EXPERT
Profile photo of Oleksii Shcherbyna, DevSecOps Engineer at InfraJump

Oleksii Shcherbyna

DevSecOps Engineer

Expertise
KubernetesTrivyGitleaksSASTSCASBOM
terminal
LIVE
root@infrajump:~# _

About

I am a DevSecOps Engineer focused on building "secure-by-default" infrastructures. I integrate security systematically into the SDLC and CI/CD pipelines, covering IaC security, supply-chain protection, and Kubernetes hardening. My approach shifts security from "post-deployment checking" to automated, measurable gates that empower development teams while ensuring robust compliance.

Key Achievements

Established Secure CI/CD Pipelines: Integrated automated security stages into GitLab CI, including secrets scanning, SAST, and dependency analysis (SCA) to block insecure releases.

Infrastructure as Code (IaC) Governance: Implemented Policy-as-Code for Terraform and Kubernetes, ensuring pre-deployment compliance and drift control.

Container & Orchestration Security: Standardized secure Dockerfile practices and hardened Kubernetes clusters using RBAC, Network Policies, and Admission Controllers.

Multi-Cloud Network Protection: Engineered secure connectivity across AWS, Azure, and GCP using PrivateLink/Endpoints and centralized WAF/Firewall logging.

Secrets & Identity Management: Eliminated hardcoded secrets by implementing vaulting solutions (HashiCorp Vault/Cloud Secret Managers) with short-lived token authentication.

Incident Readiness & Observability: Developed automated alerting for runtime threats and established clear playbooks for rapid incident response and post-mortem analysis.

Featured Projects

Secure SDLC Framework

Designed and implemented the "Security Gates" standard. This includes reusable CI/CD templates that automate vulnerability scanning and enforce release policies based on risk levels.

GitLab CISAST/SCATrivyGitleaksSBOM

Multi-Cloud Secure Networking Architecture

Designed and implemented a secure networking architecture spanning multiple cloud environments to support protected communication between services and infrastructure components. The architecture focuses on private connectivity models, centralized network monitoring, and controlled service exposure. Secure connectivity was implemented using private endpoints and encrypted tunnels while maintaining strict traffic filtering and monitoring practices.

AWSAzureTerraformWAFPrivateLinkVPNNetwork Security

Container & Kubernetes Security Platform

Built a hardened Kubernetes platform designed with security controls integrated into every layer of the container lifecycle. The platform standardizes secure Docker image builds, enforces role-based access control, and restricts network communication between services using Kubernetes Network Policies. Additional runtime protections were introduced through admission controllers and container vulnerability scanning to maintain a secure container environment.

KubernetesDockerRBACNetwork PoliciesAdmission ControllersTrivy

Technical Skills

DevSecOps & Security

SAST/DAST/SCASecrets ScanningContainer ScanningPolicy-as-Code (OPA)Network Security (nftablesVPN)

Orchestration & Cloud

Kubernetes (RBACNetPol)DockerAWSOpenStackVMwareHashiCorp Stack (ConsulNomad)

Infrastructure as Code

TerraformAnsibleGitLab CI

Observability & Systems

Prometheus & GrafanaELK StackLinux (DebianUbuntuCentOS)Bash Scripting