Johannesburg based · open to remote roles globally

Lead DevSecOps &
Cloud Security Engineer.

I build secure-by-default platforms on Azure and AWS: landing zones, hardened CI/CD, policy-as-code guardrails, and supply-chain controls that let engineering teams ship faster without breaking compliance.

Azure AWS Terraform Ansible Kubernetes GitHub Actions GitLab CI Checkov · Trivy · Gitleaks OPA HashiCorp Vault Python · PowerShell · Bash

// about

Security is a platform problem.

I'm a Lead DevSecOps Engineer based in Johannesburg with 16+ years of experience embedding security into the way engineering organisations actually ship software. My career has been spent inside regulated financial services, global enterprise, and cloud platform environments where the stakes for getting it right are real.

I treat security as a platform discipline, not a department. Most "DevSecOps" failures I've seen come from bolting scanners onto pipelines after the fact, then blaming developers for the noise. The work that actually moves the needle looks like secure-by-default templates, policy-as-code in the deployment path, and guardrails engineers can opt into rather than fight.

I'm currently focused on DevSecOps strategy across multi-cloud estates and public project work that shows how I design secure CI/CD, cloud guardrails, Kubernetes baselines, and response automation. I'm open to senior remote roles globally where I can shape the engineering culture, not just the tooling.

// current projects

What I'm building now.

Active public DevOps and DevSecOps projects with working code, pipeline examples, and GitHub history.

View all GitHub repos

Current build

Secure CI/CD Starter

Reusable GitHub Actions workflow for app tests, dependency audit, secret scanning, IaC scanning, container image scanning, and SBOM generation.

GitHub ActionsGitleaksCheckovTrivySyftDocker
Open on GitHub

Current lab

SonarQube + Trivy DevSecOps Lab

Local Jenkins and SonarQube lab with a sample Node service, quality gate, Docker image build, Trivy scan, and remediation notes.

JenkinsSonarQubeTrivyDockerNode.js
Open on GitHub

// github-ready work

DevOps & DevSecOps projects.

Public project tracks designed to show practical DevSecOps depth: secure pipelines, cloud guardrails, Kubernetes hardening, code quality, container scanning, and operational response.

Ready to publish

Secure CI/CD Starter

Reusable GitHub Actions templates for building, scanning, signing, and releasing container services with security gates that engineers can copy into real repositories.

Shows practical shift-left delivery: secrets detection, SAST, IaC checks, SBOM generation, image scanning, and signed artifacts in one pipeline.

GitHub ActionsGitleaksSemgrepCheckovTrivySyftCosign
Open project scope

Next build

Terraform Azure Landing Zone Lite

Small but realistic Azure landing zone module with identity, networking, policy, tagging, budget, logging, and least-privilege defaults.

Demonstrates cloud platform engineering, secure-by-default infrastructure, and governance-as-code for regulated teams.

TerraformAzureAzure PolicyCheckovOPAGitHub OIDC
Open project scope

Next build

Kubernetes Security Baseline

AKS/EKS-ready hardening baseline with namespaces, network policies, RBAC, admission controls, image scanning, and secure Helm examples.

Shows container platform depth: workload identity, policy enforcement, runtime visibility, and deployable secure defaults.

KubernetesHelmOPA GatekeeperTrivyFalcoPrometheus
Open project scope

Portfolio lab

SonarQube + Trivy DevSecOps Lab

Hands-on lab that builds a Java or Node service, runs code quality and security checks, scans the container image, and publishes findings.

Turns tutorial-style DevSecOps learning into your own working lab with screenshots, pipeline logs, and clear remediation notes.

JenkinsSonarQubeTrivyDockerMaven or NodeGitHub
Open project scope

// github activity

Open source activity.

Public commits, project work, and contribution history connected directly to my GitHub profile.

View GitHub profile
Rachel Khoza GitHub contribution activity chart

// stack

What I work with day-to-day.

Cloud & Platform

  • ·Azure
  • ·AWS
  • ·Multi-Cloud Landing Zones
  • ·Well-Architected
  • ·FinOps

Security & Compliance

  • ·DevSecOps
  • ·SAST / DAST
  • ·IaC Security (Checkov, tfsec, Terrascan)
  • ·Container Security (Trivy, Aqua)
  • ·Supply Chain (SBOM, SLSA, Cosign)
  • ·HashiCorp Vault
  • ·IAM · Zero Trust · OIDC Federation
  • ·ISO 27001 · PCI-DSS · SOC 2

Infrastructure as Code

  • ·Terraform
  • ·Ansible (AAP)
  • ·Helm
  • ·Pulumi

CI / CD

  • ·GitHub Actions
  • ·GitLab CI
  • ·Jenkins
  • ·Azure DevOps
  • ·ArgoCD

Containers & Orchestration

  • ·Kubernetes (EKS, AKS)
  • ·Docker
  • ·Istio

Observability

  • ·Azure Monitor
  • ·Grafana
  • ·Prometheus
  • ·Splunk
  • ·ELK
  • ·Dynatrace

Programming

  • ·Python
  • ·PowerShell
  • ·Bash
  • ·SQL
  • ·JavaScript

// credentials

Certifications.

Cloud

  • AWS Certified DevOps Engineer — Professional

    2023

  • Microsoft Azure Fundamentals (AZ-900)

    2024

Security

  • ISC² Certified in Cybersecurity (CC)

    2023

  • Cybersecurity: Managing Risk — Harvard

    2021

IaC & Data

  • HashiCorp Terraform Associate

    2022

  • AWS Certified Machine Learning — Specialty

    2021

// contact

Let's talk.

Best for Lead, Principal or Staff Cloud Security / DevSecOps roles. Open to remote globally; based in Johannesburg.