DevSecOps Engineer
Cloud Security & Infrastructure Architect
Certified DevSecOps Engineer specializing in enterprise-grade cloud security, container orchestration, and infrastructure automation. Proven expertise in architecting secure, compliant, and highly available systems for banking and government sectors. Focused on integrating security throughout the SDLC while maintaining deployment velocity and operational excellence.
About Me
Xin chao, I'm
I'm a DevSecOps engineer with deep expertise in building secure, scalable cloud infrastructure. Over the years, I've evolved from systems engineering to specializing in the intersection of development, security, and operations—helping organizations implement secure by default practices.
My focus is on designing and implementing cloud-native security architectures, hardening Kubernetes clusters, establishing secure CI/CD pipelines, and ensuring compliance with industry standards. I believe security should be embedded in every layer of the infrastructure, not bolted on as an afterthought.
I'm passionate about infrastructure as code, automation, and reducing security risks through proactive threat modeling and continuous security scanning. When not securing infrastructure, you'll find me contributing to security-focused open source projects or speaking about DevSecOps best practices.
Areas of Expertise
Cloud Security
Architecting defense-in-depth cloud security strategies across AWS, Azure, and GCP. Implementing zero-trust network architectures, advanced IAM policies with least privilege, encryption at rest/transit (KMS, CloudHSM), VPC security controls, and automated compliance monitoring (CIS benchmarks, NIST frameworks).
Kubernetes & Container Security
Expert in enterprise Kubernetes and Red Hat OpenShift administration and security hardening. Implementing Pod Security Standards, RBAC with fine-grained access controls, network policies (Calico, OVN-Kubernetes), image scanning pipelines, runtime security monitoring, and multi-tenancy isolation for production workloads.
Infrastructure as Code
Building immutable infrastructure with Terraform (multi-cloud state management), Ansible automation, AWS CloudFormation, and Helm chart templating. Implementing GitOps workflows with ArgoCD and Flux, policy-as-code validation (OPA, Sentinel), and drift detection for configuration compliance.
CI/CD Security
Designing secure CI/CD architectures with Jenkins (pipeline-as-code), GitLab CI/CD, GitHub Actions, and Tekton. Integrating SAST/DAST scanning (SonarQube, Black Duck, Coverity), dependency analysis, secrets management (HashiCorp Vault, AWS Secrets Manager), artifact signing, and policy enforcement gates.
Database Security
Securing enterprise databases (PostgreSQL, MySQL, MongoDB, RDS, DynamoDB) with TDE, column-level encryption, audit logging, network isolation, automated backup/restore strategies, and disaster recovery planning with RPO/RTO optimization for business continuity.
Compliance & Auditing
Ensuring regulatory compliance and security governance through automated controls. Experience with PCI-DSS, SOC 2, HIPAA, ISO 27001, and banking security standards. Implementing continuous compliance validation, vulnerability management programs, security information and event management (SIEM), and audit trail automation.
Technical Skills & Tools
Cloud Platforms
- AWS (EC2, ECS, EKS, Lambda, RDS)
- Azure (AKS, App Service)
- GCP (GKE, Cloud Run)
- OpenStack (On-Premise Cloud)
Container & Orchestration
- Red Hat OpenShift + Plus
- Red Hat OpenShift Virtualization
- Rancher RKE2/K3s
- Kubernetes
- Docker Compose
Infrastructure as Code
- Terraform
- Ansible
- CloudFormation
- Helm
- Kustomize
CI/CD & Automation
- Jenkins (Groovy)
- GitLab CI
- GitHub Actions
- ArgoCD
- Tekton
Security & Secrets
- HashiCorp Vault
- Kyverno
- Red Hat ACM & ACS
- SAST/DAST Tools
- Trivy
- Sonatype Nexus & IQ
- SonarQube
- Black Duck - Coverity
Monitoring & Logging
- Grafana Stack
- Prometheus
- ELK Stack
- Datadog
- Kafka
- CloudWatch
Languages & Scripting
- Bash
- Python
- Go
- TypeScript
- Groovy
- Solidity
Enterprise Tools
- IBM API Connect
- Sonatype Nexus & IQ
- SonarQube
- Black Duck - Coverity
- GitLab Enterprise/Ultimate
- VMware vSphere
- Red Hat OpenShift + Plus
- Red Hat OpenShift Virtualization
- Red Hat Advanced Cluster Management (RHACM)
- Red Hat Advanced Cluster Security (RHACS)
Professional Experience
DevSecOps Engineer
April 2024 - PresentVSI JSC
Leading enterprise DevSecOps initiatives for state-owned banks and government institutions. Architected and deployed production-grade OpenShift platforms serving 500+ containers. Designed secure CI/CD pipelines processing 200+ daily builds with integrated security scanning (SAST/DAST/SCA). Implemented HashiCorp Vault for centralized secrets management across multi-cluster environments. Reduced security vulnerabilities by 70% through automated policy enforcement and continuous scanning.
Head of Web R&D Department
June 2022 - March 2024Aimesoft
Managed cross-functional team of 12 engineers, establishing engineering best practices and technical standards. Drove adoption of modern development workflows, code review processes, and quality gates. Improved team velocity by 40% through process optimization and tooling automation. Mentored junior developers on secure coding practices and cloud-native architecture patterns.
DevOps Engineer
October 2021 - October 2023Aimesoft
Architected multi-region, highly available infrastructure on AWS and GCP supporting 99.9% uptime SLA. Designed and implemented GitOps-based CI/CD pipelines with GitLab CI and GitHub Actions, reducing deployment time from hours to minutes. Established infrastructure-as-code standards with Terraform modules, enabling consistent environment provisioning. Managed Kubernetes clusters (EKS, GKE) with 50+ microservices in production.
Intern DevOps Engineer
June 2021 - August 2021OSAM.IO
Gained foundational experience in cloud infrastructure and DevOps practices. Assisted in container orchestration with Docker and Kubernetes, implemented CI/CD pipelines using Jenkins and ArgoCD, and supported multi-cloud deployments across AWS, GCP, and OpenStack environments.
Ready to Secure Your Infrastructure?
Whether you need a security audit, help implementing DevSecOps practices, or building a secure cloud infrastructure from scratch, I'm here to help.
Start a Project