jaskarn@berlin:~

cat custody.log --roles 4

8+ years across security, cloud, and networks.

DevSecOps Engineer (Cloud Security)

Apr 2025Present
Lindera · Berlin, Germany
  • Designed and rolled out a hardened CI/CD security pipeline - Semgrep SAST, OWASP ZAP DAST, npm-audit SCA, Trivy container/IaC scanning, and Gitleaks secrets detection, with all scanner images pinned by SHA-256 digest - across 15+ production repositories.
  • Built a fleet-wide TLS certificate auto-renewal platform solo: scheduled GitLab pipelines renew and deploy certificates to every host over WireGuard and rotate Open Telekom Cloud load-balancer certificates via API, with dry-run mode, preflight diagnostics, and MS Teams reporting.
  • Eliminated 29 HIGH and 6 CRITICAL CVEs from the primary base image, drove production containers to zero HIGH/CRITICAL vulnerabilities, and enforced non-root containers across the frontend and backend fleet.
  • Own the observability stack: operate self-hosted Sentry with daily backups to object storage and automatic issue creation from qualifying alerts; rolled out Sentry SDKs to 6 applications; operationalized the ELK monitoring stack.
  • Built hardened Redis and RabbitMQ platform services with TLS, ACL-based authentication, and encrypted configuration, deployed via CI/CD; automated cloud server scheduling to reduce infrastructure costs.
  • Shipped 160 merge requests across 26 projects and 1,200+ CI pipeline runs; driving fleet-wide standardization of pipeline architecture (merge-request gates, tiered post-merge checks, nightly security scans).

Cybersecurity & DevOps Engineer (Working Student)

Oct 2023Mar 2025
Lindera · Berlin, Germany
  • Implemented and maintained ISO 27001 security controls and audit-readiness documentation in a regulated healthcare environment (GDPR, HIPAA-aligned processes).
  • Ran vulnerability assessments across cloud and application layers with remediation tracking to closure.
  • Monitored and responded to security incidents using the ELK stack, OSSEC, and Wireshark under established incident-response procedures.
  • Automated Docker builds and Hetzner server deployments in GitLab CI for web and mobile applications, including non-root container hardening.
  • Drove secure-coding practices and delivered security awareness sessions for development teams.

NOC Engineer II

Oct 2019Mar 2023
Zeta · Bangalore, India
  • Configured and managed WAF and IDS/IPS systems (FortiGate); ran vulnerability scanning with Nessus and Qualys for banking-technology infrastructure.
  • Maintained 99.99% uptime of wired and wireless network infrastructure serving card-issuing and core-banking platforms.
  • Migrated servers to AWS with infrastructure-as-code, improving production efficiency 17% with no added downtime.
  • Implemented and audited ISO 27001 and PCI-DSS security controls.
  • Reduced network downtime 30% through continuous monitoring and incident management; documented 22 client networks.
  • Reviewed, audited, and onboarded 15 external vendors handling billions of concurrent network requests.

Associate Network Engineer

Sep 2016May 2019
KocharTech · Amritsar, India
  • Provided first- and second-level support for network security incidents, including firewall configuration and intrusion-detection analysis.
  • Performed scheduled Juniper upgrades and configuration changes with zero service downtime.
  • Executed 75% of all firewall changes, installs, and upgrades; remediated 13 quarterly IDS/IPS findings.
  • Led 6 major network design, implementation, and automation projects.

Education

Degrees

  • MSc Cybersecurity
    IU International University of Applied Sciences
    Jul 2023Mar 2025 · Berlin, Germany
  • B.Tech Computer Science
    Satyam Institute of Engineering and Technology (Punjab Technical University)
    20162019 · Amritsar, India

Languages

English (Proficient) · Punjabi (Native) · Hindi (Native) · German (A1 - in active study)