I'm a DevOps Engineer building toward the next generation of cloud and platform engineering.
My focus isn't simply on deploying applications.
It's on engineering environments where:
CODE
β
AUTOMATION
β
INFRASTRUCTURE
β
CLOUD
β
SECURITY
β
IDENTITY
β
OBSERVABILITY
β
RESILIENCE
Everything should be automated, reproducible, observable, secure and scalable.
I work across the boundary between development, infrastructure and cybersecurity, using DevOps and DevSecOps principles to transform manual infrastructure into reliable engineering platforms.
If it can be automated β automate it. If it can be measured β observe it. If it can be secured β secure it by design. If it can fail β engineer for resilience.
|
Azure AWS Cloud Architecture Networking Storage |
CI/CD Git Automation Release Engineering Platform Engineering |
Terraform Infrastructure Provisioning Configuration Automation |
DevSecOps IAM Zero Trust Secrets Cloud Security |
Monitoring Logging Observability Reliability Resilience |
I think beyond individual deployments.
The goal is to create repeatable engineering platforms that allow teams to ship faster without sacrificing security or reliability.
βββββββββββββββββββββββ
β DEVELOPERS β
ββββββββββββ¬βββββββββββ
β
βΌ
βββββββββββββββββββββββ
β DEVELOPER β
β PLATFORM β
ββββββββββββ¬βββββββββββ
β
ββββββββββββββββββΌβββββββββββββββββ
βΌ βΌ βΌ
βββββββββββ βββββββββββ βββββββββββ
β CI/CD β β IaC β β CLOUD β
ββββββ¬βββββ ββββββ¬βββββ ββββββ¬βββββ
β β β
ββββββββββββββββββΌβββββββββββββββββ
βΌ
βββββββββββββββββββ
β DEVSECOPS β
ββββββββββ¬βββββββββ
βΌ
βββββββββββββββββββ
β IAM β’ SECURITY β
ββββββββββ¬βββββββββ
βΌ
βββββββββββββββββββ
β OBSERVABILITY β
ββββββββββ¬βββββββββ
βΌ
βββββββββββββββββββ
β RESILIENCE β
βββββββββββββββββββ
Cloud β’ Containers β’ Kubernetes β’ IaC β’ CI/CD β’ Automation β’ Linux β’ Scripting
Infrastructure should be versioned, repeatable and reproducible.
Infrastructure as Code
β
βββ Terraform
βββ Configuration
βββ Networking
βββ Identity
βββ Security
βββ Deployment
β
βΌ
Git-based workflow
β
βΌ
CI/CD
β
βΌ
Automated validation
β
βΌ
Cloud deployment
Terraform Β· Azure Β· AWS Β· GitHub Actions Β· Azure DevOps Β· Automation
Security isn't a final pipeline stage.
It's part of the architecture.
PLAN
β
CODE
β
BUILD
β
TEST
β
SECURITY
β
PACKAGE
β
DEPLOY
β
OBSERVE
β
IMPROVE
βΊ
π Secrets Management π‘οΈ Vulnerability Management π Security Testing π³ Container Security βοΈ Cloud Security π IAM π¦ Dependency Security βοΈ Secure CI/CD π Security Monitoring
Modern infrastructure requires modern identity.
My IAM focus includes:
Microsoft Entra ID
β Identity & Access β RBAC β Conditional Access β Managed Identities β Service Principals β Authentication β Authorization β Least Privilege β Identity Governance β Zero Trust
USER
β
IDENTITY
β
AUTHENTICATION
β
AUTHORIZATION
β
POLICY
β
RESOURCE
β
AUDIT
Azure DevOps Β· Azure Networking Β· Azure Monitor Β· Azure Container Apps Β· Azure Storage Β· Entra ID
IAM Β· EC2 Β· VPC Β· S3 Β· CloudWatch Β· Cloud-native architecture
I'm interested in the evolution from:
Servers β Virtual Machines β Containers β Kubernetes β Platforms
π³ Docker βΈοΈ Kubernetes βοΈ Azure Container Apps ποΈ Terraform βοΈ CI/CD π Container Security π Observability
You can't operate what you can't see.
My observability mindset:
ββββββββββββββ
β METRICS β
βββββββ¬βββββββ
β
ββββββββββββ βΌ ββββββββββββ
β LOGS β β SYSTEM β β TRACES β
ββββββββββββ β ββββββββββββ
βΌ
ALERTING
β
βΌ
INCIDENT RESPONSE
β
βΌ
IMPROVEMENT
Azure Monitor β’ Log Analytics β’ Metrics β’ Logs β’ Alerts β’ Dashboards
My engineering interests are strongly influenced by the security and resilience requirements of banking and financial technology environments.
Financial systems require infrastructure that is:
Secure
Highly available
Auditable
Observable
Resilient
Automated
Controlled
That means DevOps cannot operate independently from security and governance.
DEVOPS
β
βΌ
SECURITY
β
βΌ
IAM
β
βΌ
RESILIENCE
β
βΌ
AUDITABILITY
β
βΌ
TRUST
Areas of interest include:
Cloud Security Β· IAM Β· DORA Β· ISO 27001 Β· NIST Β· PCI DSS Β· Operational Resilience
Building cloud environments using:
Terraform + Azure + CI/CD + IAM + Monitoring
Experimenting with:
GitHub Actions β Security Checks β Container Build β Deployment β Monitoring
Exploring:
IAM β Cloud Security β Risk β Controls β Auditability β Resilience
I contribute to public cloud, FinOps and DevOps projects. My changes go through the normal fork β feature branch β pull request β review β merge workflow.
An open-source, provider-neutral FinOps data platform with Arrow-based pipelines, SQL-first governance policies, and DuckDB, Postgres and BigQuery destinations.
- Added a
reportcommand to the CLI that writes cost findings as an HTML report. - Added Slack/webhook notifications so findings can be pushed to team channels.
- Added PyPI package metadata and a PyPI publish step to the GitHub Actions release workflow.
- Wrote three new SQL cost policies that detect idle Azure API Management, Azure Kubernetes Fleet Manager and Azure Managed HSM resources.
- Covered every change with
pytesttests: 8 new test files across the policies, the report, notifications, packaging and the release workflow. - +417 lines across 13 files. Reviewed, approved and merged by the maintainer.
π Pull Request: raphgm/cloudcost-cli#24
An open-source, context-aware digital workspace that works with any AI provider, with Azure OpenAI preferred.
- Added myself to
CONTRIBUTORS.mdas a project contributor. - Added a standard
.gitignoreso that local environment variables and OS-generated files are not committed. - Reviewed, approved and merged by the maintainer.
π Pull Request: raphgm/pinpointpro#46
- 2 merged pull requests, both reviewed and approved by the project maintainer.
- Delivered features, cost-governance policies, CI/CD release automation and test coverage to a real FinOps codebase.
- Comfortable with the full open-source collaboration workflow: issues, forks, branches, PRs, code review and merges.
Looking forward to contributing more to open-source Cloud, DevOps, FinOps and DevSecOps projects.
π Explore Applied Skills
| Area | Applied Skill | Credential |
|---|---|---|
| π€ AI | Resolve GitHub issues by using GitHub Copilot | View Skill |
| π’ Infrastructure | Administer Active Directory Domain Services | View Skill |
| βοΈ DevOps | Implement security through a pipeline using Azure DevOps | View Skill |
| βοΈ Cloud | Deploy cloud-native apps using Azure Container Apps | View Skill |
| π Identity | Get started with identities and access using Microsoft Entra | View Skill |
| π Networking | Configure secure access to your workloads using Azure networking | View Skill |
| π‘οΈ Security | Get started with cloud security and monitoring tasks | View Skill |
| π Monitoring | Deploy and configure Azure Monitor | View Skill |
| βοΈ Management | Get started with Azure management tasks | View Skill |
| πΎ Storage | Secure storage for Azure Files and Azure Blob Storage | View Skill |
π View credentials
- ISO/IEC 27001:2022 Lead Implementer
- ISO 27001 Lead Auditor
- ISO 42001 Lead Auditor
- ISO 27701 Lead Auditor
- ISO 31000 Risk Management
- CompTIA Security+
- CompTIA CySA+
- Proofpoint Certified Security Awareness Specialist
- Certified Cybersecurity & Privacy Professional
- Certified Governance, Risk & Compliance Auditor
- Certified Privacy & Protection Specialist
βββββββββββββββββ
β DEVELOPER β
β EXPERIENCE β
βββββββββ¬ββββββββ
β
βΌ
ββββββββββββββββββββ
β PLATFORM ENGINEERβ
ββββββββββ¬ββββββββββ
β
βββββββββββββββΌββββββββββββββ
βΌ βΌ βΌ
CLOUD SECURITY DATA
β β β
βββββββββββββββΌββββββββββββββ
βΌ
ββββββββββββββββββββ
β INTELLIGENT β
β AUTOMATION β
ββββββββββ¬ββββββββββ
βΌ
ββββββββββββββββββββ
β SELF-HEALING & β
β RESILIENT SYSTEMSβ
ββββββββββββββββββββ
The long-term goal is to move beyond simply managing infrastructure toward engineering intelligent, secure and increasingly autonomous platforms.
AUTOMATE
β
SECURE
β
DEPLOY
β
OBSERVE
β
LEARN
β
IMPROVE
βΊ
Infrastructure should be reproducible.
Security should be continuous.
Identity should be explicit.
Observability should be built in.
Automation should remove friction.
Resilience should be engineered β not assumed.
Engineering the infrastructure behind the next generation of secure digital platforms.
STEΠVE.DEVOPS
