

DevSecOps / Cloud Engineer with 3+ years of experience building secure cloud infrastructure and CI/CD pipelines on AWS. Experienced in integrating security automation into DevOps workflows using Snyk, vulnerability management, and AI-assisted remediation pipelines. Skilled in Infrastructure as Code (Terraform), container orchestration (Docker, Kubernetes), and implementing automated security scanning and dependency vulnerability management within CI/CD environments. Bilingual DevOps Engineer with background designing, testing, and implementing infrastructure and applications. Talented performer with over 3 years of experience using source control tools to identify and fix bugs in code. Consistent team player with exemplary multitasking skills.
AWS Cloud Infrastructure Management
• Managed and maintained AWS cloud infrastructure including EC2, VPC, RDS, ECS, EKS, App Runner, S3, and EBS to support scalable production workloads.
• Provisioned and configured EC2 instances with appropriate security groups and IAM roles.
• Designed VPC architecture including public/private subnets, NAT gateways, and route tables.
• Managed RDS database instances with backup, monitoring, and scaling configurations.
• Configured S3 buckets for application storage with lifecycle policies and encryption.
Infrastructure as Code (Terraform)
• Designed and provisioned Infrastructure as Code (IaC) using Terraform for secure and repeatable cloud deployments.
• Created reusable Terraform modules for VPC, compute resources, and networking components.
• Managed Terraform state files and remote backends for collaborative infrastructure provisioning.
• Implemented infrastructure automation including subnets, route tables, security groups, and IAM roles.
CI/CD Pipeline Implementation
• Built and maintained CI/CD pipelines using Jenkins for automated application build and deployment.
• Configured Jenkins pipelines for build, test, security scanning, and deployment stages.
• Automated Docker image builds and pushed images to container registries.
• Implemented pipeline triggers based on Git commits and pull requests.
DevSecOps Integration (Security in Pipeline)
• Integrated DevSecOps security tools such as Snyk into CI/CD pipelines.
• Implemented SAST and dependency vulnerability scanning for application code and libraries.
• Configured automated pipeline failure when critical vulnerabilities are detected.
• Generated security reports and coordinated remediation with development teams.
Vulnerability Management
• Implemented vulnerability management workflows to maintain secure applications and infrastructure.
• Identified outdated libraries and dependencies using automated scanning tools.
• Coordinated with developers to upgrade vulnerable packages.
• Maintained vulnerability remediation tracking and security compliance practices.
Containerization and Container Orchestration
• Containerized applications using Docker and deployed workloads to Kubernetes (EKS) and Amazon ECS.
• Built and optimized Docker images for application deployment.
• Managed Kubernetes deployments, services, and namespaces.
• Implemented container scaling and orchestration strategies.
Application Deployment Support
• Supported and deployed Node.js and React applications in containerized environments.
• Managed build and deployment pipelines for frontend and backend services.
• Configured environment variables and application runtime settings.
• Troubleshot build failures, container issues, and runtime errors.
Configuration Management Automation
• Automated configuration management using Ansible.
• Developed Ansible playbooks to configure servers and application environments.
• Automated package installation, service configuration, and system updates.
• Ensured consistent server configuration across environments.
Secrets Management and Credential Security
• Implemented secure secrets management using HashiCorp Vault and AWS Secrets Manager.
• Stored application credentials, API keys, and database passwords securely.
• Implemented dynamic secret retrieval for applications and CI/CD pipelines.
• Enforced secure access policies for secret management.
Identity and Access Management
• Enforced least-privilege access control using AWS IAM policies and role-based access.
• Created IAM roles for applications, services, and CI/CD pipelines.
• Implemented granular permission policies to reduce security risks.
• Audited access policies to ensure compliance with security best practices.
Infrastructure Troubleshooting
• Troubleshot cloud infrastructure, networking, and deployment issues across environments.
• Diagnosed VPC networking issues, security group misconfigurations, and connectivity problems.
• Investigated application deployment failures in CI/CD pipelines.
• Resolved Kubernetes and container runtime issues.
DevSecOps Security Practices
• Implemented DevSecOps practices within CI/CD pipelines.
• Integrated SAST, DAST, and dependency vulnerability scanning tools.
• Implemented container image security scanning before deployment.
• Enforced security gates within pipelines to prevent vulnerable builds.
Monitoring and Performance Optimization
• Monitored and optimized cloud infrastructure and container workloads.
• Implemented monitoring for application health and resource utilization.
• Optimized container resource usage and scaling configurations.
• Ensured high availability and reliability of production workloads.