whoami

Principal Cloud Engineer & Lead Cloud Native Developer

I build cloud platforms that stay boring under pressure.

I turn complex cloud estates into secure, observable platforms that developers can use with confidence. My work spans hands-on engineering, architecture, technical leadership and the operating model around the platform.

principal-engineer.yaml
Marcin Cuber
available to connect

Marcin Cuber

London based · Engineering at enterprise scale

focus:
cloud_platforms
runtime:
kubernetes
provisioner:
terraform
delivery:
[gitops, ci/cd]
mode:
hands_on + strategic
github.com/marcincuber
10+
years in engineering

from software delivery to principal-level cloud leadership

300+
stars on the EKS project

a maintained, released Terraform implementation

4.7K
Medium followers

practical writing on AWS, Kubernetes and Terraform

394K
developers reached

through answers shared on Stack Overflow

Engineering approach

Platforms are socio-technical systems.

Good infrastructure is only half the job. I align architecture, developer experience and operations so that the whole system remains understandable as it scales.

01

Platform as a product

Start with the developer journey. Build paved roads, clear contracts and self-service workflows that teams choose to use.

02

Secure by construction

Encode least privilege, policy and supply-chain controls into the platform so the safe path is also the fast path.

03

Operate what you design

Make reliability, telemetry, cost and recovery first-class architecture decisions—not work deferred until production.

Selected work / open source

Working systems, not logo walls.

Public implementations that show how I think about lifecycle, operability and the trade-offs behind cloud-native platforms.

Elastic CI infrastructure public

Kubernetes GitLab runners

marcincuber/kubernetes-gitlab-runner

Configuration for running scalable GitLab CI workloads on Kubernetes, isolating jobs while letting the runner fleet follow demand.

  • GitLab CI
  • Kubernetes
  • Autoscaling
Cloud-native application lab public

mTLS Go microservices

marcincuber/k3d-ping-pong-go-apps-with-mtls

Small Go services running on k3d with mutual TLS—a compact demonstration of service identity, encrypted traffic and local platform testing.

  • Go
  • mTLS
  • k3d
  • Containers
Delivery automation public

GitHub Actions library

marcincuber/gha

A collection of reusable GitHub Actions workflows and delivery patterns for automating repeatable engineering tasks.

  • GitHub Actions
  • CI/CD
  • Automation

Browse all 50+ public repositories

Capability map

From account boundary to running workload.

I work across the platform stack and the organisational interfaces around it—deep enough to debug a pod, broad enough to set the direction.

01

Foundations

Cloud architecture

Multi-account AWS estates, landing zones, network boundaries and resilient multi-region design.

  • AWS Organizations & Control Tower
  • VPC, IAM, Route 53 & CloudFront
  • ECS, Lambda, RDS & event services
02

Runtime

Kubernetes platforms

Production EKS architecture with controlled tenancy, capacity, upgrades and a coherent add-on lifecycle.

  • EKS, Karpenter & KEDA
  • Helm, operators & service mesh
  • Pod security & admission policy
03

Delivery

Infrastructure & GitOps

Versioned, reviewable infrastructure and application delivery with small blast radii and reliable promotion.

  • Terraform module engineering
  • Bash automation
  • Argo CD, Flux CD & progressive delivery
  • GitHub Actions & GitLab CI
04

Assurance

DevSecOps

Identity-first security, automated guardrails and software supply-chain controls embedded into delivery.

  • OIDC, ABAC, SCPs & permission boundaries
  • Vault, Secrets Manager & External Secrets
  • SBOM, signing, Trivy & policy as code
05

Operations

SRE & observability

Telemetry and reliability practices that turn production behaviour into actionable engineering feedback.

  • Prometheus, Grafana & New Relic
  • SLIs, SLOs & error budgets
  • OpenSearch, tracing & incident learning
06

Leadership

Technical direction

Architecture strategy translated into standards, mentoring, pragmatic roadmaps and hands-on delivery.

  • Design reviews & decision records
  • Team growth & engineering standards
  • FinOps, risk and stakeholder alignment

Selected outcomes

Engineering measured in change.

Representative outcomes delivered across platform engagements.

99.99%

availability objectives

Resilient EKS platform patterns designed around fault isolation, observability and controlled change.

70%+

faster developer delivery

Self-service platform workflows that reduce hand-offs and shorten the path from change to production.

40%+

cloud cost reduction

FinOps guardrails, demand-aware scaling and architecture changes that treat cost as a system signal.

Technical writing

Field notes from operating cloud-native systems.

Runbooks, upgrade journeys and explanations shaped by the failure modes engineers meet in real environments.

Read all articles on Medium

Career journey

Software foundations. Platform depth. Technical leadership.

A progression from product software into the design and operation of enterprise cloud platforms.

Open the full CV

2026 — present

Lead Cloud Native Developer

Current

Capgemini

Combining hands-on engineering and technical leadership to build resilient, modern cloud-native systems for large-scale client environments.

2022 — 2026

Principal Cloud Engineer · DevOps Technical Lead

Dare

Led cloud-native engineering and platform direction, with an emphasis on secure AWS foundations, developer experience and high-quality operational practices.

Earlier chapter

DevOps Technical Lead

Limejump

Grew platform capability and helped establish enterprise AWS organisation and governance patterns.

Earlier chapter

Lead DevOps Engineer

uMotif

Led cloud infrastructure across multiple regions for a product operating in a regulated environment.

Earlier chapter

Cloud DevOps Engineer

News UK

Architected the organisation’s Amazon EKS environment and helped move production workloads from self-managed Kubernetes to a managed platform.

Career foundation

Software Engineer

The Times

Built software for a high-traffic digital news product before moving deeper into infrastructure and platform engineering.

Education & credentials

Deep foundations, continuous learning.

Formal study

Education

02entries

2012 — 2016

MEng (Master of Engineering), Computer Science

University College London

Four-year integrated master’s degree, including research in security, data visualisation and transport-network optimisation.

Before UCL

A Levels & BTEC National Diploma

South Cheshire College

IT, Mathematics, Further Mathematics and an Extended Project Qualification.

Professional development

Certifications

10credentials
  • AWS Certified CloudOps Engineer— AssociateAmazon Web Services · Cloud
  • AWS Certified Solutions Architect— AssociateAmazon Web Services · Cloud
  • AWS Certified AI PractitionerAmazon Web Services · Cloud
  • HashiCorp Certified: Terraform AssociateHashiCorp · Infrastructure as Code
  • GitHub AdministrationGitHub · Developer platform
  • GitHub FoundationsGitHub · Developer platform
  • GitLab Certified AssociateGitLab · Developer platform
  • Prefect Associate CertificationPrefect · Data orchestration
  • Akamai DevOps ProfessionalAkamai · Edge & delivery
  • Akamai Bot Manager AdvancedAkamai · Edge & delivery

The site is a system too

Python in the build path. Zero JavaScript in the critical path.

This portfolio is generated from validated structured content by a typed, dependency-free Python build. GitHub Actions tests it, fingerprints the assets and publishes only the immutable static output.

Inspect the source
  1. 01profile.jsonsingle content source
  2. 02Pythonvalidate + render
  3. 03CI checkstest + inspect links
  4. 04Pagesstatic deploy

Let’s compare notes

Architecture challenge, platform problem or open-source idea?

The best conversations usually begin with a system diagram and one stubborn constraint.

Connect on LinkedIn