DevSecOps Engineer

Cloud Security & Infrastructure Architect

Certified DevSecOps Engineer specializing in enterprise-grade cloud security, container orchestration, and infrastructure automation. Proven expertise in architecting secure, compliant, and highly available systems for banking and government sectors. Focused on integrating security throughout the SDLC while maintaining deployment velocity and operational excellence.

About Me

Xin chao, I'm 

I'm a DevSecOps engineer with deep expertise in building secure, scalable cloud infrastructure. Over the years, I've evolved from systems engineering to specializing in the intersection of development, security, and operations—helping organizations implement secure by default practices.

My focus is on designing and implementing cloud-native security architectures, hardening Kubernetes clusters, establishing secure CI/CD pipelines, and ensuring compliance with industry standards. I believe security should be embedded in every layer of the infrastructure, not bolted on as an afterthought.

I'm passionate about infrastructure as code, automation, and reducing security risks through proactive threat modeling and continuous security scanning. When not securing infrastructure, you'll find me contributing to security-focused open source projects or speaking about DevSecOps best practices.

Areas of Expertise

Cloud Security

Architecting defense-in-depth cloud security strategies across AWS, Azure, and GCP. Implementing zero-trust network architectures, advanced IAM policies with least privilege, encryption at rest/transit (KMS, CloudHSM), VPC security controls, and automated compliance monitoring (CIS benchmarks, NIST frameworks).

Kubernetes & Container Security

Expert in enterprise Kubernetes and Red Hat OpenShift administration and security hardening. Implementing Pod Security Standards, RBAC with fine-grained access controls, network policies (Calico, OVN-Kubernetes), image scanning pipelines, runtime security monitoring, and multi-tenancy isolation for production workloads.

Infrastructure as Code

Building immutable infrastructure with Terraform (multi-cloud state management), Ansible automation, AWS CloudFormation, and Helm chart templating. Implementing GitOps workflows with ArgoCD and Flux, policy-as-code validation (OPA, Sentinel), and drift detection for configuration compliance.

CI/CD Security

Designing secure CI/CD architectures with Jenkins (pipeline-as-code), GitLab CI/CD, GitHub Actions, and Tekton. Integrating SAST/DAST scanning (SonarQube, Black Duck, Coverity), dependency analysis, secrets management (HashiCorp Vault, AWS Secrets Manager), artifact signing, and policy enforcement gates.

Database Security

Securing enterprise databases (PostgreSQL, MySQL, MongoDB, RDS, DynamoDB) with TDE, column-level encryption, audit logging, network isolation, automated backup/restore strategies, and disaster recovery planning with RPO/RTO optimization for business continuity.

Compliance & Auditing

Ensuring regulatory compliance and security governance through automated controls. Experience with PCI-DSS, SOC 2, HIPAA, ISO 27001, and banking security standards. Implementing continuous compliance validation, vulnerability management programs, security information and event management (SIEM), and audit trail automation.

Technical Skills & Tools

Cloud Platforms

  • AWS (EC2, ECS, EKS, Lambda, RDS)
  • Azure (AKS, App Service)
  • GCP (GKE, Cloud Run)
  • OpenStack (On-Premise Cloud)

Container & Orchestration

  • Red Hat OpenShift + Plus
  • Red Hat OpenShift Virtualization
  • Rancher RKE2/K3s
  • Kubernetes
  • Docker Compose

Infrastructure as Code

  • Terraform
  • Ansible
  • CloudFormation
  • Helm
  • Kustomize

CI/CD & Automation

  • Jenkins (Groovy)
  • GitLab CI
  • GitHub Actions
  • ArgoCD
  • Tekton

Security & Secrets

  • HashiCorp Vault
  • Kyverno
  • Red Hat ACM & ACS
  • SAST/DAST Tools
  • Trivy
  • Sonatype Nexus & IQ
  • SonarQube
  • Black Duck - Coverity

Monitoring & Logging

  • Grafana Stack
  • Prometheus
  • ELK Stack
  • Datadog
  • Kafka
  • CloudWatch

Languages & Scripting

  • Bash
  • Python
  • Go
  • TypeScript
  • Groovy
  • Solidity

Enterprise Tools

  • IBM API Connect
  • Sonatype Nexus & IQ
  • SonarQube
  • Black Duck - Coverity
  • GitLab Enterprise/Ultimate
  • VMware vSphere
  • Red Hat OpenShift + Plus
  • Red Hat OpenShift Virtualization
  • Red Hat Advanced Cluster Management (RHACM)
  • Red Hat Advanced Cluster Security (RHACS)

Professional Experience

DevSecOps Engineer

April 2024 - Present

VSI JSC

Leading enterprise DevSecOps initiatives for state-owned banks and government institutions. Architected and deployed production-grade OpenShift platforms serving 500+ containers. Designed secure CI/CD pipelines processing 200+ daily builds with integrated security scanning (SAST/DAST/SCA). Implemented HashiCorp Vault for centralized secrets management across multi-cluster environments. Reduced security vulnerabilities by 70% through automated policy enforcement and continuous scanning.

JenkinsGitLab CIVaultKubernetesOpenShiftTerraformAWSSonarQubeRHACMRHACS

Head of Web R&D Department

June 2022 - March 2024

Aimesoft

Managed cross-functional team of 12 engineers, establishing engineering best practices and technical standards. Drove adoption of modern development workflows, code review processes, and quality gates. Improved team velocity by 40% through process optimization and tooling automation. Mentored junior developers on secure coding practices and cloud-native architecture patterns.

LeadershipProject ManagementWeb DevelopmentMentoring

DevOps Engineer

October 2021 - October 2023

Aimesoft

Architected multi-region, highly available infrastructure on AWS and GCP supporting 99.9% uptime SLA. Designed and implemented GitOps-based CI/CD pipelines with GitLab CI and GitHub Actions, reducing deployment time from hours to minutes. Established infrastructure-as-code standards with Terraform modules, enabling consistent environment provisioning. Managed Kubernetes clusters (EKS, GKE) with 50+ microservices in production.

AWSGCPKubernetesEKSCI/CDGitLabGitHub ActionsTerraformPrometheusGrafana

Intern DevOps Engineer

June 2021 - August 2021

OSAM.IO

Gained foundational experience in cloud infrastructure and DevOps practices. Assisted in container orchestration with Docker and Kubernetes, implemented CI/CD pipelines using Jenkins and ArgoCD, and supported multi-cloud deployments across AWS, GCP, and OpenStack environments.

AWSGCPOpenStackDockerKubernetesJenkinsArgo CD

Ready to Secure Your Infrastructure?

Whether you need a security audit, help implementing DevSecOps practices, or building a secure cloud infrastructure from scratch, I'm here to help.

Start a Project