Dominik Michalak®
open to work CV 

dominikmichalak.pl — portfolio · rev. 2026.06 · Wrocław, PL

Dominik Michalak

DevOps / Cloud Engineer AWS · Terraform · Observability

I build and run cloud infrastructure that stays up — and the monitoring that proves it. Five years in production: AWS environments from VPC to go-live, security reviews, and automation that removes toil.

internet route 53 dns cloudfront ×3 edge · geo allowlist s3 spa origin vpc · 10.x.0.0/20 · 3 az frontend subnets alb tls · ip allowlist backend subnets · ecs cluster ecs · fargate tasks ×3–9 · autoscaled ecr container images secrets manager runtime config kms encryption keys db subnets rds postgres multi-az · kms elasticache redis + replica opensearch clustered cloudwatch alarms → on-call
fig. 0 — production architecture I run, anonymized
01

Profile

whoami, in more than one line

I'm Dominik — a DevOps engineer based in Wrocław. For the last five years I've been the person who builds the platform and then answers for it: AWS environments from networking to go-live, infrastructure as code in Terraform, configuration in Ansible, and a monitoring wall I genuinely enjoy staring at.

My particular obsession is observability and security. I co-built — and now own — a company-wide stack of Grafana, Zabbix, Datadog and Wazuh, and I lead an ongoing AWS security review. If something breaks, I want a graph that said so first.

Day to day that means reviewing infrastructure changes against Terraform best practices, building internal tools that make developers' AWS work less painful, and keeping critical applications fast, reliable and quiet at 3 a.m.

base
Wrocław, Poland
mode
remote / hybrid
focus
AWS · IaC · observability · security
Dominik Michalak
fig. 1 — the engineer, off duty
02

Capabilities

bill of materials
CAP-01

Cloud & infrastructure as code

AWS — EC2 · VPC · S3 · RDS · ECS · ECR · Lambda · CloudFront · ELB / Terraform / Docker

CAP-02

Observability & security

Grafana / Datadog / Zabbix / Wazuh / Prometheus / CloudWatch

CAP-03

Automation & scripting

Ansible / Python / Bash / Git · GitHub

CAP-04

Platform & practice

Linux — Ubuntu, Debian, RHEL-family / networking / IaC review / Jira · Confluence

03

Operations log

reverse-chronological, production only
Jul 2023 — present 3 yrs

DevOps Engineer current

  • Co-developed and now own the company's Wazuh, Grafana, Datadog & Zabbix stack, focused on security monitoring and compliance.
  • Lead an ongoing company-wide AWS security review.
  • Build internal tools that streamline developers' AWS-related work.
  • Orchestrate AWS production environments end-to-end: setup, deployment, demos and go-live events.
  • Review infrastructure changes, enforcing Terraform best practices.

stack — AWS · Terraform · Datadog · Grafana · Wazuh · Zabbix · GitHub

Jan 2023 — Jul 2023 7 mos

System Administrator

  • Built and managed AWS infrastructure: EC2, VPC, S3, RDS, ELB, ECS, ECR, Lambda, CloudFront.
  • Authored security-hardening playbooks for AWS and EC2 environments.
  • Implemented infrastructure as code with Terraform.
  • Administered Zabbix, Grafana & Datadog — dashboards, alarms, performance analysis.
  • Automated admin and deployment tasks with Python & Bash.

stack — AWS · Terraform · Ansible · Python · Bash · Zabbix · ECS

Aug 2021 — Jan 2023 1 yr 6 mos

Junior System Administrator

  • Administered Jira and Confluence; resolved access and permission issues.
  • Supported IT Operations with production server updates.
  • Provisioned development and testing environments in AWS.
  • Wrote Ansible playbooks automating DNS, monitoring and host/service upgrades.

stack — Ansible · AWS · Jira · Confluence · Linux

04

Case files

selected work, declassified
FILE-001

contents pending declassification

stack — ▮▮▮▮ · ▮▮▮ · ▮▮▮▮▮

FILE-002

contents pending declassification

stack — ▮▮▮ · ▮▮▮▮▮ · ▮▮▮

FILE-003

contents pending declassification

stack — ▮▮▮▮▮ · ▮▮▮ · ▮▮▮▮

05

Contact

usually replies within a day