We provide IT Staff Augmentation Services!

Cloud Cybersecurity Architect/devsecops Resume

5.00/5 (Submit Your Rating)

TECHNICAL SKILLS:

AWS, GCP, Kubernetes, Docker, Java,Python, Ruby, JSON, YAML, PL/SQL, Redhat, Centos, Ubuntu, Powershell, Windows, Linux and UNIX; Oracle Fusion Middleware, AWS and GCP infrastructure; Source Code Management (Gitlab, Github, Bitbucket); Chef, Ansible, Terraform, Puppet, Jenkins, CloudFormation, Deployment Manager, Kubernetes, GKE, Docker

PROFESSIONAL EXPERIENCE:

Confidential

Cloud Cybersecurity Architect/DevSecOps

Responsibilities:

  • Created README.md files using Cucumber syntax from AWS CloudTrail event logs for technical and non technical people to show Security Controls functionalities.
  • Developed and Implemented Auto Remediation for RDS, S3, EC2, ECR, EKS, IAM, SAML, DynamoDB, VPC and etc. using Lambda functions with Python 3.6/3.8.
  • Used Event Driven Architecture based on CloudWatch Event Sources and Patterns based on the event trigger.
  • Created IAM granular and least privileged policies for Lambda functions and attached to respective roles.
  • Built and run Serverless Framework and Integrated existing lambda functions to Serverless framework.
  • For better debugging and troubleshooting configured Simple Queue Service with Standard and Dead Letter Queue for failed and unprocessed messages.
  • Deployed Twistlock zip file as a Lambda layer and tested using PaloAlto GUI.
  • Configured Azure Devops Pipeline and enabled GitHub hooks for CI/CD.
  • Used AWS Config to capture non compliant rules and resources
  • Used proactive automatic remediation for AWS Cloudtrail disabling, Monitor, Alert and Reenable
  • Used Attribute Based Access Control(ABAC) proactively restrict S3 access based on user tags
  • Used Attribute Based Access Control(ABAC) proactively restrict EC2 access based on tags
  • Leveraged Docker Security Concepts and prepared a documentation.
  • Participated in deployment and troubleshooting part in Controls deployments in 15 AWS regions.

Confidential, Tysons Corner, Virginia

Enterprise solutions Architect/DevSecOps Engineer

Responsibilities:

  • In order to achieve reusability configured and built Ansible roles with Ansible Galaxy from scratch for different application in different environment .
  • Built and run Terraform files in order to build immutable infrastructure and one click deployment to various environments using Terraform workspaces.
  • Configured Parametrized Jenkinsfile for running end to end application deployment using Artifactory, Ansible Roles, Gitlab, Docker Containers.
  • Debugged Java applications with Tomcat 8/9 and analyzed the logs . Tested Database connectivity with different SQL queries using sqlplus cli, configured JDBC connectivity.
  • Monitored the VMs running in Azure and created reports based on the Monitoring with ElasticStack . Used Ansible/Python SDK for Rubrik for Vspehere VMware VMs on demand snapshots . Used Terraform provider for Vsphere for backup strategy.
  • Configured Keyclock for different environments with H2 and Oracle Database 12c R2.
  • Automated end to end Apigee - Edge using Ansible Galaxy and deployed to dev and staging environments.
  • Configured Postgres, Cassandra, Zookeeper, QPID in clustered deployment in Production environment.
  • Configured and built Ansible Role for Oracle 12c Database and integrated with PL/SQL and Shell script for Database flashbacks and checkpoints for DB backup and rollbacks.
  • Automated Oracle Golden Gate (OGG) and Operational Data Store (ODS) for DB migrations and upgrades.
  • Took part in different critical Production Deployments for various environments, debugged DB connections, DB upgrades, Webserver logs and etc.
  • Configured and built backups for different applications based on timestamps and dates.
  • Deployed application to AKS cluster and utilized HELM for reusability and easy maintainability.

Confidential, Rockville, Maryland

Enterprise Solutions Architect/DevSecOps Engineer

Responsibilities:

  • Built and pushed private Docker images for Elasticsearch, Fluentd and Kibana to Elastic Container Registry
  • Built Kubernetes Cluster using EKS on AWS and deployed ElasticStack (EFK) on EKS cluster with 3 worker nodes.
  • Redirected http to https (SSL/TLS) between FluentD and Elasticsearch and Kibana UI using SearchGuard plugins.
  • Spin up private subnets and deployed Kubernetes worker nodes to private subnets
  • Configured Bastion Host and NAT Gateway for private connectivity
  • Built and deployed Metricbeat, APM Server and APM Agent for System/Infrastructure and Application logs
  • Leveraged IAM roles and policies in order to obtain the most granular access to AWS resources
  • Helped team to build Ansible playbooks and get benefit of Ansible - Vault In order to achieve production ready EKS cluster implemented some security practices such as running sidecar pods which perform encryption based on nginx, complete Service Mesh like Istio which also offers same option
  • Studied and leveraged Calico for restricting Inbound and Outbound traffic

Confidential

Enterprise Solutions Architect/Devops Engineer

Responsibilities:

  • Scripted whole AWS resources using CloudFormation and Integrated with Ansible playbooks for Configuration Automation
  • Enabled SSL/TLS for DevOps tools including Jenkins, Gitlab and Artifactory
  • Installed and enabled Cloudera/Hadoop ecosystem on AWS on dev, stage and prod environments
  • Established Jira/Confluence, Jenkins, Gitlab and Artifactory on AWS with HA using ALB and NLB accordingly
  • Used Infrastructure as Code with leveraging Python, Shell Scripting, Json, YAML and Boto3 libraries
  • Created Terraform scripts for Infrastructure Automation and AWS
  • Automated NGINX Reverse Proxy and SSL Termination using Ansible Playbooks and CloudFormation
  • Worked on building cloud infrastructure from scratch using EC2, ASG, ELB, Route53, DynamoDB and VPC
  • Chef is used as the provisioning tool along with Terraform
  • Created Chef Cookbook for Oracle 11G R2 installation
  • Managed recipes, template and attribute files to create WebLogic, fusion middleware and repository creation utility
  • Worked on Ansible to manage Web Applications, Config Files, Data Base, Commands, Users, Mount Points, and Packages
  • Ansible to assist in building automation policies
  • Maintained and administered GIT source code tool
  • Installed and configured GIT and communicating with the repositories in GITHUB
  • Support the code builds by integrating with continuous integration tool (Jenkins)
  • Installed and configured Jenkins for Automating Deployments and providing an automation solution During the engagement with Confidential extensively utilized GCP and especially GKE and Docker containers
  • Implemented continuous delivery pipe line using Docker and Jenkins
  • Configured the Kubernetes cluster and supported it running on the top of the CoreOS
  • Used Jenkins and pipelines to drive all microservices builds out to the Docker registry and then deployed to Kubernetes, Created Pods and managed using Kubernetes
  • Building/Maintaining Docker container clusters managed by Kubernetes Linux, Bash, GIT, Docker, on GCP
  • Utilized Kubernetes and docker for the runtime environment of the CI/CD system to build, test deploy
  • Used Configuration Management tool Chef, created Chef Cookbooks using recipes to automate system operations
  • Converting production support scripts to Chef recipes
  • Configured Chef to build up services and applications on the instances once they have been configured using Terraform
  • Worked with Docker and help improve our Continuous Delivery framework to streamline releases and reliability
  • Apart from Confidential project I worked on Liberty Power project to install and configure Elasticsearch 6.2.4 version on Compute and Container Engines on Google Cloud Platform in Sandbox environment
  • Used GCP Managed Kubernetes Engine to create master and worker nodes on Container Engine
  • Wrote Manifest files in YAML format from scratch in order to install Docker containers and Elasticsearch, Fluentd and Kibana on Google Kubernetes Engine
  • Configured and Installed Pivotal Cloud Foundry on Google Cloud Platform by launching Ops Manager Director Instance, Shared VPC and deploying Elastic Runtime on GCP

Confidential, Chevy Chase, Maryland

AWS Solutions Architect

Responsibilities:

  • Designed, configured and deployed Amazon Web Services (AWS) for applications utilizing the AWS stack (Including EC2, Route53, S3, RDS, Direct Connect, Cloud Formation, Cloud Watch, SQS, IAM), focusing on high-availability, fault tolerance, auto-scaling, load-balancing capacity monitoring and alerting
  • Configured AWS Identity and Access Management (IAM) Groups and Users for improved login authentication Also handled federated identity access using IAM to enable access to our AWS account
  • Configured KMS using IAM to provide encryption/decryption keys to secure Amazon S3, EBS and RDS
  • Handled content distribution and data transfer and implemented content delivery network over Amazon CloudFront using Amazon WAF
  • Used AWS sample and own created CloudFormation templates in order to describe the AWS resources, any associated dependencies or runtime parameters required to run the application
  • Scheduled, deployed and managed container replicas onto a node cluster using Kubernetes
  • Container management using Docker by writing Docker files and set up the automated build on Docker HUB and installed and configured Kubernetes
  • Handled streaming and live content over Amazon CloudFront
  • Used Chef to automate deployment of applications on Amazon EC2
  • Handled configuration management of servers using Chef
  • Handled API requests using REST
  • Expertise in running applications using Elastic Bean Stalk
  • Created a AWS RDS Aurora DB cluster and connected to the database through an Amazon RDS Aurora DB Instance using the Amazon RDS Console
  • Design and implement disaster recovery for the PostgreSQL Database
  • Configured an AWS Virtual Private Cloud (VPC) and connected it to the on-Premises data center using AWS VPN Gateway for Cloudfront distribution
  • Used AD connector to connect existing on-premises Active Directory to AWS
  • Performed AWS lambda functions on S3
  • Configured AWS RDS Aurora database users to allow each individual user privileges to perform their related tasks
  • Experience in using Linux Distributions and Linux Commands
  • Migrated the production MySQL schema to the new AWS RDS Aurora instance
  • Implemented AWS High-Availability using AWS Elastic Load Balancing (ELB), which performed a balance across instances in multiple Availability Zones
  • Assigned AWS Elastic IP Addresses used to work around host or availability zone failures by quickly remapping the address to another running instance or a replacement instance that was just started
  • Defined AWS Security Groups which acted as virtual firewalls that controlled the traffic allowed to reach one or more AWS EC2 instances
  • Implemented Apache Hadoop cluster using hdfs in a testing environment
  • Managed application and patch management of applications running on AWS World Bank December 2014 - May 2017 AWS Solutions Architect Washington DC
  • Analyzed World Bank application portfolios, identified dependencies and infrastructure platform components in traditional environments for workload migrations to AWS
  • Created migration roadmaps to AWS public Cloud regions, designed architecture models compliant with security policies and Federal Information Processing Standards
  • Provided architecture guidance for selected Business Units, assessing migration feasibility and deployment strategy based on AWS Architecture best practices
  • Strong focus on security; Designed and delivered company-wide security training for all employees, wrote formal security incident response plan, overhauled public vulnerability reporting process, and wrote extensive documentation on security processes and best practices
  • Worked on Ingress and egress of data to and from AWS
  • Designed, built, and deployed a multitude applications utilizing almost all of the AWS stack (Including EC2, R53, S3, RDS, DynamoDB, SQS, IAM, and EMR), focusing on high-availability, fault tolerance, and auto-scaling
  • Developed Disaster Recovery Plan and Business Continuity proposal utilizing AWS Services for World Bank centers
  • Resolved AWS Network Infrastructure Issues, troubleshoot HPC Performance and HA Configuration
  • Provided potential technical workarounds or resolutions via interaction in technical discussions, knowledge base articles and product documentations

Confidential, Charlotte, North Carolina

AWS Solutions Architect/Software Engineer

Responsibilities:

  • Designed and developed fault tolerant banking website
  • Used multiple EC2 (AMI) instances for webserver
  • Used S3 buckets as failover webpage
  • Worked in Dev, QA, UAT and Prod environments
  • Used ELB for load balancing between different instances in multiple availability zones
  • Used VPC and Route53 as networking and DNS service respectively
  • Database(MySQL) update and management using PHP MyAdmin
  • Implemented best SEO practices to increase the search engine visibility among different browsers Prepared Acceptance Criteria for all the new feature User Stories that are developed by Scrum team
  • Developed and maintained automated regression test cases in Selenium WebDriver using Java programming language
  • Have followed a test automation framework based on Page Object Model, TestNG and Selenium WebDriver
  • Developing test suites in Selenium WebDriver in Java with Testing framework in Eclipse IDE for regression and sanity testing Automated Smoke Test suite in Selenium WebDriver and maintained the suite by constantly updating it with new tests and any fixes to failures due to changes in the functionality
  • Developed Selenium tools from scratch and configured various other peripherals tools to perform Selenium WebDriver test
  • Implemented cross browser compatibility and cross platform web testing using TestNG in Selenium WebDriver
  • Used Selenium WebDriver to expand test scenarios to catch more bugs and improve quality
  • Designed and developed automated scripts for Functional, Regression Testing using Selenium WebDriver tools
  • Developed and implemented Data Driven framework in Cucumber BDD using a Selenium WebDriver

Confidential, Richmond, Virginia

QA Analyst

Responsibilities:

  • Analyzed and developed test script, test cases and performed Manual and Automation Testing like Positive Testing and Negative Testing
  • Choose Selenium tools and Configuring Selenium Test Environment such as Eclipse IDE, Java, Selenium WebDriver, TestNG, Maven
  • Performed functional, regression and UAT Testing extensively used Selenium WebDriver Extensively used CSS Selectors, XPath expressions to identify web elements using Firefox plugins like Firebug and FirePath for Selenium WebDriver
  • Generated TestNG test result, HTML report after execution using Selenium WebDriver
  • Maintained Automation scripts and responsible for code check - ins into GitHub
  • Used JAVA to code the test cases in Selenium WebDriver and also process strong knowledge on it
  • Developed BDD framework in the organization by writing features files, step definitions and closely worked with the Product owner using Cucumber
  • Performed Black Box Testing, UAT Testing and extensively used Selenium WebDriver for Regression, Smoke, Functional Testing and Data Driven testing using excel file in Selenium WebDriver
  • Defects were tracked, reviewed, analyzed and compared using JIRA
  • Worked with SQL queries using Oracle SQL Back-End Testing

We'd love your feedback!