Professional Summary
Results-driven Senior DevSecOps / Platform Engineer with 20+ years in IT and 15+ years specializing in Cloud Security, DevSecOps, and Site Reliability Engineering. Proven track record embedding "Shift-Left" security practices, automated vulnerability management, zero-trust architecture, and identity governance into enterprise CI/CD pipelines across AWS, Azure, and GCP. Hands-on expertise managing SOX, HIPAA, and GDPR compliance, enterprise secrets governance, and Kubernetes runtime protection.
Professional Experience
SOX Compliance & Security Governance | Houston, TX (Contract)
- Led HPβs enterprise SOX GitHub Migration program β migrated 2,500+ repositories for 100+ SOX-regulated applications into a highly secure GitHub Cloud SOX Organization.
- Designed team/repo hierarchy, enforced org-level branch protection rulesets, mandatory PR reviews, signed commits, and established guardrails aligned with SOX CM1, CM2, and RU control frameworks.
- Integrated GitHub Organization with Identity Governance & Administration (IGA) for automated least-privilege access provisioning and lifecycle de-provisioning.
- Embedded automated security gates (CodeQL, Snyk vulnerability scanning, dependabot alerts) into Harness CI/CD pipelines across 100+ application teams.
Key Tools: GitHub Cloud, Harness CI/CD, IGA, CodeQL, Snyk, ServiceNow, SOX (404, CM1, CM2)
- Automated DevSecOps pipeline controls by integrating SonarQube, Snyk, and CodeQL into GitHub Actions, establishing zero-tolerance quality and security gates for release blocking.
- Upgraded cloud secret management architecture using HashiCorp Vault and OIDC fine-grained controls, eliminating hardcoded credentials across AWS deployment environments.
- Enforced least-privilege AWS IAM policies across multi-account environments using Terraform, Sentinel policy-as-code, and AWS GuardDuty.
- Built automated disaster recovery and encrypted failover pipelines for multi-region RDS PostgreSQL and Aurora databases.
Key Tools: GitHub Actions, Snyk, CodeQL, HashiCorp Vault, Terraform, Sentinel, AWS GuardDuty
- Architected hardened CaaS+ Kubernetes infrastructure on AWS EKS and Azure AKS adhering to CIS Benchmarks, HIPAA, and GDPR compliance standards.
- Deployed Twistlock (Prisma Cloud) and Aqua Security for continuous container vulnerability scanning and runtime threat detection.
- Configured Kubernetes RBAC, Pod Security Standards (PSS), network isolation policies, and transit/at-rest encryption across dynamic compute environments.
Key Tools: Terraform, Terragrunt, EKS, AKS, Twistlock, Aqua Security, HIPAA, GDPR, GitLab CI
- Implemented Istio service mesh across production AKS and EKS clusters to enforce strict mTLS encryption, zero-trust traffic policies, and secure API gateways.
- Integrated HashiCorp Sentinel policy-as-code into Terraform enterprise deployment workflows to prevent non-compliant infrastructure provisioning.
- Built centralized audit logging and threat detection pipelines with Splunk and Dynatrace to deliver real-time security alerting.
Key Tools: Istio (mTLS), HashiCorp Sentinel, Terraform, AKS, EKS, Azure DevOps, Dynatrace, Splunk
- Designed and managed Kubernetes clusters on AWS and Azure using GitOps (Flux CD, Argo CD) for automated Git-based deployments.
- Integrated Istio and Linkerd service meshes for mTLS and traffic management; optimized cluster efficiency via KEDA and Karpenter.
Key Tools: Kubernetes, EKS, AKS, Helm, Flux CD, Argo CD, Istio, KEDA, Karpenter
- Provisioned Azure infrastructure (VMs, App Services, AKS, ACR, Data Lake, SQL) using Terraform and ARM templates.
- Configured Prometheus, Grafana, and Datadog monitoring for Kubernetes clusters and implemented SSO with Azure AD.
Key Tools: Azure DevOps, Terraform, AKS, Argo CD, Helm, Prometheus, Datadog
- Built and maintained AWS infrastructure (EC2, S3, IAM, RDS, VPC, CloudFront) using Terraform and CloudFormation.
- Reduced OpenShift deployment time by 70% via automated Terraform + Ansible scripts; built Jenkins CI/CD master-slave pipelines.
Key Tools: AWS, Terraform, Kubernetes, OpenShift, Jenkins, Ansible, ELK, Prometheus