whoami
Cloud Security & DevSecOps Engineer | AI/Agentic Security (USAP) — Berlin
cat mission.txt
I design security architecture for cloud-native production systems and build open-source tooling for securing AI agents. Creator of USAP: cybersecurity agents that reason, cite resolvable evidence, and gate every mutating action behind human approval.
Evidence
cat evidence.log --tail 5
Architecture designed, pipelines built, risk removed.
- Exhibit 01Verified15+Production repos on one security architecture
Designed the fleet-wide CI/CD security architecture - Semgrep SAST, OWASP ZAP DAST, npm-audit SCA, Trivy container/IaC scanning, Gitleaks secrets detection, every scanner image pinned by SHA-256 digest - and rolled it across 15+ production repositories.
- Exhibit 02Verified100%TLS lifecycle automated, fleet-wide
Architected and built the certificate-renewal platform solo: scheduled pipelines renew and deploy certificates to every host over WireGuard and rotate cloud load-balancer certificates via API - dry-run mode, preflight diagnostics, MS Teams reporting.
- Exhibit 03Verified0HIGH/CRITICAL CVEs in production images
Cleared 29 HIGH and 6 CRITICAL CVEs from the largest base image, drove production containers to zero HIGH/CRITICAL findings, and enforced non-root containers across the frontend and backend fleet.
- Exhibit 04Verified6 appsObservability designed and rolled out
Operate self-hosted Sentry (daily backups to object storage, automatic issue creation in the tracker from qualifying alerts), rolled out Sentry SDKs to 6 applications, and operationalized the ELK monitoring stack.
- Exhibit 05Verified1,200+CI pipelines across 26 projects
160 merge requests across 26 projects: designed Redis and RabbitMQ platform services as hardened infrastructure-as-code (TLS, ACL auth, encrypted configs, CI/CD deploys), plus cloud server auto-scheduling that cuts infrastructure costs.
ls --sections