Senior DevSecOps and platform engineer with 15+ years building secure, automated infrastructure for startups and enterprise SaaS. Often the first or founding infrastructure hire, owning cloud architecture, CI/CD, compliance, and increasingly product engineering from the ground up. Most effective in early-stage environments, turning vague security and infrastructure needs into systems a small team can run.
Summary
Qualifications | Skills
Platform & Cloud
- AWS, Google Cloud, Azure
- Multi-tenant & single-tenant SaaS, BYOC / BYOVPC
- Event-driven, serverless
Kubernetes & Runtime Isolation
- Kubernetes, ECS, Docker
- Cilium, Karpenter, autoscaling, hardened networking
- Kata, Cloud Hypervisor, Firecracker, gVisor
Infrastructure as Code
- Terraform, Packer, Ansible, Puppet
- GitOps, declarative infrastructure
- High availability, disaster recovery
CI/CD & Developer Productivity
- GitHub Actions, CircleCI, Dagger, Renovate
- Monorepo & open-source release workflows
DevSecOps & Compliance
- SOC 2 Type 2 readiness & renewal
- IAM, SSO, identity & access
- Vault, Consul, etcd
Languages & Product Engineering
- Golang, Python, Rust, Bash, Ruby, PowerShell
- Backend services, CLIs, TUIs
- Tauri, product auth, developer tooling
Data & Observability
- DynamoDB, RDS, Spanner, Snowflake
- MySQL, PostgreSQL, MongoDB
- Datadog, Splunk, CloudWatch, Prometheus, ELK
Leadership & Advisory
- Building & leading DevOps / DevSecOps teams
- Startup DevSecOps advising & consulting
Work Experience
typedef · Founding DevSecOps Engineer
Seattle, WA (Remote)Founding DevSecOps engineer at an early-stage data AI company, building the infrastructure and security function from day one.
- Stood up the DevSecOps foundation: cloud infrastructure, CI/CD, identity, security operations, and IT.
- Led SOC 2 Type 2 readiness and renewal: integrated compliance tooling across cloud and business systems, drove certification with auditors.
- Contributed to product engineering, from the auth lifecycle to the Tauri desktop app in Rust and Python, and built the CI/CD and infrastructure that runs, distributes, and secures it.
- Shaped how the founding team worked: SDLC, planning cadence, delivery process.
Sandboxed Query Engine
Architected a Kubernetes-based multi-tenant sandbox platform for untrusted customer and agent workloads using Cilium, Karpenter, and Kata Containers with Cloud Hypervisor / Firecracker-backed microVM isolation. Balanced startup latency, cost, and tenant isolation across workload profiles.
BYOC Dataplane
Designed a BYOC dataplane that provisioned private customer-hosted infrastructure with scoped access, least-privilege permissions, and managed control-plane integration. Built on experience from 100+ customer-hosted deployments to move early customers toward minutes-long, near self-service provisioning.
Reusable CI/CD Platform
Built typedef’s CI/CD from scratch with GitHub Actions and Dagger across several application and infrastructure monorepos, including the open-source Python library fenic. Kept dozens of pipelines maintainable and reusable as the codebase, product, and release model evolved.
Tecton · DevOps Lead / Manager
Seattle, WA (Remote)Joined as the first DevOps engineer and grew into the technical lead and manager for the DevSecOps team behind Tecton’s managed platform.
- Grew a one-person function to eight direct reports, owning platform operations, infrastructure product work, business IT, and compliance & security.
- Ran daily operations across all of Tecton’s deployment models, scaling to 100+ single-tenant customer-hosted, Tecton-managed, environments in addition to larger enterprise deployments.
- Partnered with product, engineering leadership, and customers to build the infrastructure enterprise adoption required.
- Led architecture direction, hiring, mentorship, and incident response.
Deployment Strategy
Architected Tecton’s three deployment models: enterprise bring-your-own-VPC, hybrid bring-your-own-dataplane (Tecton-hosted control plane), and fully hosted SaaS. The enterprise model won customers spanning high-growth fintech to large, highly-regulated enterprises.
Single-Tenant Provisioning
Cut single-tenant provisioning from 2-3 days of cross-team & customer friction to 15-60 min by moving setup up-front and tightening handoffs across sales, support, and engineering. Larger enterprise deployments benefited, but tended to stay hands-on, closer to embedded consulting.
Bitnomial · DevOps Engineer
Seattle, WA (Remote)DevOps engineer supporting infrastructure and delivery systems for a regulated digital asset derivatives exchange.
- Applied infrastructure-as-code and CI/CD practices to the exchange’s cloud infrastructure under strict security and compliance requirements.
Shujinko · Lead DevSecOps Engineer / Co-Founder
Seattle, WAFounding lead DevSecOps engineer for a compliance automation SaaS product that helped enterprises prepare for and pass security audits.
- Built the infrastructure, security, and SDLC foundation on AWS, GCP, Terraform, Packer, CircleCI, and Golang.
- Led DevSecOps and backend engineers across planning, architecture, delivery, and code review.
- Owned the lifecycle, operational health, and security of cloud infrastructure, backend microservices, and CI/CD.
CI/CD Framework
Built a centrally maintained framework that delivered applications and infrastructure from non-production to production across dozens of GitHub repositories, using Mage, Make, Golang, Bash, Terraform, and CircleCI.
GitOps
Built a self-service GitOps model that let engineers provision their own resources, from S3 buckets to GitHub repositories, with gated approvals where they mattered.
Infrastructure & Security as Code
Developed a library of reusable Terraform modules, used internally and shipped through the Shujinko product, so customers could apply cloud security best practices in their own accounts.
Event-Driven Architecture
Co-designed one of the platform’s most-used products: an event-driven backend (Lambda, SQS) that pulled compliance evidence from customers’ cloud accounts (AWS, Azure, GCP) & other related integrations (i.e. GitHub) which automated multi-cloud evidence collection across AWS, Azure, and GCP for customers.
Starbucks Coffee Company · Lead DevOps Engineer
Seattle, WA (Remote)Co-led a team of DevOps & software engineers to implement containerized microservices platform.
- Engineered highly resilient, repeatable, and secure cloud infrastructure
written in a declarative model to achieve infrastructure as code at scale that
could be easily adopted by software development teams
- AWS, Terraform, Kubernetes, Vault, Ansible, Concourse (CI/CD)
- Launched a global rewards program on the platform that handled millions of transactions a day and went on to host many more services for internal teams across the company
Clustrix · Infrastructure Engineer
San Francisco, CA- Engineer and maintain datacenter and cloud infrastructure
- 300+ physical servers
- 100+ virtual servers / container services
- Reduced data center power footprint saving $3k recurring monthly costs
- Procure, provision, configure and deploy new infrastructure and services (physical and cloud)
- Design, manage, and maintain automation relied upon by engineering, QA and
other teams
- PXE, kickstart, Ansible, Puppet, Python + Bash
- Assess, communicate and remediate risks associated within the IT infrastructure and systems
- Security vulnerabilities, hardware failure, business continuity
- Systematically develop and maintain internal documentation (MediaWiki & Confluence)
- Manage IT vendor relationships
- Vendor selection, contract renewals, licensing
CardFree · Sr. Infrastructure Engineer
San Francisco, CA- Engineer & maintain enterprise infrastructure through highly available
virtualized solutions
- Focus on engineering and maintaining back end systems and infrastructure for several of the largest white label mobile commerce initiatives in the U.S. spanning two datacenters and hundreds of nodes
- Created consistent and agile server infrastructure allowing for quick and painless builds by engineering environments-based roles and profiles model with Puppet (infrastructure as code)
- Implement infrastructure automation eliminating hours of manual processes through scripted jobs and reactionary alerts
- Improve environment health monitoring through Zabbix implementation and Splunk collection analytics, alerts and dashboards
- Develop highly effective working relationship with developers to achieve efficient, successful solutions and code deployments
Puppet
Saved hundreds of manual build hours and thousands of dollars on an underutilized Puppet Enterprise implementation by migrating to open source Puppet with roles and profiles model for five environments and three Puppet master servers. Created strong, well documented workflow for contribution and deployment with the use of Git, R10k, Hiera, custom Ruby Facter facts and tests for functionality, style and syntax.
Workstation Build and Maintenance
Recognized and improved inefficient workstation (Mac / OS X) onboarding and maintenance process by building and documenting a new solution that was successfully handed off for use by others.
Infrastructure Monitoring
Gained redundant health monitoring quickly utilizing Puppet to implement multiple Zabbix instances in multiple environments for greater insight into environment and faster, more reliable issue response times.
Local Development Platform
Contribute to local development platform by utilizing Puppet, Packer and Vagrant to build custom vagrant images that allow developers and team members to run solutions on virtual machines nearly identical to production eliminating numerous factors that can cause development and deployment issues downstream.
Westerra Credit Union · System Administrator II
Denver, CO- Maintain, implement and improve operations of enterprise server and desktop infrastructure (100+ server, 400+ desktop)
- Linux, Windows and Unix - Physical & Virtual environment (VMWare + Hyper-V)
- Primary on Linux environment, Nagios/Orion (Server Monitoring), Puppet/System Center (System Configuration), SharePoint
- Implement and architect interdepartmental needs and internal IT projects created from scratch to save money, create time efficiencies and reduced manual dependencies
- Change management, Power management, Vendor management (web based solutions)
- Other implementations that were able to reduce cost and increase efficiencies
- Ubuntu, Puppet, SVN, Nagios, VMWare
- System Center: Configuration Manager, Service Manager, Windows Deployment Services, Hyper-V, Solarwinds Orion
- Manage highly available systems and disaster recovery between multiple datacenters
- Perform a full disaster recovery test once every six months
- Part of small team that relocated two datacenters within six months (Denver to Las Vegas)
- Training/mentoring individuals on processes, solutions and products deployed
SCCM Implementation
Saved the organization ~240 manual hours quarterly by architecting new SCCM 2012 R2 infrastructure, a migration from 2007 R2 implementation, with automation being a key focus of the project.
Puppet Implementation
Implemented Puppet configuration management on small number of Linux servers, which allowed for more automated and streamlined processes.
Power Management
Saved power consumption on idle machines for the organization by implementing scripted power management solution; originally implemented using Linux & Bash, recently revamped using Windows and PowerShell.
Server Monitoring
Gained redundancy and extended monitoring with multi-site Nagios and Orion implementations.
Change Management Solution
Replaced multiple weekly meetings by creating an electronic automated change management process using SharePoint forms and workflows; requests submitted receive approvals in minutes instead of days.
SharePoint 2013 Migration
Proactively reallocated resources to correct an over taxed SharePoint 2010 single server farm by migrating to a multi-server SharePoint 2013 farm which is utilized by the whole organization.
Westerra Credit Union · IT Support Technician II
Denver, CO- Install, maintain, troubleshoot and repair computer systems, hardware and computer peripherals both on-site and remotely
Custom Windows Imaging
Streamlined and optimized imaging process with scripting and portable solution to allow for flexibility and gains in time efficiency, with this update imaging could be completed in one tenth of the time and was able to meet disaster recovery requirements that were not being met prior.
SCCM Implementation
Replaced archaic configuration management solution by implementing SCCM 2007 R2.
Jeffco Credit Union · PC Technician
Denver, CO- Handled various responsibilities:
- Daily technical processes within Unix environment
- PC and User support
- Install and maintain server, desktop and network infrastructure
- Architected and implemented virtual environment to simplify and streamline infrastructure
Education | Training
Technical Coursework
Golang, AWS, Cloud Architecture, RHEL, Ubuntu Linux