Naga Sunkara

Naga Sunkara

Senior DevSecOps | SRE | Cloud & Platform Lead
πŸ“ Houston, TX πŸ“§ nsssunkara@gmail.com πŸ“ž +1 (346) 558-0144 πŸ”— DEV Community πŸ“– Medium πŸ™ GitHub ⚑ IEEE Member (#100476898)

EB-1A Extraordinary Ability Profile & Impact Summary

Demonstrated national and international acclaim in DevSecOps, Cloud Security Architecture, and Enterprise Platform Engineering.

CRITICAL & LEADING ROLE

Enterprise SOX Governance Leadership

Spearheaded the enterprise-wide DevSecOps & SOX compliance transformation for 2,500+ repositories across 100+ business-critical applications at Fortune 100 company (HP Inc.), ensuring multi-billion dollar operational security and audit compliance.

ORIGINAL CONTRIBUTIONS

Zero-Trust & Security Automation

Designed original Shift-Left security architecture, automated policy-as-code frameworks (Sentinel/OPA), and secret-management workflows widely adopted across financial, healthcare, and enterprise cloud deployments.

SCHOLARLY & THOUGHT LEADERSHIP

Published Technical Innovations

Author of widely read technical publications on DevSecOps, Zero-Trust Architecture, and Kubernetes Security reaching thousands of global cloud engineers and cybersecurity professionals on DEV Community and Medium.

JUDGING & PEER REVIEW

Technical Evaluation & Peer Review

Active IEEE Member (#100476898). Evaluator and reviewer for cloud security policies, open-source IaC frameworks, and technical codebases across the DevSecOps ecosystem.

Professional Summary

Results-driven Senior DevSecOps / Platform Engineer with 20+ years in IT and 15+ years specializing in Cloud Security, DevSecOps, and Site Reliability Engineering. Proven track record embedding "Shift-Left" security practices, automated vulnerability management, zero-trust architecture, and identity governance into enterprise CI/CD pipelines across AWS, Azure, and GCP. Hands-on expertise managing SOX, HIPAA, and GDPR compliance, enterprise secrets governance, and Kubernetes runtime protection.

Publications & Open Source Innovations

Enterprise Shift-Left Security & Zero-Trust CI/CD Architectures β€” Published on Medium & DEV Community

Pioneering methodology on embedding automated security gates, OIDC authentication, CodeQL, and secret governance into enterprise-grade deployment pipelines.

Kubernetes Hardening & Runtime Threat Protection at Enterprise Scale β€” Published on DEV Community

Comprehensive architectural framework covering CIS Benchmarks, OPA Gatekeeper enforcement, and Istio mTLS zero-trust communication across multi-cloud environments.

Open Source Infrastructure-as-Code Guardrails β€” Public GitHub Repositories

Developed reusable HashiCorp Sentinel and Terraform modules for automated least-privilege access control and policy-as-code enforcement.

Core Competencies

DevSecOps & AppSec
SnykSonarQubeCodeQLTwistlock / Aqua SecurityShift-Left SecuritySecrets Scanning
Cloud Security & Governance
AWS GuardDutySecurity HubAWS IAM & KMSAzure Key VaultHashiCorp VaultSentinel Policy-as-Code
Compliance Frameworks
SOX (404, CM1, CM2, RU)HIPAAGDPRCIS BenchmarksNIST CSFZero Trust & RBAC
Containers & K8s Security
KubernetesEKSAKSIstio / Linkerd (mTLS)Network PoliciesOPA / GatekeeperKarpenter
IaC & GitOps Automation
TerraformTerragruntAnsibleCheckovTfsecArgo CDFlux CD

Professional Experience

HP Inc. β€” Senior GitHub Migration & Platform DevSecOps Lead May 2025 – Present
SOX Compliance & Security Governance | Houston, TX (Contract)
  • Led HP’s enterprise SOX GitHub Migration program β€” migrated 2,500+ repositories for 100+ SOX-regulated applications into a highly secure GitHub Cloud SOX Organization.
  • Designed team/repo hierarchy, enforced org-level branch protection rulesets, mandatory PR reviews, signed commits, and established guardrails aligned with SOX CM1, CM2, and RU control frameworks.
  • Integrated GitHub Organization with Identity Governance & Administration (IGA) for automated least-privilege access provisioning and lifecycle de-provisioning.
  • Embedded automated security gates (CodeQL, Snyk vulnerability scanning, dependabot alerts) into Harness CI/CD pipelines across 100+ application teams.
Key Tools: GitHub Cloud, Harness CI/CD, IGA, CodeQL, Snyk, ServiceNow, SOX (404, CM1, CM2)
Mutual of Omaha β€” Senior DevSecOps / Cloud Security Engineer Oct 2024 – Apr 2025
  • Automated DevSecOps pipeline controls by integrating SonarQube, Snyk, and CodeQL into GitHub Actions, establishing zero-tolerance quality and security gates for release blocking.
  • Upgraded cloud secret management architecture using HashiCorp Vault and OIDC fine-grained controls, eliminating hardcoded credentials across AWS deployment environments.
  • Enforced least-privilege AWS IAM policies across multi-account environments using Terraform, Sentinel policy-as-code, and AWS GuardDuty.
  • Built automated disaster recovery and encrypted failover pipelines for multi-region RDS PostgreSQL and Aurora databases.
Key Tools: GitHub Actions, Snyk, CodeQL, HashiCorp Vault, Terraform, Sentinel, AWS GuardDuty
Capstone IT Solutions β€” Senior Platform Engineer / Security Lead Jul 2023 – Sep 2024
  • Architected hardened CaaS+ Kubernetes infrastructure on AWS EKS and Azure AKS adhering to CIS Benchmarks, HIPAA, and GDPR compliance standards.
  • Deployed Twistlock (Prisma Cloud) and Aqua Security for continuous container vulnerability scanning and runtime threat detection.
  • Configured Kubernetes RBAC, Pod Security Standards (PSS), network isolation policies, and transit/at-rest encryption across dynamic compute environments.
Key Tools: Terraform, Terragrunt, EKS, AKS, Twistlock, Aqua Security, HIPAA, GDPR, GitLab CI
Micro Focus / OpenText β€” Senior Site Reliability & Security Engineer Aug 2021 – Jul 2023
  • Implemented Istio service mesh across production AKS and EKS clusters to enforce strict mTLS encryption, zero-trust traffic policies, and secure API gateways.
  • Integrated HashiCorp Sentinel policy-as-code into Terraform enterprise deployment workflows to prevent non-compliant infrastructure provisioning.
  • Built centralized audit logging and threat detection pipelines with Splunk and Dynatrace to deliver real-time security alerting.
Key Tools: Istio (mTLS), HashiCorp Sentinel, Terraform, AKS, EKS, Azure DevOps, Dynatrace, Splunk
HPD LendScape β€” Senior Kubernetes Engineer Nov 2020 – Aug 2021
  • Designed and managed Kubernetes clusters on AWS and Azure using GitOps (Flux CD, Argo CD) for automated Git-based deployments.
  • Integrated Istio and Linkerd service meshes for mTLS and traffic management; optimized cluster efficiency via KEDA and Karpenter.
Key Tools: Kubernetes, EKS, AKS, Helm, Flux CD, Argo CD, Istio, KEDA, Karpenter
Kantox (FinTech) β€” Senior Azure DevOps Engineer Jan 2020 – Oct 2020
  • Provisioned Azure infrastructure (VMs, App Services, AKS, ACR, Data Lake, SQL) using Terraform and ARM templates.
  • Configured Prometheus, Grafana, and Datadog monitoring for Kubernetes clusters and implemented SSO with Azure AD.
Key Tools: Azure DevOps, Terraform, AKS, Argo CD, Helm, Prometheus, Datadog
T.J. Maxx β€” Senior AWS DevOps / Cloud Engineer Oct 2012 – Dec 2019
  • Built and maintained AWS infrastructure (EC2, S3, IAM, RDS, VPC, CloudFront) using Terraform and CloudFormation.
  • Reduced OpenShift deployment time by 70% via automated Terraform + Ansible scripts; built Jenkins CI/CD master-slave pipelines.
Key Tools: AWS, Terraform, Kubernetes, OpenShift, Jenkins, Ansible, ELK, Prometheus

Earlier Career

Jack Wills
Infrastructure Engineer
May 2010 – Sep 2012
Shell
Build & Release Engineer
Jul 2009 – Apr 2010
Betclic
Systems Engineer
Jul 2006 – Jun 2009

Certifications

πŸ›‘οΈ HashiCorp Certified: Terraform Associate
☸️ Certified Kubernetes Administrator (CKA)
☁️ AWS Certified Solutions Architect – Associate
πŸ”· Microsoft Certified: Azure Administrator

Education

πŸŽ“ MSc Computing β€” University of Greenwich, London, UK (2009)