DevOps · Infrastructure · Yerevan, Armenia

Production infrastructure that stays up — automated, observable, secure.

I'm Nerses Antonyan, a DevOps engineer and system administrator. After 13 years keeping regulated banking systems accurate and online, I now design, automate and operate production infrastructure across Linux and Windows — with monitoring, CI/CD and infrastructure-as-code built in from day one.

Systems that areSecureReliableObservable
Remote & on-site Full infrastructure lifecycle Security-minded
Nerses Antonyan Nerses Antonyan
Why Nerses

Financial-grade discipline, applied to infrastructure.

A rare combination: someone who has lived inside systems where an error or an hour of downtime has real consequences — and who now builds the automation and observability that prevent both.

Secure by design

Hardened servers, least-privilege access and hands-on penetration testing — finding weaknesses before attackers do.

Reliable by default

13+ years in banking, where downtime and inaccuracy weren't options — now built into how every system runs.

Fully observable

Prometheus, Grafana and Zabbix wired in from the start, so incidents surface — and get resolved — before users notice.

Automated end to end

Terraform, Ansible and Bash turn manual, error-prone work into reproducible, version-controlled infrastructure.

13yr
In regulated financial systems — reporting, credit & treasury
5yr
Trading digital assets & cryptocurrency markets
11+
Core DevOps & infrastructure technologies
3
Languages — Armenian, Russian & English
Experience

From bank ledgers to build pipelines.

A career built on operational accountability — carried from financial institutions into modern infrastructure.

◆ Current focusCurrent

DevOps Engineer & Infrastructure Consultant

Independent · Remote

Designing, provisioning and operating production infrastructure for clients — Linux and Windows servers, containerized workloads, CI/CD pipelines and infrastructure-as-code, with monitoring and alerting in place from the first deploy. Everything built to be secure, reliable and observable — now expanding into penetration testing and security assessments.

Jul 2025 — Present Remote Linux · Docker · Kubernetes · Terraform · Observability

Red Invest Group LLC Current

Sep 2025 — Present
Banking & Notarial Processes Manager
Yerevan, Armenia

Artsakhbank

Feb 2024 — Sep 2025
Dealer — Financial Operations Department
Yerevan, Armenia · treasury & market operations

Artsakhbank

Nov 2018 — Feb 2024
Senior Specialist — Credit Committees Support & Credit Analysis
Yerevan, Armenia · risk & credit assessment

Artsakhbank

May 2012 — Nov 2018
Specialist / Senior Specialist — CBA Reporting Department
Yerevan, Armenia · regulatory reporting & data accuracy
Selected Work

Infrastructure, shipped and running.

// case-study links coming in a future update

Securitynew direction

Penetration testing & security assessment

SYN/FIN/Xmas/NULL scanning, OS fingerprinting, UFW bypass via conntrack INVALID, hping3, infrastructure recon, hardening recommendations.

hping3SYN/FIN scanOSINTFirewall bypass
CI / CDlive

Automated deployment pipeline

GitLab CI: test (go test) → build (Docker + GitLab Container Registry) → deploy (ssh + docker pull). Three stages, zero-downtime, deploy to test and prod from a single pipeline.

GitLab CIDockerGoContainer Registry
Observabilitylive

Monitoring & alerting stack

Prometheus (node_exporter + textfile collector), Grafana (dashboards), Loki + Promtail (container logs + syslog), Alertmanager (8 alerts: CPU, RAM, disk, WireGuard, Nginx, SSH brute force).

PrometheusGrafanaLokiAlertmanager
IaClive

Infrastructure as code

Terraform: VPC, subnet, Cloud NAT, MIG, HTTP LB, two environments (test/prod) with VPC peering. Ansible: 7 roles (common, docker, firewall, wireguard, monitoring, nginx, totp). CI validates terraform + ansible-lint.

TerraformAnsibleGCPVPC peering
App Securitylive

E2E encrypted messenger

ZeroTalk: Go WebSocket server with TLS 1.3, Ed25519 challenge-response, pre-key store (24h), file sharing (5min + secure overwrite). HTML client embedded in binary, XSS-protection, rate limiter, 6 security headers.

GoWebSocketEd25519TLSXSS-protection
Networklive

Network security & IDS/IPS

Multi-layered defense: GCP firewall + UFW + iptables. Zeek IDS (protocol analysis, JA3), Suricata IPS (30,000+ Emerging Threats rules), ntopng (visualization), fail2ban (SSH), egress filtering with alerts.

ZeekSuricataUFWiptablesfail2ban
Core Competencies

The full toolchain, hands-on.

Security & Penetration Testing

Penetration testingVulnerability assessmentServer hardeningNetwork securityAccess control

Systems & Administration

Linux serversWindows serversSSHDNSDHCPUser privileges

Automation & IaC

TerraformAnsibleBash scriptingInfrastructure as Code

Containers & CI/CD

DockerKubernetesCI/CD pipelines

Networking & Web

TCP/IPOSI modelNGINXApacheIIS

Data & Observability

PostgreSQLMySQLPrometheusGrafanaZabbix

Financial & Crypto Domain

Banking operationsCBA reportingCredit analysisTreasury dealingCrypto trading
Education
Armenian National Agrarian University
Stepanakert, Armenia
Master's2012 — 2014
Artsakh State University
Stepanakert, Armenia
Bachelor's2006 — 2012
Let's talk

Looking for a DevOps engineer who owns reliability?

I'm available now for remote or on-site roles and infrastructure consulting. Bring me your servers, pipelines and uptime targets — I'll bring the discipline to keep them running.