows, Scheduler, VPC, Compute Engine, App Engine, Artifact Registry, Container Scanning (Artifact analysis and vulnerability scanning), Security Command Center, Secret Manager, Key Management, Certificate Manager.
    AWS: IAM, Lambda, VPC.
    Terraform, Python, Golang, Kubernetes, PowerShell, Bash, Networking, Fortigate, HP Aruba, Ruckus, Linux/Windows, Git, CI/CD.

    Visa mer
    • Linux
    • Agile
    • Git
    • Cloud
    • AWS
    • CI/CD
    • Azure
    • VPC
    • Bash
    • DevOps
    • PowerShell
    • Network Security
    • Go
    • Automation
    • Windows
    • IAM
    • RBAC
    • Lambda
    • Kafka
    • Kubernetes
    • Key Management
    • Incident Response
    • Python
    • Terraform
    • Telemetry
    • Firestore
    • BigQuery
    • App Engine
    • Pub/Sub
    • AzureAD
    • Audit Logging
    • Continuous monitoring
    • FortiGate
    • CI/CD Workflows
    • Vulnerability Management
    • Cloud Security
    • Google Cloud Platform (GCP)
    • CI/CD Pipelines
  • Acne Studios AB

    jan. 2019 – jan. 2021

    IT Operations Specialist

    Acne Studios, a high-fashion brand based in Sweden. They require global networks
    and cloud resources able to handle big workloads of data regarding new customers and purchases. Marcus supported operations across on-prem and Azure to deliver secure, reliable, and scalable hybrid cloud integrations. He focused on standardizing platforms, hardening services, and automating high-volume operational workflows.

    Design, secure, and maintain hybrid cloud infrastructure with strong guardrails; automate common procedures to improve reliability and throughput.

    Script automation with PowerShell to reduce manual toil and enforce consistency.
    Operate and troubleshoot network and server infrastructure on-prem and in Azure.
    Design and implement Azure resources with policy, RBAC, and secure baselines.
    Resolve escalated incidents from Service Desk and drive root-cause remediation.
    Design and implement new services and infrastructure projects.
    Manage global networks (Cisco Meraki, HP switches, Fortigate) with segmentation and secure configurations.
    Maintain AD/Exchange and Microsoft SQL with proper access controls and backup/restore practices.
    Integrate CI/CD (Git/GitHub Actions) with quality gates for infrastructure changes.

    Result: Delivered a hardened, automated hybrid platform with standardized processes and security controls, reducing incident volume and deployment risk while improving change velocity and global network reliability.

    Method/Tech: Azure: IAM, Service Bus, Azure Functions, Logic Apps, Blob Storage, Azure Monitor, Azure Key Vault, Azure VM, Azure Active Directory, Azure Blueprints, Azure Resource Manager (ARM), ARM Template, VPC.
    PowerShell, Windows Server, Git, Github Actions, Networking, Fortigate, HP Switches, AD/Exchange, Microsoft SQL, VMWare, Cisco Meraki, Incident Management, SCOM, Change/Project Delivery.

    Visa mer
    • VMware
    • Agile
    • Windows Server
    • Git
    • CI/CD
    • Azure
    • VPC
    • Switches
    • PowerShell
    • SCOM
    • Blueprints
    • IAM
    • RBAC
    • Azure VM
    • Azure Active Directory
    • Project Delivery
    • Cisco Meraki
    • Azure Resource Manager
    • Hybrid Cloud
    • Azure Monitor
    • Azure Key Vault
    • Azure Functions
    • Microsoft SQL
    • GitHub Actions
    • Network Reliability
    • Security controls
    • Hybrid Cloud Infrastructure
    • FortiGate
  • Star Stable Entertainment AB

    jan. 2019 – jan. 2019

    Internal IT System Administrator

    Marcus operated across hybrid cloud and on-prem environments to deliver secure, reliable connectivity and platform services. He combined platform engineering with security operations to standardize infrastructure, harden core services, and automate routine workflows.

    Maintain, upgrade, and secure internal systems and platforms with strong guardrails, least-privilege access, and automated controls.

    Operate and harden network/server infrastructure with segmentation, RBAC, MFA, and secure configurations.
    Maintain core services (email, wiki, availability systems) with backup/restore, patching, and access governance.
    Provide user support and manage IT budget/procurement; drive root-cause remediation for escalations.
    Coordinate with providers/partners to align on security baselines and incident processes.
    Automate operations with PowerShell/Python to enforce consistency and reduce manual toil.
    Set up Azure/AWS integrations with policy, identity, and secrets management; implement monitoring and alerting.

    Result:
    Hardened hybrid platform with standardized security controls and automated operations
    Reduced incident volume and change risk through guardrails, least-privilege access, and policy enforcement.
    Improved service reliability and support throughput via automation and structured monitoring/alerting.
    Established consistent identity, secrets, and configuration management across Azure/AWS and on-prem.

    Method/Tech: Windows Server, Ubiquiti, Networking, PowerShell, Python, Git, Active Directory/Exchange, Azure (IAM/Policy), AWS (IAM/Secrets), RBAC, MFA, Backup/Restore, Monitoring/Alerting.

    Visa mer
    • Windows Server
    • Git
    • AWS
    • Azure
    • Active Directory
    • Budget
    • PowerShell
    • Automation
    • IAM
    • RBAC
    • Python
    • Hybrid Cloud
    • Security Operations
    • AzureAD
    • Platform Engineer
    • Network Security
    • AWS IAM
    • Azure IAM
  • Lernia

    jan. 2018 – jan. 2019

    Service Desk

    Lernia is one of Sweden's leading partners in staffing, recruitment, education, and
    workforce development.
    Enterprise support spanning 1st–3rd line with infra administration responsibilities.

    Support users and administer core enterprise systems.

    Handle support via phone, mail, and ticketing.
    Administer Exchange and Active Directory.
    Perform server administration and app support.
    Automate repetitive through Powershell.

    Result: Improved support throughput and service reliability through automation and standardized administration, reducing resolution times and operational toil.

    Method/Tech: Exchange, Active Directory, Windows Server, Ticketing, PowerShell, Azure.

    Visa mer
    • Windows Server
    • Azure
    • Service Desk
    • Active Directory
    • PowerShell
    • Recruitment
    • Administration
    • Automation
    • Automated
    • Workforce Development
    • Server administration
    • Education
    • AzureAD
    • Throughput
    • Application Support
    • User Support
    • Exchange
    • Ticketing Systems
    • 1st–3rd Line Support
  • Regeringskansliet

    jan. 2017 – jan. 2018

    IT Support

    Regeringskansliet is a government agency supporting the government in governing the country and and implementing its policies. Marcus had the task to provide IT support to government employees, including embassies.

    Deliver user support across two distinct environments, following formal procedures and controlled operations.

    Split duties between phone support and ticket handling.
    Troubleshoot and resolve environment-specific issues with remote support tools. - Follow defined processes and escalation paths to maintain compliance and auditability.

    Result: Consistently met service levels and compliance requirements by enforcing process discipline, reducing resolution times and ensuring reliable support across both environments.

    Method/Tech: Windows, Ticketing, Remote Support, Process-driven operations.

    Visa mer
    • Phone Support
    • IT support
    • Windows
    • User Support
    • Remote Support
    • Compliance requirements

Kompetens · nivå och år

Tekniker

  • IAM
  • Python
  • Telemetry
  • Backend
  • Backend services
  • Blueprints
  • Build Automation
  • Cloud Architecture
  • Cloud Engineer
  • Cloud Functions
  • Encryption
  • Hybrid Cloud
  • Load Balancer
  • Metrics
  • Microsoft SQL
  • Network Security
  • OAuth
  • Scalability
  • Switches
  • Vulnerability Scanning
  • Vulnerabilities

Plattformar

  • AWS
  • Azure
  • Cloud
  • GCP
  • GitHub Actions
  • GitLab
  • Kubernetes
  • Linux
  • VPC
  • Windows
  • Azure Functions
  • EC2
  • Google Cloud
  • Kafka
  • Servers
  • Windows Server
  • IT System
  • Version control

Produkter

  • Automated
  • Docker
  • FortiGate
  • Azure Monitor
  • Azure Resource Manager
  • Azure VM
  • CloudFront
  • CloudWatch
  • Grafana
  • Lambda
  • Nginx
  • Prometheus
  • S3
  • VMware
  • Active Directory
  • Dataflow
  • Azure Key Vault
  • Windows Server Administration

Verktyg

  • Bash
  • Git
  • Go
  • Infrastructure
  • PowerShell
  • Terraform
  • ArgoCD
  • Azure Active Directory
  • BigQuery
  • CRM system
  • Dashboards
  • Network Policies
  • Route 53
  • SCOM
  • Remote Support
  • Puppet
  • Tooling

Metoder och processer

  • Agile
  • Automation
  • CI/CD
  • DevOps
  • Operational Risk
  • RBAC
  • Workflows
  • Branding
  • Cost Optimization
  • Governance
  • Incident Response
  • IT Operations
  • Key Management
  • Network Reliability
  • Project Delivery
  • Standardize
  • Vulnerability Remediation
  • Access governance
  • Analytics
  • Change Management
  • Compliance requirements
  • Configuration Management
  • Education
  • Risk
  • Workforce Development
  • Operational Efficiency

Verksamhetsområden

  • Security
  • Advise
  • Cisco Meraki
  • Incident Management
  • Service Desk
  • Administration
  • Budget
  • IT support
  • Phone Support
  • Procurement
  • Recruitment
  • User Support

Branscher

  • Banking

Övrigt

  • Audit Logging
  • AzureAD
  • Continuous monitoring
  • Security controls
  • Security Operations
  • Access controls
  • App Engine
  • CI/CD Workflows
  • Compute Engine
  • Firestore
  • Hybrid Cloud Infrastructure
  • Online game
  • Playground
  • Pub/Sub
  • Reproducible
  • Tagging
  • Throughput
  • BigTable
  • Policy Enforcement
  • Google Cloud Certified Professional Cloud Architect

Den som känner Marcus

Theodor Wahlgren

Theodor är Marcus kontaktperson på Kvadrat.