About
Platform & DevSecOps Engineer
To me, a good DevSecOps engineer is one who makes the system stop needing them.
It's when infrastructure scales itself while you sleep.
It's when CI/CD is good enough that a junior ships on day one.
It's when Ops sees the whole system on a few screens.
It's when Security manages risk proactively — not chasing incidents.
And it's when a complex change to production becomes a single, simple action.
That's what I build: Kubernetes platforms, delivery pipelines, secrets management, and observability.
Career Timeline
From backend development to platform engineering — 3+ years operating production infrastructure across fintech, e-commerce, and SaaS. Full resume with company details available on request.
DevSecOps Engineer
Enterprise Consumer Finance
Core banking workloads · Hanoi, Vietnam
Operate hybrid infrastructure (OpenShift on-prem + AWS Landing Zone) and build the delivery platform used by multiple engineering teams.
- Re-architected CI/CD from isolated pipelines into a shared platform (Jenkins Shared Library) serving 40+ repositories — cut pipeline maintenance effort by ~70%
- Designed centralized secrets management (HashiCorp Vault) integrated with CI/CD and Kubernetes workloads — eliminated hardcoded secrets across all repositories
- Built a security gate into every release (Trivy, SonarQube, DefectDojo) — critical vulnerabilities block promotion to UAT/Prod automatically
- Deployed centralized observability (OpenTelemetry, Prometheus, Grafana) covering 100+ servers and all microservices
- Migrated legacy workloads to OpenShift HA with GitOps (ArgoCD) — zero-downtime deployments with automatic rollback
- L3/L4 on-call for UAT/Prod incidents and go-live support
DevOps Engineer
Print-on-Demand SaaS
15 tenant sites, ~300k orders/month · Hanoi, Vietnam
Owned AWS infrastructure and delivery workflow for a multi-tenant e-commerce platform (team of 12).
- Provisioned the full AWS stack with Terraform modules (VPC, EKS, RDS, ALB, IAM) — environment setup went from days to under 30 minutes
- Designed multi-tenant EKS with namespace-per-tenant isolation (NetworkPolicy, ResourceQuota) — zero cross-tenant interference at ~300k orders/month
- Cut CI pipeline duration ~50% via path-based selective builds and parallel jobs across a monorepo
- Hardened workload security: IRSA least-privilege access, restricted Pod Security Standards, deny-by-default network policies, Trivy gate in CI
- Reduced MTTD from ~30 min to under 5 via SLA-based alerting; rightsized compute to save ~$200/month
DevOps Engineer
Financial Software Provider
Investment fund management platform · Hanoi, Vietnam
First DevOps role — containerized a microservices platform and built its CI/CD from the ground up on VM + Docker Swarm infrastructure.
- Containerized microservices with multi-stage Dockerfiles; standardized Swarm stack files across dev/staging/prod — eliminated environment drift
- Built CI/CD (Jenkins, GitLab CI) covering build, test, image push, and zero-downtime rolling updates — enabled same-day hotfix delivery under production SLA
- Administered PostgreSQL/Oracle: migrations, backups, query optimization that cut report generation time for fund operations
- On-call for production issues across Kafka, Redis, Oracle integration points
Skills
Technologies and tools I use to build reliable infrastructure.