☁️ AWS Solutions Architect
I designscalable cloud systems
Hi! I'm Moritz — a Cloud Consultant focused on AWS solutions for public and private sector clients. If you're looking for support with your project or would like to exchange ideas on cloud topics, feel free to get in touch.

Pragmatic, secure and cost-aware cloud architectures — designed to ship fast and scale safely.
My Portfolio
Hands-on cloud consulting with a strong focus on reliability, security and cost efficiency.
Cloud Architecture
Designing scalable AWS architectures based on best practices and proven patterns.
Migration & Modernization
Safely migrating workloads to AWS and modernizing legacy systems sustainably.
DevOps & Automation
CI/CD, Infrastructure as Code (Terraform/CDK) and improving developer experience.
Consulting
Technical consulting for complex challenges and sound architectural decision-making.
Automation
Optimizing infrastructure, deployment and operational processes through automation.
Architecture Design
Designing platform and system architectures based on requirements, scalability and maintainability.
Container Migration
Migrating monolithic applications into containerized and cloud-native architectures.
Day-2 Operations
Monitoring, logging and operational strategies for stable and maintainable platforms.
Security
Security concepts for identities, networks, platforms and data in cloud environments.
Projects
A selection of projects — delivered reliably, securely and cost-aware following best practices.
ETL Pipeline with AWS Glue & PostgreSQL
Banking & Insurance · 2025
Implemented a scalable ETL pipeline using AWS Glue and PostgreSQL to improve data processing and business intelligence.
Designed and implemented a modern, cloud-based data architecture to process enterprise-wide data efficiently and enable better decision-making based on consolidated information. The core component is a scalable ETL pipeline built on AWS Glue, extracting raw data from a central Amazon S3 data lake, transforming it, and loading it into a structured PostgreSQL database. Database access is integrated with Active Directory to ensure secure, role-based access control. Qlik is used for analytics and reporting, providing user-friendly dashboards and in-depth insights. The implementation also included establishing secure network connectivity between data sources and AWS, as well as configuring the complete ETL workflow in AWS Glue. The infrastructure is provisioned via Infrastructure as Code (IaC) using Terraform, following AWS best practices to ensure a repeatable, scalable, and maintainable environment. Finally, involved teams were onboarded through a hands-on workshop to ensure a smooth transition into usage and operations. This architecture lays the foundation for an efficient, future-proof data processing and BI solution that can flexibly scale with growing requirements. Delivery was carried out in close collaboration with an experienced cloud service provider to ensure professional integration into the existing system landscape.
Security Audit for AWS CloudFront & WAF
Utilities / Energy Sector · 2025
Performed a comprehensive security audit of CloudFront and AWS WAF to strengthen the security architecture and improve caching behavior.
In a security-critical engagement, a comprehensive audit of existing AWS services was conducted, with a strong focus on Amazon CloudFront and AWS Web Application Firewall (WAF). The goal was to assess the overall cloud setup and identify potential weaknesses in configuration and architecture early. A key part of the work was a detailed review of CloudFront configuration, especially caching behavior, policies, and security integrations. In parallel, AWS WAF rules and protections were evaluated for effectiveness against common attack vectors such as SQL injection, cross-site scripting (XSS), and other web vulnerabilities. Additional focus areas included access controls as well as logging and monitoring strategies to ensure early detection and traceability of potential security incidents. Findings were documented in a structured final report including concrete, prioritized recommendations and aligned with internal security stakeholders. By implementing the recommended measures, the platform’s security posture and resilience were improved sustainably, creating a robust foundation against current and future threat scenarios.
Scalable n8n Platform on AWS with EKS & Fargate
Energy Provider · 2025
Built a scalable, security-focused n8n platform on AWS to automate business-critical processes.
Designed and implemented a scalable, highly available cloud platform for the automation solution n8n on AWS in an agile Scrum environment. The goal was a future-proof architecture provisioned fully via Infrastructure as Code, supporting business-critical workflows reliably and maintainably. The platform was deployed on Amazon EKS using Helm charts, focusing on scalability, multi-tenancy, and a clear separation between infrastructure and application layers. To ensure performance and high availability, components such as load balancing, auto scaling, an in-memory Valkey cluster, and persistent EFS storage for workflows were integrated. An existing AWS RDS for PostgreSQL database containing business-critical data was securely connected. Sensitive configuration data is managed centrally using AWS Secrets Manager, with access strictly limited to service-bound IAM roles following the least-privilege principle. In addition to the Kubernetes platform, a separate serverless ECS cluster on AWS Fargate was created for an internal application. Selected n8n workflows interact with this app to deliver aggregated and processed data automatically. In parallel, an AWS Landing Zone initiative was started to establish a policy-driven, scalable multi-account structure. Existing workloads are being migrated step-by-step into the new AWS organization. Multiple isolated staging clusters and dedicated sandbox environments for development, testing, and proof-of-concepts were also set up. Finally, modern CI/CD pipelines are being introduced to automate builds, tests, container creation, Helm deployments, and rollbacks—accelerating release cycles and improving operational quality.
On-Prem OpenShift Platform with IBM Backup
Healthcare · 2024
Contributed to an on-prem OpenShift platform for secure management and distribution of medical research data.
As part of a project delivering an on-prem OpenShift container platform for managing and distributing medical health data to connected research institutes, I worked within the Kubernetes team and took a key role in backup and platform automation. My main responsibility was implementing and deploying an IBM-based backup solution tailored to specific applications running in the Kubernetes clusters, meeting requirements for consistency and recoverability. A core objective was fully automated provisioning of all required components—especially when setting up new clusters. To achieve this, I implemented an App-of-Apps pattern with ArgoCD, enabling structured and chronologically coordinated installation of the IBM marketplace, operator configuration, and application deployment into dedicated namespaces. To ensure high security standards, dedicated service accounts were used for cross-cluster actions. These followed the least-privilege principle and were granted only the minimum permissions required for the specific resources. This resulted in a robust, secure, and maintainable backup integration that could be rolled out reproducibly to new clusters and significantly improved platform operational safety.
Cloud Architecture & CI/CD with GitHub Actions
Industrial Sector · 2024
Designed a scalable cloud architecture and modern CI/CD pipelines to accelerate application delivery.
In an agile Scrum environment, a scalable cloud architecture was designed and implemented to modernize and accelerate the customer’s application delivery. A central component was building CI/CD pipelines using GitHub Actions. Dedicated pipelines were developed for individual endpoints (WordPress, application frontend, and backend) to automate build, test, and deployment processes efficiently. Sensitive configuration and secrets were encrypted using SOPS and protected with AWS-managed keys to ensure secure handling of secrets within the pipelines. After analyzing an existing AWS EKS setup that caused operational challenges, the deployment was migrated to AWS ECS using the serverless capacity provider Fargate—improving stability and reducing operational overhead. Secure and performant connectivity to existing databases was established. In addition, targeted code changes were implemented, including integrating nginx as a reverse proxy to optimize the application architecture. The entire infrastructure was built as code using Terraform and Terragrunt, enabling efficient multi-environment management, reducing redundancy, and improving maintainability and reproducibility.
Cloud Architecture & CI/CD with Bitbucket and Self-Hosted Runners
Customer Service · 2023
Designed a scalable cloud architecture and built a Bitbucket CI/CD pipeline to modernize application development.
Designed and implemented a scalable cloud architecture in an agile Scrum setup. In parallel, a CI/CD pipeline was built using Bitbucket with self-hosted runners running on AWS to modernize and accelerate the customer’s development workflows. The existing monolithic application was split into separate frontend and backend containers, enabling higher flexibility, improved scalability, and better resource efficiency. A further focus was secure handling of sensitive configuration. Secret retrieval was modernized and is now performed programmatically via AWS Secrets Manager. Sensitive data is stored in a separate AWS account and accessed strictly via service-bound IAM roles configured according to the least-privilege principle. Finally, the pipeline was configured and tested end-to-end. In close collaboration with the customer, a new branching and deployment concept was introduced to better structure development and release processes and ensure long-term maintainability.
Career path
Here’s my journey so far — from intern to Cloud Solution Architect.
Cloud Solution Architect
Bechtle AG · Bonn
Consulting public and private sector clients in complex cloud projects. Designing and implementing scalable, secure, and resilient AWS architectures in close collaboration with customers and partners. Working in cross-company, interdisciplinary teams to deliver cloud initiatives successfully. Technical project leadership and presentation of results in hackathons and internal events.
Junior Cloud Solution Architect
Bechtle AG · Bonn
Designed and delivered container platforms with AWS ECS, EKS, and Red Hat OpenShift. Built CI/CD pipelines, implemented IaC with Terraform, and supported public & private sector clients. Consulted on AWS architectures, delivered scalable and secure platforms, produced TCO analyses, and consistently applied AWS best practices.
Cloud Consultant (Internship)
Pexon Consulting GmbH · Jena
Built highly available web applications using Docker, Kubernetes, Helm, Prometheus, and Grafana. Provisioned infrastructure with Terraform and implemented CI/CD pipelines.
E-Commerce Manager (Working Student)
NewWebTec GmbH · Jena
Implemented SEO initiatives, supported social media marketing, and coordinated directly with clients. Built a strong understanding of customer needs, digital products, and business impact.
Operations & E-Commerce (Intern → Working Student)
diva-e Digital Value Excellence GmbH · Jena
Started in operations and e-commerce consulting. Supported platform operations, contributed to client projects, and gained hands-on experience in digital commerce environments.
About me
Hi, I'm Moritz — a cloud enthusiast with a clear focus on AWS and modern cloud architectures.
My main focus is DevSecOps and building resilient, secure, and scalable systems. What excites me most is the intersection of thoughtful architecture, intelligent automation, and clean engineering — that's where real quality emerges for me.
Beyond classic cloud topics, I'm also interested in related areas such as load testing, data pipelines, and proof-of-concepts, where new ideas quickly become tangible. During my studies, I quickly realized that I enjoy the technical side much more than other aspects. For my master's thesis, I built a cloud-agnostic ETL pipeline and consciously chose the path of a Solution Architect afterward.
I work with a strong customer focus and adapt my solutions to the specific needs of each project. At the same time, I always keep a pragmatic perspective: the goal is a solution that is not only technically sound, but also practically usable.
Outside of larger projects, I enjoy experimenting with smaller ideas as well — such as this website or various Raspberry Pi projects.
Certifications
Industry-recognized certifications validating hands-on experience in cloud architecture, security and operations.
Let’s build something solid
Have a cloud project in mind or need AWS support? Let’s talk.
[email protected]


