Evolvex
Available for new engagements

Cloud infrastructure built to be operated, not just deployed.

Senior DevOps consulting for European startups and SMBs. Azure platforms, secured and automated — written reviews and shipped PRs, not slide decks.

Services

/services
01

Azure Security Reviews

A pragmatic posture review of your Azure estate: IAM and RBAC, Key Vault and secrets, network segmentation, and Policy alignment with Microsoft's Cloud Adoption Framework (CAF) and Well-Architected Framework (WAF). Delivered as a prioritised written review with concrete remediation paths.

02

Infrastructure-as-Code Review

Line-by-line review of your Terraform, with Checkov policy-as-code layered on top. Module structure, state and drift, secret handling, CI integration. Delivered as a written review plus fix PRs against your repo — including custom policies tuned to your conventions.

03

DevSecOps Engineering

End-to-end pipeline build on Azure DevOps or GitHub Actions: static analysis (SAST), dependency scanning (SCA), secret scanning, and environment promotion. Built around GitHub Advanced Security, CodeQL, SonarQube, and Mend.io. Delivered as a working pipeline plus a runbook your team can maintain.

Selected engagements

/work
2026 — presentBig 4 audit & advisory firm

Checkov policy framework, multi-country rollout

Designed and built a Checkov-based IaC security framework deployed across multiple member firms in different countries. 40+ custom Azure security policies covering Data Factory, SQL Managed Instance, Redis, ACR, AKS, Databricks, and Container Apps. Distributed from GitHub to consuming Azure DevOps projects via OpenID Connect (OIDC) federation — no long-lived secrets across organisations.

2025European energy enterprise

Azure Landing Zones across 17+ subscriptions

Implemented CAF/WAF-aligned Landing Zones across 17+ subscriptions, organised into corp, online, sandbox, and platform management groups. Hub-spoke networking, Azure Arc for hybrid governance, and a custom monitoring stack across Azure and on-premises. Terraform + Terragrunt + Atlantis for PR-driven IaC.

2025Big 4 audit & advisory firm

Native Azure SQL monitoring stack

Replaced an enterprise SQL monitoring product (~$30K/year licensing) across 20 servers with native Azure Monitor, Log Analytics, and Data Collection Rules. Adopted by the German entity, then rolled out organisation-wide — leading a small team of engineers through delivery.

How it works

/process
01

Discovery call

30-minute call to understand your stack, the problem, and your goals. No commitment.

02

Scoped proposal

Written scope, deliverables, timeline, and fee within three business days. Fixed-price where it makes sense.

03

Delivery

Reviews, fixes, and PRs against your repos. Async written progress; no daily standups required.

04

Handover

Final writeup, a runbook your team owns, and a follow-up call after sign-off.

About

/about

Evolvex is a one-person consultancy run by a senior DevOps engineer with six years of experience, the last three focused on Azure platform engineering and IaC security in enterprise and Big 4 environments. Recent work spans Checkov-based policy-as-code distributed across multi-country member firms, CAF/WAF Landing Zones across 17+ subscriptions, and a native Azure Monitor stack that replaced ~$30K/year of third-party SQL monitoring tooling.

Engagements range from focused security reviews to long-term embedded work. The same engineer who reviews your code writes the fix PRs — no handoffs, no junior shadowing. Fixed scope, written deliverables, and a runbook your team owns at the end.

Based
Sofia, Bulgaria
Working with
EU startups & SMBs (remote)
Stack
Azure · Terraform · Checkov · Azure DevOps · GitHub Actions
Engagements
Project, weekly, or day rate
Certifications
AZ-400 · AZ-104 · GH-500

Contact

/contact

Send a brief about your stack, the problem, and your timeline. Replies within two business days.

hello@evolvex.ltd