DevSecOps Engineer (Cloud Security)
Apr 2025 – Present- —Designed and rolled out a hardened CI/CD security pipeline - Semgrep SAST, OWASP ZAP DAST, npm-audit SCA, Trivy container/IaC scanning, and Gitleaks secrets detection, with all scanner images pinned by SHA-256 digest - across 15+ production repositories.
- —Built a fleet-wide TLS certificate auto-renewal platform solo: scheduled GitLab pipelines renew and deploy certificates to every host over WireGuard and rotate Open Telekom Cloud load-balancer certificates via API, with dry-run mode, preflight diagnostics, and MS Teams reporting.
- —Eliminated 29 HIGH and 6 CRITICAL CVEs from the primary base image, drove production containers to zero HIGH/CRITICAL vulnerabilities, and enforced non-root containers across the frontend and backend fleet.
- —Own the observability stack: operate self-hosted Sentry with daily backups to object storage and automatic issue creation from qualifying alerts; rolled out Sentry SDKs to 6 applications; operationalized the ELK monitoring stack.
- —Built hardened Redis and RabbitMQ platform services with TLS, ACL-based authentication, and encrypted configuration, deployed via CI/CD; automated cloud server scheduling to reduce infrastructure costs.
- —Shipped 160 merge requests across 26 projects and 1,200+ CI pipeline runs; driving fleet-wide standardization of pipeline architecture (merge-request gates, tiered post-merge checks, nightly security scans).