Senior DevOps Engineer

Senior DevOps Engineer working across cloud infrastructure, Kubernetes, automation, observability, and compliance-ready systems.

I build and document practical infrastructure work through projects, technical writing, and operational notes from real-world DevOps experience.

Open to freelance, contract, part-time, and consulting collaborations.

Active initiatives
Open-source-friendly stacks and compliance guardrails

2

Experience horizon
Years shipping DevOps programs

6

Latest post
Jul 3, 2026

Wazuh Ansible Series

Focus Areas

Focus Areas

Areas I work on across infrastructure, platform engineering, automation, operations, and compliance-ready environments.

Cloud Infrastructure

AWS/GCP infrastructure, Terraform, DNS, SSL, environment separation, and platform reliability.

Kubernetes & Platform Engineering

Kubernetes, EKS/GKE, Helm, ArgoCD, ingress, cert-manager, and platform standardization.

Automation & CI/CD

GitHub Actions, Jenkins, Docker workflows, Ansible automation, deployment and rollback flows.

Observability & Operations

Prometheus, Grafana, Loki, logging, metrics, alerts, runbooks, and operational visibility.

Compliance-Ready Infrastructure

Access controls, logging, monitoring, backup, documentation, and audit evidence preparation for ISO 27001, PCI DSS, and financial-company requirements.

Selected Projects

Selected Projects

Infrastructure, automation, and platform work from real-world DevOps projects and experiments.

View all projects
Wazuh Compliance Operations – Security Monitoring for Audit-Ready Environments
Consulting Offer

A Wazuh-based security monitoring and compliance operations offering focused on audit readiness, repeatable deployment, alert tuning, malware detection, and operational guardrails for ISO 27001, PCI DSS, and similar control-heavy environments.

WazuhISO 27001PCI DSSComplianceSIEMAnsible
Security DAST – Centralized Dynamic Application Security Testing
Publish

A reusable centralized DAST project with OWASP ZAP, Nuclei, and OPA policy logic, offering consistent PASS/WARN/FAIL policies, audit-ready artifacts, PR summaries, and a reusable GitHub Actions workflow for dynamic security testing.

DASTGitHub ActionsCentralized SecurityCompliance

Infra Notes

Infra Notes

Small operational notes for issues that are easy to forget and expensive to debug twice.

Read notes
Compliance
Compliance evidence is easier when logging and backup are designed early

Audit evidence becomes easier when logging, monitoring, backup, restore testing, and access control are part of the infrastructure design from the beginning.

ComplianceISO 27001PCI DSS
Operations
Backup exists, but restore was never tested

A backup is only useful if the restore path has been tested, documented, and validated against the expected recovery scenario.

BackupRestoreReliability
Cloud Security
Access review is painful when IAM naming is not standardized

Access reviews become harder when IAM users, roles, groups, policies, and permission sets are named without a clear convention.

IAMAccess ReviewCloud Security

Technical Writing

Technical Writing

Long-form articles and implementation notes around DevOps, Kubernetes, cloud infrastructure, automation, observability, and compliance-ready systems.

Read blog
Wazuh Ansible Series

A Wazuh-by-Ansible implementation track covering deployment, SAML, manager and agent configuration, rule tuning, ClamAV, YARA, index backup automation, and Zeek telemetry integration.

SecurityAnsibleWazuh
Wazuh Ansible Series Part 11: Zeek Network Telemetry into Wazuh

How to install Zeek on selected hosts, collect JSON logs with the Wazuh agent, and promote them into custom network-security rules.

WazuhCloud SecurityAnsible
Wazuh Ansible Series Part 10: Automating Wazuh Indexer Backups to Google Cloud Storage

How I backed up Wazuh index data to Google Cloud Storage, kept snapshots for 9 days, and trimmed live index data to 7 days with three small moves.

WazuhAnsibleDevOps

Experience Snapshot

Experience Snapshot

A quick view of the environments, tools, and operational scope behind the work.

View experience

6+ years working across DevOps, cloud infrastructure, Kubernetes, CI/CD, observability, automation, and compliance-related environments.

Hands-on with AWS, GCP, Kubernetes, Terraform, Ansible, Jenkins, ArgoCD, Prometheus, Grafana, Loki, Wazuh, and Cloudflare.

Experienced in production, pre-production, sandbox, PCI DSS, and compliance preparation environments.

Talks & Community

Talks & Community

Public sessions, CFPs, and community sharing around DevOps, Kubernetes, GitOps, cloud infrastructure, and open-source tools.

View talks

Jan 22, 2026

Kubernetes, As It Turns Out: Understanding Common Issues in EKS & GKE

Kubernetes Cloud Native Online Meetup January 2026

Dive into the common challenges faced when using managed Kubernetes services like EKS and GKE, and learn practical solutions to overcome them.

KubernetesEKSGKETroubleshooting

May 27, 2025

Auth That Works: Building Seamless Login Experiences for Internal Tools with Keycloak

Kubernetes Cloud Native Offline Meetup August 2025

Explore how to implement Keycloak for authentication in internal tools, enhancing security and user experience.

KeycloakOpensourceAuthenticationAuthorization

Interested in collaborating?

Interested in collaborating?

I'm open to freelance, part-time, contract, and consulting opportunities around cloud infrastructure, cloud security, Kubernetes, automation, observability, and compliance-ready systems.