Sr. Devsecops Engineer Resume
Billerica, MA
SUMMARY
- Over 10+ years of experience as a System Engineer, worked on AWS, AZURE services, CI/CD pipeline, Build/release management and VMware technologies.
- Administration of Production, Development and Test environment’s carrying Red hat Linux, SUSE Linux, CentOS, and Solaris and HP - UX servers.
- Expertise in Installation, Support, Configuration, Red Hat Enterprise Linux (RHEL) 4,5,6,7,8 Oracle Enterprise Linux (OEL) 5,6,7,8 SUSE Enterprise Linux Server 10,11,12, SOLARIS 9, 10,11 and UBUNTU 10, 12, & 14 LTS, IBM AIX 5,6.
- Expertise in Agile framework such as Scrum, Kanban and Waterfall methods in software development lifecycle (SDLC).
- Experience on troubleshooting Network, memory, CPU, Swap space, File system issues, TCP/IP, NFS, DNS and SMTP in Linux servers.
- Experience Configuring and maintaining virtual server environment using VMware ESX/ESXi, VCenter, and vSphere.
- Installing OpenShift through IPI and UPI Methods.
- Played a pivot role in implementing DevSecOps Model across the organization, platform and implemented vulnerability checks at different phases.
- Experience in DevSecOps strategy for security auditing, continuous monitoring of the entire infrastructure and applied Web Application Firewall (WAF) rules for blocking the attacks through SQL injection and patterns.
- Hands-on implementation experience wif Google Cloud Platform (GCP) Services
- Experience wif Big Data on GCP Big Query, Pub/Sub, Datapost, Dataflow, Composer env, IAM.
- Experience hosting an application on GCP using Compute Engine, App Engine, Cloud SQL, Kubernetes Engine, Cloud Storage
- Experience in Azure ELT tools Azure Data Factory and Azure Data Lake.
- Good understanding of OpenShift platform in managing Docker containers and Kubernetes Clusters.
- Worked wif Azure Data Factory components like Pipelines, Linked Service, Triggers and Control Flow.
- Experience in Monitoring the Azure Cloud Resources through Application Insights.
- Experience in Creating Integration Runtime like Azure, self-hosted, Azure-SSIS and shared self-hosted in Azure Data factory.
- Worked wif installation and configuration of Docker environment including Docker registry hub for managing different Docker images and deployment of applications inside the software containers.
- Experience wif creating private cloud using Kubernetes that supports DEV, TEST, and PROD environments.
- Hands on experience in writing Terraform API modules to manage infrastructure, for automatic creation of AWS services like RDS instances, VPCs, Autoscaling groups, Load balancers, SQS, S3 buckets.
- Experience in Docker container orchestration framework using Kubernetes to create pods, Config Maps and deployments into cluster. Containerized legacy Java and Nodejs application, run it in AWS ElasticKubernetes Service. Auto-scaled the application in both pods level and instance level.
- Proficient on Terraform key features such as Infrastructure as code, execution plans, resource graphs, change automation and created infrastructure to deploy various applications across multiple cloud providers.
- Worked wif OpenShift Machine Sets and Red hat Core OS RHCOS.
- Experience on Installing, configuring, and maintaining application servers like JBOSS, Tomcat, Apache Web server, WebSphere, Web logic, Oracle, Samba Servers.
- Worked on integrating GIT, Bitbucket, TFS, SVN wif Jenkins/Bamboo and scheduling jobs by using Poll SCM and integrated in code checkout processes.
- Expertise in Monitored the systems and administered Servers for day-to-day problems, patches, useradministration and hardware failure, monitoring log files,backup, software upgradation, configuration changes and documentation.
- Monitoring RHEL 7/centos servers wif command line monitoring tools such as top, htop, lsof, iOS tat, iotop, tcpdump, sysstat (SAR), Splunk and Nagios.
- Experience on Installed and Configured Monitoring and Ticketing Tools like Nagios, Splunk, ELK, AWS Cloud Watch, Service Now, Jira.
- Experience wif Azure Service Bus Queues.
- Expertise in Installation, Configuration Data Base Servers like MySQL, MariaDB, PostgreSQL, MongoDB (NOSQL), Oracle DB on various Linux distributions.
- Worked wif Ngnix, HAProxy, F5 load balancers that improve the overall performance of applications by decreasing the burden on servers associated wif managing and maintaining application and network sessions, switching, routing and VPN's.
- Experience in creatingDocker Containersleveraging existing Linux Containers and AMI's in addition to creatingDocker Containersfrom scratch.
- Experience in working wif Agile practices using CI/CD pipelines, wif Jenkins/Bamboo (Continuous Integration), Nexus for Maven Repository, Maven Builds, Artifactory, Junit testing, Ansible playbooks tests and deployments using multiple Jenkins’s plugins.
- Worked on Hashi CorpVaultsecrettool to provide security for credentials, tokens and API keys.
- Implementation of cloud services IAAS, PAAS, and SaaS, which include AWS and Docker.
- Experience wif CDN Content Delivery Network using Akamai
- Expertise in using Puppet Dashboard and Puppet DB for configuration management to existing infrastructure.
- Expertise in adding Service Mesh, a dedicated infrastructure layer for communication between Kubernetes microservices and balances inter-service traffic upon specific policies.
- Experience in OpenShift platform in managing Docker Containers, Kubernetes Clusters, Ingress Rules, Services and Helm Charts and implemented a production ready, load balanced, highly available, fault tolerant Kubernetes infrastructure.
- Experienced in Installing, Configured and management in Ansible Centralized Server and creating the playbooks to support various middleware application servers, and involved in configuring the Ansible tower as a configuration management tool to automate repetitive tasks.
- Experience in designing and deploying of applications utilizing almost all the AWS stack including EC2, Route53, S3, RDS, Dynamo DB, SNS, SQS, LAMDA, focusing on high-availability, fault tolerance and auto-scaling in AWS cloud formation.
TECHNICAL SKILLS
Operating Systems: RHEL 4/5/6/7, CENTOS 4/5/6/7, SUSE 10/11/12, Solaris 11/10/9IBM AIX 5/6, HPUX11i V1/V2/V3, OEL 5/6, Ubuntu 10/12/14Windows NT 2000/2003/2008.
Cloud Platforms: AWS, Azure
Hardware: Dell PowerEdge 6950/M-series, Sun servers DRAC, HP Blade enter C-7000 series, BL460, Dl585, DL380 ILO MANAGEMENT, IBM Blade enter HS-series/x-series, CISCO 6500 series Switches, EMC, NetApp SAN and NAS.
Networking Tools: TCP/IP, HTTP/HTTPS, Basic cable crimping, Ethernet, net stat, NFS, NIS.
Databases: MySQL, MariaDB, PostgreSQL, MongoDB (NOSQL), Oracle DB 10g, 11g.
Automation Tools: Puppet, Chef, Ansible, Terraform, Jenkins, Cloud Foundry, Docker, Kubernetes, JFrog
Web Server: Apache Tomcat 5/6/7, APACHE 2, JBoss 4/5, Web Logic 8/9/10 & Web Sphere 4/5/7/8
Languages/Scripts: Shell, Perl, Python, Ruby, Json, Yaml.
Version Control: Git, GitHub, Atlassian Stash, Bitbucket, TFS, Gitlab, CVS, SVN.
Virtualization Technologies: VMware ESXi, Virtual box, Vagrant, KVM, Amazon Web Services, OpenStack, Docker.
File Systems: UFS, Vxfs, ZFS, ext., ext2, ext3, ext4, NFS, NAS.
Ticketing/Monitoring tools: JIRA, Remedy, HP Service Manager, IBM ServiceNow, Splunk, NagiosAWS Cloud watch, ELK.
PROFESSIONAL EXPERIENCE
Confidential, Billerica, MA
Sr. DevSecOps Engineer
Responsibilities:
- Involved in Implementing and Configuring of variousAWScloud services like EC2, S3, RDS (MySQL), Elastic Load Balancing (ELB), Elastic Block Storage (EBS), Cloud Watch, SNS, SQS, Route53, Dynamo DB, LAMDA, REDSHIFT, AMI, IAM, VPC.
- Configured Identity Access Management (IAM) policies for users belonging to different teams and involved in Implementation of Virtual cloud platforms using Amazon Virtual Private Cloud (VPC).
- Supported AWS Cloud environment wif multiple AWS instances and configured Elastic IP & Elastic Storage and experience working on implemented security groups and NACL’s.
- Written Policy-as-code using Terraform Sentinel.
- Setup Bastion Hosts to connect to private instances inside the VPC so that communication goes between private instances to the internet by creating NAT gateways and Azure Bastion.
- Building CI/CD pipelines in OpenShift Using Tekton pipelines.
- Involved in the migration of Multiple application from on prem to Google cloud (GCP)
- Involved in provide IAM, dataset access and GS bucket level access to service account and AD group on GCP.
- Used AWS Beanstalk for deploying and scaling web applications and services developed wif Java.
- Transformed Terraform as an enterprise level cloud infrastructure automation solution by maintaining prewritten cloud formation scripts and converting Python BOTO3 CLI scripts as a custom wrapper in terraform null resources.
- Deploying Azure Paas services like azure data factory and azure data lakes using ARM templates via Azure Devops Pipelines.
- Provisioned the AWS App Mesh for network traffic controls on EC2 instances, ECS, EKS, AWS Fargate and integrated monitoring tool cloud watch to automatically export the data to Splunk and Kibana.
- Monitoring and alerting of applications deployed in AWS using Cloud Watch, Cloud Trail and Simple Notification Service (SNS).
- Integrated Service Now wif Splunk to get the alerts and raise tickets wif service now.
- Experience wif configuring and supporting Red hat OpenShift Cluster 3.x, 4.x
- Develop ARM templates to automate the provisioning and deployment process in Azure.
- Configured terraform wif Jenkins in the AWS, tan integrated Jenkins wif GitHub for continuous integration using web-hooks and used Ansible in AWS- OPS works for continuous deployment by utilizing code build and code deploy.
- Experience wif configuring Persistent Storage in Red hat OpenShift Cluster 3.x, 4.x
- Experience in integrating Team city CI pipeline to Octopus CD deployments.
- Integrated Docker container-based test infrastructure to Jenkins CI/CD test flow and executed build environment by integrating wif Jira to trigger builds using Webhooks and Slave Machines.
- Worked on load balancers like HAProxy, Ngnix and AWS ELB for load-balancing the API calls and configured SSL certificates for production and wed application servers.
- Deploy and Monitor Scalable Infrastructure on AWS using Cloud formation templates/Terraform wif Configuration Management Ansible and Cloud watch.
- Publishing and promoting the build version to Octopus environments.
- Deployed and configured Elastic search, Logstash and Kibana (ELK) using Ansible for log analytics, full text search, application monitoring in integration wif AWS Lambda and Cloud Watch.
- Worked wif Red hat OpenShift cluster cli, oc cli.
- Deploying Iaas and Paas services using Infrastructure as a code IaC Terraform
- Involved in Configuration Automation and Centralized Management wif Ansible and Implemented Ansible to manage all existing servers and automate the build/configuration of new servers.
- Maintained complex applications Cloud Formation IaC stacks using Terraform and provided generic modules to support Immutable deployments thereby converted terraform as enterprise Infra automation tool and used Terraform Graphs to visualize TF plans.
- Involved in writing various Custom Ansible Playbooks for application stack deployment and developed Ansible Playbooks to simplify and automate day-to-day server administration tasks.
- Automating Day-to-day tasks using Ansible Tower, creating Job Templates for pipelines.
- Administering red hat OpenShift Cluster 3.x, managing projects, pods, setting Quotas
- Experience in Creating and Managing Azure Resource Groups, VMSS, Availability Set, Storage Accounts, Virtual Networks and App Services.
- Configured V-Nets and NSG’s inbound and outbound firewall rules to enforce the security of the Azure cloud VM’s
- Experience in managing Azure Web Apps, Websites, Web role and Worker roles and Deployment Slots.
- Worked wif Ansible Tower dashboard to customize and schedule jobs, configure adhoc job runs, inventory updates, playbook runs and job activities.
- Experience in Registering the Apps to Azure AD Active Directory and creating Service TEMPPrincipals.
- Creating pipelines in Team city for automated Builds
- Experience working on Docker hub, creating Docker images, for middleware installations and domain configuration.
- Installing Kubernetes on Azure cloud platform using AKS wif ARM templates customization.
- Managed docker cluster using Kubernetes wif Http basic autantication for Kubernetes server API calls. Used Kubernetes modules in ansible playbooks to create container name spaces in existing Docker cluster.
Environment: AWS, Azure, RHEL, CentOS, Ubuntu, SUSE, Windows 2008, 2012, Solaris 10, Oracle Linux 6.3, 6.5, Logical Volume Manager, VM ESX 3.x/2.x, TCP/IP, NFS, DNS, SMTP, PostgreSQL, MySQL, JAVA, Ansible, Docker, Kubernetes, Jenkins, Maven, Git Atlassian Stash, AWS, LAN, Middleware Application, Servers.
Confidential, MD
Sr. AWS Devops/ Cloud Engineer
Responsibilities:
- Worked wif Cloud infrastructure based of VPC, EC2, Route53, S3, RDS, Dynamo DB, SNS, SQS, Lambda, Redshift, Network ACLs, ELB, NLB, Autoscaling, IAM on AWS using Cloud formation templates and Terraform.
- Used AWS Faregate in collaboration wif AWS ECS and AWS EKS for container-based application running to provide high security and reliability.
- Implemented DevSecOps wif Jenkins to reduce threats, vulnerabilities and performed risk assessments to detect and analyze threats during the CI/CD process.
- Implemented Security Scans like Static and Dynamic Application testing at each layer of DevOps life cycle and converted the existing DevOps methodologies/workflows to DevSecOps model.
- Worked on AWS CloudWatch, CloudFormation, Cloud Trail services and CloudFront to set up and manage cached content delivery.
- Worked on Terraform Template key features such as Infrastructure as a code, Execution plans, Resource Graphs, Change Automation and extensively used Auto Scaling launch configuration templates for launching Amazon EC2 instances while deploying microservices.
- Used Terraform for creating stacks of VPCs, ELBs, Security groups, SQS queues, S3 buckets in AWS and updated the Terraform Scripts based on the requirement on regular basis.
- Implemented cluster services usingDockerand Kubernetes to manage local deployments by building a self-hosted Kubernetes cluster using Terraform and Ansible.
- Responsible for writing reusable Infrastructure as a Code (IaC) Modules by using Terraform for IaaS, PaaS and SaaS AWS cloud resources and mentoring the peers to write consumable code to automate the infrastructure provisioning for cloud applications.
- Created function in Lambda that aggregates the data from incoming events, tan stored result data in Amazon DynamoDB and S3.
- Expertise in using Boto3 python libraries integrating wif Ansible and Terraform for Managing EBS volumes and scheduling Lambda functions for AWS tasks.
- Integrated Kubernetes wif network, storage, and security to provide comprehensive infrastructure and orchestrated containers across multiple hosts.
- Migrating existing AWS infrastructure to Serverless Architecture (AWS Lambda) by deploying Terraform (Iac) code from GitHub repositories to implement AWS Lambda functions to run scripts in response to CloudWatch events in the Amazon DynamoDB table and S3 bucket to HTTP requests using Amazon API gateway and AWS SDK’s.
- Used Jenkins Pipelines to drive all Microservices builds out to the Docker-registry and tan deployed to Kubernetes, Created Pods and managed using Kubernetes.
- Developed Kubernetes Config files for load testing of applications and gave insights to teams using Dynatrace.
- Developed dashboards and alarms on Dynatrace to understand behavior/state of Microservices, help understanding the possible source of the problem and prevent outages.
- Created Terraform templates for provisioning AWS resources and used Terraform graph to visualize execution plan.
- Used Terraform to deploy the infrastructure necessary to create development, test, and production environments for software development projects.
- Worked wif Red hat OpenShift wif S2I builds for different application containerization, Image Streams wif integrated Docker registry, Routes, OpenShift templates for application deployments as per the application requirements and demands.
- Worked wif Ceph Storage Cluster as Storage Class and RGW in Red hat OpenShift for Persistent Volumes and Claims for EFK, MySQL and PostgreSQL State full Sets and Other Application persistence requirements.
- Installed AppDynamics controller and agents on VMs and physical servers.
- Responsible for installing Jenkins’s master and slave nodes and involved in plugin Git and schedule jobs using hooks and Creating the build scripts using Maven for Java projects.
- Configuring, automation and maintaining build and deployment CI/CD tools Git/GitLab, Jenkins, Bit Bucket, Docker Registry, Nexus, and JIRA for Multi-Environment.
- Worked on writing multiple Python, Shell scripts for internal applications for various organizational tasks.
Environment: AWS EC2, S3, EBS, VPC, Elastic search, Route53 (DNS), API Gateway, Hashi Corp, Cloud Formation, Dynamo DB, RDS, Redshift, SNS, Kubernetes, Ansible, Maven, Jenkins, Docker, Terraform, Shell scripts, Python, Git, GitHub, Jira.
Confidential, San Francisco, CA
Devops Engineer
Responsibilities:
- Build, manage, and continuously improved the build infrastructure for global software development engineering teams including implementation of build scripts, continuous integration infrastructure and deployment tools.
- Built environment in AWS using EC2 instance creation, Route 53 DNS routing, Cloud Watch alarming, VPC setups, AWS Elastic Load Balancing, Auto Scaling groups and databases like RDS, DynamoDB and networking services like Route53, Direct Connect.
- Worked on Amazon Web Services (AWS) cloud platform and services like Lambda, DynamoDB, EBS, ELB, AMI, Elastic Beanstalk, CloudFront, CloudWatch, Ops Work SNS, Glacier, Auto-Scaling, IAM, Route53, EC2, S3, RDS, VPC, VPN, Security-Groups and through AWS management console.
- Installed and configured red hat satellite server, as well as manually configured and worked on Active Directory for User administrative tasks.
- Create, maintain and customize complex JIRA project configurations including workflows, custom fields, permissions and notifications.
- Design and develop Continuous Integration and continuous deployments wif tools like GIT, Maven, ANT and Jenkins. Worked on a centralized build system, maintained several applications.
- Developed and maintained LINUX/Perl/ANT, Ruby, Python scripts for Java/J2EE build and release tasks.
- Creating the build script using the ANT as build tool, for JAVA and .NET web applications.
- Coordinated wif various teams by establishing appropriate branching, labeling and merging methods using source control tools like GIT, GITHUB, BITBUCKET.
- Implemented Ansible Playbooks for Deployment of builds on internal Data Centre Servers. Also re-used and modified same Ansible playbooks to create a Deployment directly into Amazon EC2 instances using Aw’s ops.
- Strong knowledge of Infrastructure & Configuration Management tools like chef and Strong experience in chef cookbooks development.
- Built and configured red hat Satellite 5.x and 6.x which is integrated wif puppet from scratch, Expertise in both Configuration Management and Patch Management.
- Experience on AWS cloud to create both Windows and Linux instances and used various AWS services like EC2, EBS, S3, Route 53, Cloud Formation, Amazon Elastic Cache and Elastic Load Balancing (ELB).
- Used IAM to create new accounts, roles, groups, polices and developed critical modules like generating amazon resource numbers and integration points wif S3, Dynamo DB, RDS, Lambda and SQS Queue.
- Developed and supported key pieces of the company's AWS cloud infrastructure Optimized volumes and EC2 instances and created multiple AZ VPC instances.
- Experience in infrastructure Integration between private and public clouds and involved in migrating the physical servers and Enterprise applications, into AWS private cloud Environment.
- Setting up the Application Server environment wif Tomcat/Apache, configuring the setup wif F5 virtual load balancer for Customer application.
Environment: AWS, JENKINS, GIT, ANT, MAVEN, Shell, Batch file, SQL Scripts, Windows Server 2008 R2, SQL Server Mirroring, Active Directory, DFS, Ubuntu, CentOS, Linux, Solaris, java, Ruby, Chef.
Confidential
Sr. Linux Engineer
Responsibilities:
- Administration of Sun, Dell, HP Servers running and SUSE, RHEL 4, 5, 6 HP-UX, CentOS which included jumpstart, performing live upgrades of Solaris operating systems and Kickstart RHEL, 5.x, 6.
- Installation and support of various applications and Databases including, MySQL, NOSQL and Sybase along wif Web Logic, JBoss, Sun Java System Web Server, Tomcat.
- Involved in working wif QA team in Load and Integration testing of J2EE applications on JBoss Application Servers.
- Experience in Shell scripting (ksh, bash) to automate system administration jobs.
- Setting up DATE, TIME, TIMEZONES and NTP (Network Time Protocol) server on Red Hat Enterprise Linux Systems to ensure accurate time synchronization required for scheduled jobs and programs.
- Automated server builds and web/database application deployments utilizing Puppet and shell scripting.
- Worked wif Facter to define custom facts using Ruby and shell scripts. Configured and maintained Puppet DB and integrating it wif PostgreSQL as the backend server to export resources.
- Wrote Puppet manifests for deploying, configuring, install shield and managing collected for metric collection and monitoring.
- Installing, Configuring, and maintaining Puppet on Linux and Windows servers and creating repositories in Bit Bucket.
- Patch management using native commands on Linux and following the chance control procedures.
- Performance tuning and troubleshooting of the applications arising out of the ticketing systems in Remedy.
- Monitoring the servers using tools like BMC Patrol and providing 24x7 supports on call rotation basis.
- Modified the Linux Kernel to control the swap.
- Performed processes administration and management like monitoring, start/stop/kill various processes/sub processes.
- Designed bash, ksh, Shell and Perl scripts to automate application and system management activities. These scripts provided the application startup and shutdown, monitored systems and applications health, and web site management.
- Worked in development, testing, and production environment using SQL, PL/SQL procedure, python and Ruby.
- Writing the API/Command line automation frameworks in Python.
- Creating the delivery pipeline of the build in Jenkins and Groovy Script.
- Implemented and administeredVMware ESX for running the Windows, Centos, SUSE and red hat Linux Servers on development and test servers.
- Worked on troubleshooting the triggered alarms generated from VMware VCenter Servers.
- Backup and restore of file systems using VERITAS NetBackup.
Environment: RHEL 4/5/6, CentOS 6, SUSE, Windows 2008, 2012 Apache 1.2/1.3/2.x, DNS, SVM, Logical Volume Manager, Hitachi, VERITAS net backup 5.x, VM ESX 2.x, SVN, Puppet.
Confidential
Linux and UNIX Administrator
Responsibilities:
- Responsible to solve technical Problems related System administration (Linux of Our Clients).
- Maintaining and Troubleshooting of FTP Server, Samba Server of the client.
- Working Knowledge in setting up VMware architecture (VMware Server/KVM).
- Extensive use of LVM, creating Volume Groups, Logical volumes, and disk mirroring, Fix the Problem wif the partially mirrored Logical volumes.
- Installed and configured Apache and Tomcat web server.
- Installation and setting up Firewall (IP tables) and enabled IPs to access console remotely.
- Configured UNIX infrastructure, and supported RHEL (Linux) 4,5 servers.
- Handling the day-to-day Operations, install software, apply patches, and manage file systems.
- Implemented remote installation on servers using RedHat Linux Kickstart and jumpstart/JET Servers.
- Installed and configured RedHat software’s and 3rd Party tools using RPM’s and YUM on RedHat servers.
- Developed BASH shell scripts to automate corn jobs and system maintenance. Scheduled corn jobs for job automation through Autosys.
- Worked wif Linux Security extensions like SElinux in both enforcing and permissive modes to guard misconfigured/compromised services.
Environment: Red Hat Enterprise Linux 4.x/5.x, CentOS 5.x, Subversion, Apache Tomcat, Samba, Bash, Scripting, VMware GSX.
