Senior DevOps Engineer
I build and document practical infrastructure work through projects, technical writing, and operational notes from real-world DevOps experience.
Open to freelance, contract, part-time, and consulting collaborations.
2
6
Wazuh Ansible Series
Focus Areas
Areas I work on across infrastructure, platform engineering, automation, operations, and compliance-ready environments.
AWS/GCP infrastructure, Terraform, DNS, SSL, environment separation, and platform reliability.
Kubernetes, EKS/GKE, Helm, ArgoCD, ingress, cert-manager, and platform standardization.
GitHub Actions, Jenkins, Docker workflows, Ansible automation, deployment and rollback flows.
Prometheus, Grafana, Loki, logging, metrics, alerts, runbooks, and operational visibility.
Access controls, logging, monitoring, backup, documentation, and audit evidence preparation for ISO 27001, PCI DSS, and financial-company requirements.
Selected Projects
Infrastructure, automation, and platform work from real-world DevOps projects and experiments.
A Wazuh-based security monitoring and compliance operations offering focused on audit readiness, repeatable deployment, alert tuning, malware detection, and operational guardrails for ISO 27001, PCI DSS, and similar control-heavy environments.
A reusable centralized DAST project with OWASP ZAP, Nuclei, and OPA policy logic, offering consistent PASS/WARN/FAIL policies, audit-ready artifacts, PR summaries, and a reusable GitHub Actions workflow for dynamic security testing.
Infra Notes
Small operational notes for issues that are easy to forget and expensive to debug twice.
Audit evidence becomes easier when logging, monitoring, backup, restore testing, and access control are part of the infrastructure design from the beginning.
A backup is only useful if the restore path has been tested, documented, and validated against the expected recovery scenario.
Access reviews become harder when IAM users, roles, groups, policies, and permission sets are named without a clear convention.
Technical Writing
Long-form articles and implementation notes around DevOps, Kubernetes, cloud infrastructure, automation, observability, and compliance-ready systems.
A Wazuh-by-Ansible implementation track covering deployment, SAML, manager and agent configuration, rule tuning, ClamAV, YARA, index backup automation, and Zeek telemetry integration.
How to install Zeek on selected hosts, collect JSON logs with the Wazuh agent, and promote them into custom network-security rules.
How I backed up Wazuh index data to Google Cloud Storage, kept snapshots for 9 days, and trimmed live index data to 7 days with three small moves.
Experience Snapshot
A quick view of the environments, tools, and operational scope behind the work.
6+ years working across DevOps, cloud infrastructure, Kubernetes, CI/CD, observability, automation, and compliance-related environments.
Hands-on with AWS, GCP, Kubernetes, Terraform, Ansible, Jenkins, ArgoCD, Prometheus, Grafana, Loki, Wazuh, and Cloudflare.
Experienced in production, pre-production, sandbox, PCI DSS, and compliance preparation environments.
Talks & Community
Public sessions, CFPs, and community sharing around DevOps, Kubernetes, GitOps, cloud infrastructure, and open-source tools.
Jan 22, 2026
Kubernetes Cloud Native Online Meetup January 2026
Dive into the common challenges faced when using managed Kubernetes services like EKS and GKE, and learn practical solutions to overcome them.
May 27, 2025
Kubernetes Cloud Native Offline Meetup August 2025
Explore how to implement Keycloak for authentication in internal tools, enhancing security and user experience.
Interested in collaborating?
I'm open to freelance, part-time, contract, and consulting opportunities around cloud infrastructure, cloud security, Kubernetes, automation, observability, and compliance-ready systems.