Senior DevSecOps Engineer
Chenega Corporation, Stafford, VA | Client: Department of Defense (DoD) — Sept 2021 – Present
- Led the design and implementation of CI/CD pipelines, incorporating security best practices throughout the software development lifecycle. This initiative ensured secure, frequent, and efficient deployment processes, resulting in a 95% reduction in deployment time and a 45% decrease in overall development costs. By minimizing testing and debugging time, developers received immediate feedback on their changes, enabling quicker bug detection and faster resolution.
- Automated and optimized CI/CD pipelines using tools and services such as AWS EC2, S3, CloudWatch, Grafana, Atlassian Jira, Confluence, Jenkins, Docker, FitNesse, Marklogic, and Appian, while integrating OWASP Zap for security testing and vulnerability scanning, and enabling automated alerting via Mattermost and Slack to enhance security awareness and response.
- Worked with various teams, including development, qa, product/project management, and government, to assess the impact on processes and business value for enterprise strategies, while developing implementation plans and success objectives.
- Led the infrastructure operations and monitoring teams in transitioning from Splunk to AWS CloudWatch, realizing a 90% reduction in licensing costs while enhancing system monitoring and scalability.
- Worked closely with DoD government teams to prepare and review contract and technical documents, along with architecture, ensuring compliance with FedRAMP and NIST SP 800-53 frameworks. This collaboration enhanced customer service, satisfaction, and confidence, as reflected in the Service Level Agreement (SLA).
- Developed and managed CI/CD pipelines with integrated security scanning (SAST, DAST, dependency checks)
- Prepared cost analysis and budget estimate documents, which were submitted to the management team for approval prior to purchasing and implementing the necessary infrastructure resources to enhance IT infrastructure and software development processes.