About
I am a DevSecOps Engineer focused on building "secure-by-default" infrastructures. I integrate security systematically into the SDLC and CI/CD pipelines, covering IaC security, supply-chain protection, and Kubernetes hardening. My approach shifts security from "post-deployment checking" to automated, measurable gates that empower development teams while ensuring robust compliance.
Key Achievements
Established Secure CI/CD Pipelines: Integrated automated security stages into GitLab CI, including secrets scanning, SAST, and dependency analysis (SCA) to block insecure releases.
Infrastructure as Code (IaC) Governance: Implemented Policy-as-Code for Terraform and Kubernetes, ensuring pre-deployment compliance and drift control.
Container & Orchestration Security: Standardized secure Dockerfile practices and hardened Kubernetes clusters using RBAC, Network Policies, and Admission Controllers.
Multi-Cloud Network Protection: Engineered secure connectivity across AWS, Azure, and GCP using PrivateLink/Endpoints and centralized WAF/Firewall logging.
Secrets & Identity Management: Eliminated hardcoded secrets by implementing vaulting solutions (HashiCorp Vault/Cloud Secret Managers) with short-lived token authentication.
Incident Readiness & Observability: Developed automated alerting for runtime threats and established clear playbooks for rapid incident response and post-mortem analysis.
Featured Projects
Secure SDLC Framework
Designed and implemented the "Security Gates" standard. This includes reusable CI/CD templates that automate vulnerability scanning and enforce release policies based on risk levels.
Multi-Cloud Secure Networking Architecture
Designed and implemented a secure networking architecture spanning multiple cloud environments to support protected communication between services and infrastructure components. The architecture focuses on private connectivity models, centralized network monitoring, and controlled service exposure. Secure connectivity was implemented using private endpoints and encrypted tunnels while maintaining strict traffic filtering and monitoring practices.
Container & Kubernetes Security Platform
Built a hardened Kubernetes platform designed with security controls integrated into every layer of the container lifecycle. The platform standardizes secure Docker image builds, enforces role-based access control, and restricts network communication between services using Kubernetes Network Policies. Additional runtime protections were introduced through admission controllers and container vulnerability scanning to maintain a secure container environment.


