I will set up a devsecops pipeline with automated security scanning

Einige Informationen werden in englischer Sprache angezeigt.

Indien

Ich spreche Englisch

10 Aufträge abgeschlossen

Cloud Architect, DevOps, Intune, SOC and Compliances

Azure Certified Cloud Architect with more than 13 years of expertise with Microsoft Azure, AWS, and GCP. I know a lot about Azure AD B2C custom policies, DevOps, Infrastructure as Code (Terraform, Bic...
Über diesen Service

Most engineering teams bolt security on at the end of their release cycle. By then it's too late, expensive, and disruptive. I'll integrate security directly into your CI/CD pipeline so vulnerabilities are caught before they ever reach production.


I am a cloud architect and DevSecOps specialist with experience across GitHub Actions, GitLab CI, AWS CodePipeline, and Azure DevOps.


WHAT I'LL BUILD & CONFIGURE:

  • SAST (Static Application Security Testing) via Semgrep or SonarQube
  • SCA (Software Composition Analysis) for dependency vulnerabilities via Snyk or Dependabot
  • Container image scanning with Trivy or Grype
  • IaC security scanning (Terraform / Bicep) with Checkov or tfsec
  • Secrets detection (detect-secrets, GitGuardian integration)
  • Pipeline-as-code: all security steps in version-controlled YAML
  • Security gate policies fail builds on critical findings
  • Full pipeline documentation and configuration guide


WHO THIS IS FOR:

  • Startups building on AWS, Azure, or GCP who need security without slowing down
  • Teams preparing for SOC 2 or ISO 27001 (requires secure SDLC evidence)
  • CTOs who want shift-left security built into the development workflow

Tell me your CI/CD platform and cloud provider.

Tools:

Docker

Jenkins

BitBucket

CloudFormation

Frameworks:

Terraform

Ansible

Koch

Puppe

Cloud-Provider:

Amazon Web Services

microsoft azure

Programmiersprache:

Bash

Python

Expertise:

Installation

Migration

Debuggen

Mein Portfolio