Senior DevSecOps Engineer
a London-headquartered DeFi protocol
I own the multi-account Terraform estate, EKS node lifecycle, the delivery pipeline and the security posture. I do not own application code or smart contracts.
- Architected a production AWS EKS platform in Terraform supporting multi-environment workloads, with dynamic autoscaling through Karpenter and KEDA.
- Rebuilt delivery around GitOps — Jenkins, GitHub Actions and ArgoCD orchestrating Helm releases. Median pipeline fell from 35 to 20 minutes, measured as ArgoCD sync plus Helm rollout across 90-day medians either side of the migration.
- Automated multi-account provisioning with Terraform and Ansible, cutting environment setup from days to under an hour.
- Ran to a 99.9% monthly availability SLO on successful request ratio at the edge, with an enforced error-budget policy: two consecutive breaching months froze feature rollout in favour of reliability work.
- Designed a PCI-DSS-aligned architecture — IAM least privilege, Secrets Manager, VPC segmentation, Route 53, WAF, Security Hub, and centralised telemetry via AWS Security Lake with OpenSearch and Athena.
- Built a unified observability platform on Prometheus, Grafana, Loki, Jaeger and Alertmanager with severity-routed alerting, cutting MTTR by 30%.