jaskarn@berlin:~
jaskarn@berlin:~ — sessiononline

whoami

Cloud Security & DevSecOps Engineer | AI/Agentic Security (USAP) — Berlin

cat mission.txt

I design security architecture for cloud-native production systems and build open-source tooling for securing AI agents. Creator of USAP: cybersecurity agents that reason, cite resolvable evidence, and gate every mutating action behind human approval.

threat feed
Years in security & infrastable
8+
CI pipelines shippedactive
1,200+
HIGH/CRIT CVEs in prod imagesclear
0

Evidence

cat evidence.log --tail 5

Architecture designed, pipelines built, risk removed.

  1. Exhibit 01Verified
    15+
    Production repos on one security architecture

    Designed the fleet-wide CI/CD security architecture - Semgrep SAST, OWASP ZAP DAST, npm-audit SCA, Trivy container/IaC scanning, Gitleaks secrets detection, every scanner image pinned by SHA-256 digest - and rolled it across 15+ production repositories.

  2. Exhibit 02Verified
    100%
    TLS lifecycle automated, fleet-wide

    Architected and built the certificate-renewal platform solo: scheduled pipelines renew and deploy certificates to every host over WireGuard and rotate cloud load-balancer certificates via API - dry-run mode, preflight diagnostics, MS Teams reporting.

  3. Exhibit 03Verified
    0
    HIGH/CRITICAL CVEs in production images

    Cleared 29 HIGH and 6 CRITICAL CVEs from the largest base image, drove production containers to zero HIGH/CRITICAL findings, and enforced non-root containers across the frontend and backend fleet.

  4. Exhibit 04Verified
    6 apps
    Observability designed and rolled out

    Operate self-hosted Sentry (daily backups to object storage, automatic issue creation in the tracker from qualifying alerts), rolled out Sentry SDKs to 6 applications, and operationalized the ELK monitoring stack.

  5. Exhibit 05Verified
    1,200+
    CI pipelines across 26 projects

    160 merge requests across 26 projects: designed Redis and RabbitMQ platform services as hardened infrastructure-as-code (TLS, ACL auth, encrypted configs, CI/CD deploys), plus cloud server auto-scheduling that cuts infrastructure costs.

ls --sections