>Selected Work

Projects

Real infrastructure and security challenges — each with the problem, architecture, technologies, and outcome.

DevOps

Multi-Cloud GitOps Platform

PROBLEM

A growing engineering team needed a consistent way to deploy services across AWS and GCP without environment drift or manual provisioning.

SOLUTION

Built a GitOps platform using ArgoCD and Terraform that reconciles cluster state from Git, with policy guardrails and automated drift detection.

TerraformArgoCDKubernetesAWSGCPOPAGitHub Actions
DevSecOps

DevSecOps Pipeline Hardening

PROBLEM

An organization shipped container images without security scanning, leaving known CVEs and misconfigurations undetected until production.

SOLUTION

Implemented a multi-stage security pipeline with SAST, dependency scanning, container image scanning, IaC scanning, and policy-as-code gates.

JenkinsTrivySonarQubeCheckovOPACosignDocker
Monitoring

Kubernetes Observability Stack

PROBLEM

Teams lacked visibility into cluster health, application latency, and log correlation, leading to slow incident response and prolonged outages.

SOLUTION

Deployed a unified observability stack with Prometheus for metrics, Loki for logs, and Grafana for dashboards, with SLO-based alerting.

PrometheusGrafanaLokiAlertmanagerKubernetesS3
Cloud Security

Zero-Trust Cloud Hardening

PROBLEM

An AWS environment had overly permissive IAM roles, open security groups, and no continuous compliance monitoring, creating a large attack surface.

SOLUTION

Implemented least-privilege IAM, network segmentation, CIS benchmark enforcement, and continuous configuration scanning with automated remediation.

AWS ConfigGuardDutyIAM Access AnalyzerTerraformLambdaConftest
Cybersecurity

Web Application Penetration Test

PROBLEM

A client needed a pre-release security assessment of a customer-facing web application handling sensitive data.

SOLUTION

Conducted a manual penetration test complemented by automated scanning, covering OWASP Top 10, authentication, authorization, and API endpoints.

Burp SuiteOWASP ZAPNmapNiktoMetasploit
Cloud Cost

IaC-Driven Cost Optimization

PROBLEM

An organization had uncontrolled cloud spend growth with no visibility into per-team costs or idle resources.

SOLUTION

Built FinOps dashboards, automated rightsizing recommendations, and implemented spot-instance strategies with graceful fallback.

AWS Cost ExplorerGrafanaLambdaTerraformSpot Instances
$ init --secure

Let's Build Something Secure

Looking for a DevOps, DevSecOps, Cloud, or Cybersecurity engineer? Let's talk about how I can help your team build, deploy, and secure its infrastructure.