Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Timeline
Core Competencies
Generic

Ashfak A. M

Los Angeles,USA

Summary

Senior IT Consultant with 10+ years of experience in software development and specialize in various system design and application development. I worked as an IT Release and Configuration manager, Cloud and DevOps Consultant, Microsoft technology lead and currently working as IT Release Engineer II. In these roles, I was able to deliver some critical projects while working in a regulated industry for California state local county such as LAUSD and L.A Care Health Plan. My expertise is in Application development cycle process, setting up CI/CD pipelines using advance tools and cloud services for Azure and AWS services. I was involved in automation of build & deployment processes, managing code releases, and ensuring high-quality, reliable software delivery. I have strong problem-solving skills with a proven track record of collaborating with cross-functional teams to optimize the release workflow and timely delivery of software applications. Highly skilled in project planning, application design and implementing various version control systems, build & deploy process, code quality, vulnerability management, remediation management for cloud and native platforms. I would continue to deliver with a passion for innovation and technology.

Overview

16
16
years of professional experience
1
1
Certification

Work History

Release and Change Management

L.A Care Health Plan
Los Angeles, CA, USA
12.2017 - Current
  • Planning and execution of code migration to GitHub, helping team with branching strategy applying policies for rules around code promotion
  • Leading and mentoring developers to write secure software through activities like defensive programming techniques, usage of security frameworks, and performing threat modeling.
  • Functional knowledge on State and federal Health Plans and adherence to various audits and compliance
  • Spearheaded the design, implementation, and optimization of the CI/CD pipelines using ART, resulting in a 30% increase in deployment cycle and a 25% reduction in deployment failures.
  • Lead and mentored a team of 4 release engineers, fostering best practices and maintaining high standards in release management processes.
  • GitHub Action setup for Build job pipeline
  • Integration with GitHub, JFrog, SonarQube for Build, Code scan
  • Setup up AWS CodeCommit, CodeBuild, SQ, CodeDeploy, Monitoring and CloudWatch
  • Jira integration with Source Control version tool for KB setup for daily tracking of RFCs for ePMO
  • Implemented version control practices using Git, ensuring smooth integration of code changes with minimal conflict and faster resolution of merge issues.
  • Managed the deployment of software releases to both on-premises and cloud environments (AWS, Azure), ensuring high availability and scalability.
  • Developed and maintained automation scripts for build, test, and deployment workflows, reducing manual intervention by 40%.
  • Collaborated closely with development, QA, and operations teams to coordinate release schedules and troubleshoot post-release issues.
  • Conducted regular codebase and configuration audits, resulting in improved code quality and reduced downtime.
  • Plan, deploy, and configure networking and cybersecurity systems by minimizing security threats
  • Maintain and audit EMR (Electronic Medical recording) and look for any PHI violation
  • Setup Business process Automation for TPM- Total provider management project with integrating remote Git with LA Care GitHub, and setting up Agile process for CICD deployment.
  • Leading and mentoring developers to write secure software through activities like defensive programming techniques, usage of security frameworks, and performing thread modeling.
  • Cloud Virtualization using Microsoft ARM Azure, Infrastructure and Operation strategy planning for VM. DB, Security and Deployment planning
  • With several years of experience in information technology, with a focus on cybersecurity and Vulnerability management using SonarQube and application monitoring
  • Review and enhance configuration changes, firewall policies, DDoS protection, and client security posture to optimize ROI and network security control effectiveness
  • With Strong knowledge of data protection and disaster recovery processes, understanding of firewalls, proxies, SIEM, antivirus, and patch management concepts
  • I have ability to lead and motivate a team, and work well under pressure
  • Up-to-date knowledge of the latest security principles, techniques, firewall, tunneling and working of various protocols
  • Run daily scrum and triage QA bugs and review post release plan
  • Part of CAB team to approve RFC’s and involve in go-no-go decision making.
  • Setup Process template based on projects for different teams thru planning Release Train pipeline, work item types for bug fixes, enhancements and production support team
  • Experience in planning and implementation of automation pipelines
  • To support non-native Microsoft stack I was able to setup Atlassian tools sets such as Bit bucket, Jira and Confluence and can able to setup and integrate CICD with Jenkins, SQ and Deployment tools
  • Worked consistently with ServiceNow and Jira ticking tools
  • SonarQube Integration with VSTS, Jenkins for Code Check in, Build and Code Scan.
  • Worked closely with the functional, technical, business teams to meet release deadlines.
  • Creation/setup of new branch policies, check-in, check-out policies to mitigate delays in meeting release deadlines.
  • Training the new member on RM process and also setting up the application on their local machine.
  • Upgraded various CI/CD tools like Jenkins/JIRA using SDLC process and supported upgrading the software patches and worked with vendor for any issues to completion

Lead Microsoft technologist/DevOps

Teachie Brain Vendor
LAUSD/Herbal Life, LA
08.2016 - 11.2017
  • Managed multiple software releases and deployments across development, staging, and production environments.
  • Automated build and deployment processes using Jenkins, significantly reducing build times and improving the consistency of releases.
  • Worked with cross-functional teams to ensure accurate version control and release management processes, aligning with agile development practices.
  • Supported the migration of legacy build systems to modern tools and processes, improving release reliability and efficiency.
  • Monitored and troubleshot issues related to deployment pipelines, ensuring high system availability and stability during releases.
  • Coordinated on-site and off-shore team to meet deadlines to priorities Bug and Enhancement before release.
  • Coaching developers, DBA, Testing and BA team for Timely delivery of DevOps Strategy items.
  • With a proven track record in onboarding data and enhancing detection capabilities of Microsoft Sentinel or similar SIEM/SOAR platform.
  • Actively leading in conducting system tests and vulnerability audits
  • Participate and test incident response plan and mitigate risk management conducting audits
  • Conduct information security training and awareness programs
  • Ensure compliance with the changing laws and applicable regulations
  • Oversee vendor risk management including the review of vendor contracts
  • Report to executive management about the status of the information security program, security incidents and progress of the security improvement plan
  • Keep SOPs on latest intelligence, including hackers’ methodologies, in order to anticipate security breaches
  • Familiar with web protection technologies like FTPS, email gateways, firewalls, intrusion detection/prevention systems, and web application firewalls.
  • Excellent knowledge with JIRA, TFS other ALM, CI/CD tools and proficiency with MS Visio and rational rose for business model interpretation to real time scenario
  • Good understanding of scripting languages such as python, terraform, yaml, for creating build & CICD templates.
  • Worked closely with functional and release team to meet release deadlines.
  • Creation/setup of new branches based upon project requirements.
  • Training the new member on CM policies and also setting up the application on their local machine.
  • Created Batch/PowerShell Scripting for deploying the applications to different environments.
  • Responsible for installing window services and batch jobs on QA environments.
  • Set up websites, applications, app pools in the IIS including authentications & securities.
  • Detailed technical knowledge in security engineering, system and network security, authentication and security protocols, cryptography, and application security.
  • Created and maintaining “IT Security Champions” for each product area. Assist in the development & creation of risk assessments to drive direction, decisions and remediation.
  • Continuously assess the current state of security to recommend life cycle of security technologies.
  • Assist in defining the exception processes and making exception decisions.

System Analyst

Adams Comm & IT Sol
AUS
12.2009 - 11.2016
  • Develops and maintains the build environment, the source code control system and the issue tracking systems.
  • Creates and tests builds, resolves issues, applies labels to file and communicates build status.
  • Assist engineering management in making choices for source code management systems, and other development
  • I have developed and implemented security policies and procedures (P&Ps) and standard operating procedures (SOPs)
  • Conduct system tests and oversee vulnerability audits
  • Test an incident response plan and recovery procedures
  • Conduct information security training and awareness programs with vendors and Enterprise team
  • Ensuring and being in compliant with the changing laws and applicable regulations
  • Oversee vendor risk management including the review of vendor contracts
  • Report to executive management about the status of the information security program, security incidents and progress of the security improvement plan
  • Keeping up to date with the latest intelligence, including hackers’ methodologies, in order to anticipate security breaches

Education

Masters - Information Technology

University of New England (UNE)
NSW, Australia
01.2009

Bachelors - Electronic Engineer

Visvesvaraya Technological University (VTU)
Karnataka, India
01.2003

Skills

  • Technical skills: CI/CD, DevOps, App security, DevSecOps and Monitoring, CAB readiness, RFC specialist
  • Experience in DevOps Tools: GitHub, GitLab, ADO, AWS CodeCommit, CodeBuild and CodeDeploy, Jenkins, Maven, Nexus, Jfrog, Jfrog xray, SonarQube, Quality gate, Snyk, Vulcan, Jira Service Management, Azure KB, GitHub Action, Splunk, BMC Footprint Cloud version, Jira Service management, BI, Tableau

Accomplishments

  • Achieved implementing Java builds by setting up Maven projects for weblogic team with accuracy and efficiency.
  • Supervised Solution delivery team of 150+ developers moving out from local system build process to central build server by setting up enterprise builds servers working with system admin team
  • Moving existing business critical app to Acquia cloud platform for Drupal based applications
  • Collaborated with SAP team to payment portal in the development for CalHeer and PCP application

Certification

  • PMP Certified and ITIL
  • Azure DevOps Certification
  • SAFe Release Train Engineer Certified

Timeline

Release and Change Management

L.A Care Health Plan
12.2017 - Current

Lead Microsoft technologist/DevOps

Teachie Brain Vendor
08.2016 - 11.2017

System Analyst

Adams Comm & IT Sol
12.2009 - 11.2016

Bachelors - Electronic Engineer

Visvesvaraya Technological University (VTU)

Masters - Information Technology

University of New England (UNE)

Core Competencies

  • Leading DevOps/Release Management for automation process using advance tools and processes such as ITIL framework, Change Control, Change Advisory Board (CAB) management
  • Mentoring devops team and making sure adhere to DevOps practices thru Enterprise DevOps Hubs
  • Managing Azure DevOps and IDM access management, Worked with Azure DevOps setup for centralize versioning control storage, adopted various branching strategy that support Agile and work fall approach. Branching strategy to support Configuration management.
  • Setup Azure Kanban board to track work items and integrated with Jira.
  • Prosci ADKAR modeling in restructuring, implementing and bringing culture change in organization
  • Proven ability in integrating robust CI/CD Pipeline Design & Implementation using AWS services such as CloudFormation CodeCommit, CodePipeline, CodeBuild, CodeDeploy,CodeWatch, Lamda services and CloudWatch for monitoring purpose.
  • Build Systems (Jenkins, GitHub Action, Bamboo, TeamCity, GitLab CI)
  • Hands on working with SNYK, SonarQube for DAST and SAST integration and implementation for shift left approach
  • Hands on experience working with SBOM integration with Vulnerability management for tracking of software supply chain management for prioritizations, decision making and risk mitigation
  • Concept of SBOM derivatives such as Technical Dept, HBOM, OBOM and Vulnerability Disclosure report.
  • Work on Application security mitigation applying best practices of top 10 OWASP vulnerability framework, such as injection flaws, out of scope components and broken access.
  • Version Control Systems (GitHub, SVN, Perforce, Core Helix)
  • Planning, design, and implementation of robust Configuration Management
  • Delegating tasks, mentoring team members, and ensuring collaboration.
  • Good understanding on implementation of Agile & Scrum Methodologies
  • Monitoring & Troubleshooting, Cross-functional Team Collaboration and Performance Optimization
  • Expertise in Electronic Medical Record system with more than 80% reduction in Data error and clean data
  • Achieved process automation adhering to industry standards such as HIPAA, data security and governance.
  • Mitigating Risk and taking corrective action and ensuring security measures following administrative standard operating procedures to ensure software patch management timely completed with vendor management
  • Experienced in application technology security testing such as white box, black box and code review
  • Aware of Security Vulnerability defect fixing process.
  • Working knowledge on Amazon Web Services (AWS) resource, Azure, GCP, GitHub cloud technologies.
  • Help design secure application architectures and apply secure design principles and perform application vulnerability assessments
  • Analyze, assess, and respond to various security threats rain developers in secure coding practices.
  • Good understanding of the Medical Recording philosophy and contributed to automate our systems.
  • Experienced with Development, Staging to Production code build install from in software product development life cycle, implementation, and quality assurance, complete product cycles.
  • Installation and commissioning of SEIM tools such as AppInsight, AppDynamics, Splunk, ALM tools such as TFS, Azure Data , AWS CodeCommit, AWS CloudWatch and AWS CodePipeline.
  • Setting up Sonarqube and Quality gates to detect security hotspots and vulnerability to mitigate security risk using SNYK and Vulcan (remediation process)
  • Robust applicable knowledge on Agile method, Project Collections, Build Definitions, CTF, Release definitions, Kanban board, Work Items, SharePoint Portal, Reporting.
  • Extensive experience in using Continuous Integration tools like Cruise Control, Build Forge
  • Run daily scrum and triage QA bugs and review post release plan
  • Part of CAB team to approve RFC’s and involve in go-no-go decision making
  • Integrated Open-Source tools Jenkins with TFS, Octane, Jira and Service Now
Ashfak A. M