DevOps/DevSecOps Engineer with strong experience supporting regulated industries, cloud environments, and secure CI/CD automation. Proven track record delivering high‑availability platforms for financial services, healthcare, and enterprise IT. Skilled in Kubernetes, Terraform, GitOps, cloud security, SCA (Software Composition Analysis), SBOM generation, and compliance frameworks (ISO 27001, SOC2, GDPR, CSSF expectations).
Multilingual (EN/DE/FR) with leadership experience across cross‑functional teams. Known for reliability, incident ownership, and building secure, automated, and scalable infrastructure.
Designed and deployed a production‑grade Kubernetes platform (EKS/AKS) with full GitOps automation. Implemented ArgoCD, Helm, and Terraform modules to standardize infrastructure provisioning across environments. Integrated OPA/Kyverno for policy enforcement, RBAC hardening, Pod Security Standards, and network policies. Built an observability stack using Prometheus, Grafana, Loki, and OpenTelemetry, reducing MTTR by 40%. Automated CI/CD pipelines with GitHub Actions and GitLab CI, enabling fully declarative and secure application delivery.
Key technologies: Kubernetes, Docker, Terraform, Ansible, ArgoCD, Helm, OPA/Kyverno, Datadog, Grafana Stack ( Prometheus, Loki, Tempo ), GitLab CI, Jenkins.
Led the modernization of enterprise CI/CD pipelines by integrating DevSecOps controls including SAST, DAST, SBOM generation, dependency scanning, and container vulnerability scanning (Trivy, Snyk, SonarQube). Implemented secrets management using HashiCorp Vault and AWS Secrets Manager. Used AWS KMS to auto-unseal Hashicorp Vault, Automated compliance checks using OPA. Reduced critical vulnerabilities by 80% and improved deployment reliability through automated testing, artifact signing, and environment promotion workflows.
Key technologies: GitLab CI, Jenkins, Trivy, Snyk, SonarQube, Vault, AWS Secrets Manager, AWS KMS, OPA, SBOM.
Developed reusable Terraform modules to provision standardized infrastructure across AWS, including networking, compute, IAM. Implemented automated cost‑monitoring dashboards and alerting using CloudWatch. Migrated legacy workloads to containerized microservices, reducing cloud spend by 30%. Integrated Ansible for configuration management and automated environment bootstrapping and scaffolding.
Key technologies: Terraform, Ansible, AWS, AWS CloudWatch, Docker, microservices.
Spoken Languages:
Hobbys