A DevSecOps Engineer who treats security as infrastructure, not an afterthought. I design self-healing, zero-downtime Kubernetes platforms and weave SAST, DAST, SCA, SBOM, and image-signing directly into the CI/CD fabric — so vulnerabilities are caught before merge, not after breach.
|
Config propagation time (down from full restarts) |
Manual release effort cut via CI/CD automation |
Service availability during hybrid-cloud cutover |
Vuln detection shift from post-deployment |
role: DevSecOps Engineer @ Tata Elxsi
focus: [Kubernetes, GitOps, Application Security, Hybrid Cloud]
philosophy: "Shift security left, automate everything, break nothing"
current_mission: Building zero-downtime, self-securing delivery platforms
fun_fact: I write Rust for infrastructure that can't afford to restart- 🔐 Security-First Engineer — I don't bolt security onto pipelines, I build pipelines around security
- ☸️ Kubernetes Native — from bare-metal Talos cluster provisioning to production-grade RBAC and network policy
- ⚙️ Automation Obsessed — if a human is doing it twice, I'm already scripting it
- 🌐 Hybrid-Cloud Practitioner — zero-downtime migrations across on-prem and cloud, validated in production
- 📖 Perpetual Learner — currently deep in platform engineering, supply-chain security, and AI-assisted DevSecOps
| 🏗️ What I Built | 📊 Measurable Result |
|---|---|
| Zero-downtime Kubernetes config hot-reload platform (Rust + NATS JetStream + Apache Arrow) | Config propagation cut to <5 seconds — zero service restarts |
| End-to-end signed CI/CD pipeline (GitHub Actions + Cosign + Harbor/Nexus hub-spoke) | ~60% reduction in manual release effort |
| GitOps rollout with ArgoCD + Helm across multi-cluster environments | Improved deployment consistency and faster rollback |
| Hybrid-cloud migration via IBM Hybrid Cloud Mesh + Concert Workflow | 100% service availability maintained during cutover |
| Full-spectrum security tooling integration (SAST/DAST/SCA/SBOM/Cosign) into CI/CD | Detection shifted from post-deployment → pre-merge |
| Continuous remediation cycles using SonarQube, Trivy, OWASP ZAP, Nessus, Kiuwan | Steady reduction of open critical/high findings |
| Kubernetes hardening for NCCS compliance alignment | Platform met regulatory security baselines |
| Jun 2023 — Present |
|
|
Network Function Orchestration Platform (ETSI-based) Problem: Orchestration workloads needed a security-hardened, compliance-ready foundation. Solution: Hardened configs, aligned controls to NCCS, integrated SAST/DAST/SCA into CI/CD. Stack: Impact: Elevated platform security posture; achieved compliance readiness for ETSI orchestration workloads. |
Hybrid-Cloud Migration & Automation Problem: Workloads needed cross-environment migration with zero disruption. Solution: Secure connectivity via IBM Hybrid Cloud Mesh + Concert Workflow using IBM-provisioned VANs. Stack: Impact: 100% service continuity across the full migration cutover. |
Kubernetes Configuration Management Platform Problem: Config changes forced restarts, causing downtime at the edge. Solution: Zero-downtime runtime updates; automated validate → sign → distribute via GitHub Actions, ArgoCD, Helm, and Kargo-driven promotion. Stack: Impact: Fully automated OCI artifact promotion to edge — zero downtime, zero manual intervention. |
💡 Swap
revendhfor your real GitHub username to bring every widget above to life.
Kubernetes • Cloud Native • DevSecOps • Platform Engineering • Cyber Security • Infrastructure Automation • AI-Driven DevSecOps

