Gabriel Emmanuel Idachaba in a black suit, photographed in profile against a red and purple studio background

Current remit

Senior DevSecOps Engineer

a London-headquartered DeFi protocol · London, UK — remote · Mar 2023 — present

I own the multi-account Terraform estate, EKS node lifecycle, the delivery pipeline and the security posture. I do not own application code or smart contracts.

Working rules

The reasoning visible in the work.

Infrastructure

Keep authentication at the environment boundary.

Reusable Terraform modules describe infrastructure; they do not own environment-specific authentication.

Architecture

Treat data differently from compute.

Application compute is replaceable; data is not. Managed, encrypted and backed up by default rather than by discipline.

Operations

A detection needs a response path.

A detection with no runbook produces a page nobody knows how to action. Mapping to ATT&CK turns alerts into coverage whose gaps can be found.

Experience

Scope, ownership and operating context.

Mar 2023 — present

London, UK — remote

Senior DevSecOps Engineer

a London-headquartered DeFi protocol

I own the multi-account Terraform estate, EKS node lifecycle, the delivery pipeline and the security posture. I do not own application code or smart contracts.

  • Architected a production AWS EKS platform in Terraform supporting multi-environment workloads, with dynamic autoscaling through Karpenter and KEDA.
  • Rebuilt delivery around GitOps — Jenkins, GitHub Actions and ArgoCD orchestrating Helm releases. Median pipeline fell from 35 to 20 minutes, measured as ArgoCD sync plus Helm rollout across 90-day medians either side of the migration.
  • Automated multi-account provisioning with Terraform and Ansible, cutting environment setup from days to under an hour.
  • Ran to a 99.9% monthly availability SLO on successful request ratio at the edge, with an enforced error-budget policy: two consecutive breaching months froze feature rollout in favour of reliability work.
  • Designed a PCI-DSS-aligned architecture — IAM least privilege, Secrets Manager, VPC segmentation, Route 53, WAF, Security Hub, and centralised telemetry via AWS Security Lake with OpenSearch and Athena.
  • Built a unified observability platform on Prometheus, Grafana, Loki, Jaeger and Alertmanager with severity-routed alerting, cutting MTTR by 30%.

Concurrent

Wuse 2, Abuja, Nigeria

Concurrent

Senior DevSecOps Engineer

Zyntrix Technologies Limited

I own infrastructure, delivery, security and observability, and built the Python integration services. Odoo functional configuration sits with the ERP team.

  • Infrastructure provisioning, secure CI/CD, security posture and observability across four client platforms spanning retail, hospitality, e-commerce and cooperative finance.
  • One delivery standard across nine runtimes — AWS, Azure, GCP, Vercel, Render, Railway, Heroku, App Engine and Azure App Service — selected per client against operability after handover, compliance, cost at their scale, traffic shape and warmth requirements.
  • Built the Python services keeping Shopify, Odoo and Glovo consistent for a gifting retailer, including the idempotency, retry and reconciliation design that none of those platform APIs provide.

Jan 2022 — Mar 2023

Remote

Platform Engineer — contract

Radiant Commons

  • Built the AWS estate for a privacy-focused Cosmos chain in modular Terraform — VPC, EKS, KMS, ACM, and public and private Route 53 zones — with per-service-account IAM through IRSA rather than shared node roles.
  • Ran Penumbra full nodes as stateful workloads under the Cosmos Operator, on gp3 volumes for chain data behind an ALB with sticky sessions: the chain's streaming gRPC connections break when consecutive requests land on different backends.
  • Delivered every workload through ArgoCD ApplicationSets from a single GitOps repository across development, shared and OVH environments, with image bumps committed by automation carrying the source commit SHA.
  • Packaged the chain's public services — block explorer, tokenomics dashboard, governance voting app and indexer — as Helm charts, with Karpenter provisioning nodes on demand.

Aug 2020 — Dec 2021

Abuja, Nigeria

DevOps / Platform Engineer

Zenith Chain

  • Operated blockchain nodes, wallet services and indexers on Kubernetes across 20+ microservices, sustaining 99.99% uptime through high-availability configuration and automated failover.
  • Cut cloud spend 35% with KEDA event-driven autoscaling and workload right-sizing.
  • Raised deployment frequency 3× with zero-downtime releases.
  • Reduced incident detection and diagnosis time 30% via Prometheus, Grafana, Loki and OpenTelemetry, and cut environment provisioning 60% with reusable Terraform modules.

Apr 2019 — Jul 2020

London, UK — remote

DevOps Engineer

PeoplePerHour

  • Multi-client DevOps engagements standardising CI/CD and containerised deployment with Jenkins, Docker and Kubernetes, cutting release cycle times 30–40%.
  • Supported 5+ client environments across development and production.
  • Automated DNS with Kubernetes external-dns and Route 53, reducing service exposure time from hours to minutes.