Portrait of Navid Rad Kusha

Navid Rad Kusha

DevOps · Cloud & Automation

I build the plumbing that gets software safely into production — Azure landing zones, Kubernetes, CI/CD pipelines and infrastructure as code. Most of my work starts at discovery and a high-level design, and ends with a validated environment handed over to the team that runs it.

Over the last few years that has meant moving VM-based workloads onto AKS, writing Terraform and Bicep modules teams actually reuse, automating Entra ID provisioning and least-privilege RBAC, and building FinOps tooling that switches off what nobody is using at 2 a.m.

  1. Cloud Engineer

    Pax8 · Full-time · Zwolle, Netherlands (Remote)

    • Deliver cloud infrastructure projects across Azure Landing Zones, Azure Virtual Desktop, application hosting platforms, networking, governance, monitoring, backup and security-aligned deployments — from discovery and high-level design through workload deployment, environment validation and technical handover.
    • Designed and deployed standardised Azure Virtual Desktop environments across multiple client tenants, including session host orchestration, scaling plans and AVD Insights monitoring.
    • Supported hybrid identity integration spanning Active Directory and Entra ID: domain-join troubleshooting, sync configuration and cross-tenant identity models.
    • Developed and captured custom golden images for AVD via Azure Compute Gallery, streamlining session host provisioning.
  2. Application Engineer — YPTO (NMBS/SNCB)

    Narato

    CI/CD & Infrastructure as Code

    • Designed and maintained end-to-end CI/CD pipelines in Azure DevOps, integrating automated build, test and release stages.
    • Authored Terraform modules to provision and manage Azure resources, ensuring consistency, repeatability and version control.

    Legacy application modernisation

    • Migrated on-premise and VM-based workloads to Azure Kubernetes Service, reducing operational costs and improving resilience.
    • Optimised Dockerfiles with multi-stage builds for smaller, more secure container images.
    • Developed reusable Helm chart templates to standardise deployments; implemented Azure Key Vault for centralised secret management.
    • Enhanced autoscaling with sidecar containers and KEDA, improving performance under variable traffic.

    FinOps automation & identity

    • Co-architected and refactored a legacy monolith into microservices for a FinOps tool that shuts down workloads outside business hours; integrated Azure Event Hubs for event-driven communication.
    • Built a microservice to automate Entra ID provisioning and custom RBAC role assignments, dynamically granting least-privilege access.
    • Conducted performance profiling and optimisation (caching, connection pooling, async patterns) to keep the platform scalable and highly available.
  3. DevOps Engineer — Flanders Investment & Trade (FIT)

    Narato

    • Built and optimised Azure DevOps (YAML) pipelines with automated testing.
    • Deployed scalable APIs and microservices on Kubernetes; applied Blue/Green and Canary strategies with KEDA for event-driven autoscaling.
  4. DevOps Engineer — Kapelli

    Narato

    • Automated deployments with Azure DevOps CI/CD pipelines.
    • Developed Bash automation functions to streamline recurring workflows.
    • DevOps Engineer — Dept. of Finance & Budget (DFB)

      Narato

      • Configured secure infrastructure with Bicep, VPN, Azure Firewall and Application Gateway.
      • Built automated CI/CD pipelines for Azure Container Apps, applying scalability and security best practices.
    • Backend Developer & Research — Internship

      Integration Designers

      • Secured a GraphQL API using IBM API Connect with OAuth and API key security.
      • Researched GraphQL integration patterns and performance improvements.