I build and secure cloud infrastructure end to end: provisioning it as code, running workloads on Kubernetes, wiring up delivery pipelines, and hardening the whole path against real attackers. I care about least privilege, defence in depth, and proving a control works by trying to break it β not just deploying it.
Currently going deep on DevSecOps and platform/SRE work: admission control, supply-chain signing, service-mesh zero-trust, and hands-on penetration testing.
| Category | Skills |
|---|---|
| Containers & Orchestration | Kubernetes, Istio (mTLS, AuthorizationPolicy), Argo CD, Docker, Docker Compose |
| Cloud | AWS (EKS, EC2, VPC, S3, RDS, IAM, CloudWatch) Β· GCP (Compute, IAM, Firewall) |
| Infrastructure as Code | Terraform (modules, state management, providers) |
| CI/CD & Supply Chain | GitHub Actions, Jenkins, Cosign (keyless), SBOM / SLSA, Trivy, Semgrep, Gitleaks |
| Security & Policy | Pod Security Standards, Kyverno, Sealed Secrets, NetworkPolicy, RBAC, CVSS, OWASP Top 10 |
| Observability | Prometheus, Grafana |
| Automation & OS | Python (Boto3), Bash, Linux (RHEL/Ubuntu), system hardening |
Hardening a PCI-scoped payments microservice end to end, every control verified at runtime.
- Workload: non-root + read-only rootfs + dropped capabilities, PSS
restricted+ Kyverno admission, Sealed Secrets, least-privilege RBAC - Supply chain: GitHub Actions gating (Trivy Β· Semgrep Β· Gitleaks) β cosign keyless signing + SBOM attestation β pull-based GitOps with Argo CD
- Zero-trust: Istio mTLS STRICT, default-deny AuthorizationPolicy on SPIFFE identity (200 vs 403), NetworkPolicy defence-in-depth
- Offensive: passive OSINT + a pen-test (RCE 9.8, SSRF 8.6, PAN exposure, weak tokenization) with each finding mapped back to the control that stops it
βΈοΈ AWS Enterprise EKS Platform
Production-ready Kubernetes on AWS via Terraform β custom networking, automated node provisioning.
Self-healing application with automated sync policies β "zero-touch" delivery.
Full CI/CD with automated builds, security scanning, and real-time observability.
- LinkedIn: linkedin.com/in/jubeth-cloud-devops
- Email: sjubeth3@gmail.com
Open to Cloud / DevOps / SRE / DevSecOps roles β remote or relocation.
