Current build
Secure CI/CD Starter
Reusable GitHub Actions workflow for app tests, dependency audit, secret scanning, IaC scanning, container image scanning, and SBOM generation.
I build secure-by-default platforms on Azure and AWS: landing zones, hardened CI/CD, policy-as-code guardrails, and supply-chain controls that let engineering teams ship faster without breaking compliance.
// about
I'm a Lead DevSecOps Engineer based in Johannesburg with 16+ years of experience embedding security into the way engineering organisations actually ship software. My career has been spent inside regulated financial services, global enterprise, and cloud platform environments where the stakes for getting it right are real.
I treat security as a platform discipline, not a department. Most "DevSecOps" failures I've seen come from bolting scanners onto pipelines after the fact, then blaming developers for the noise. The work that actually moves the needle looks like secure-by-default templates, policy-as-code in the deployment path, and guardrails engineers can opt into rather than fight.
I'm currently focused on DevSecOps strategy across multi-cloud estates and public project work that shows how I design secure CI/CD, cloud guardrails, Kubernetes baselines, and response automation. I'm open to senior remote roles globally where I can shape the engineering culture, not just the tooling.
// current projects
Active public DevOps and DevSecOps projects with working code, pipeline examples, and GitHub history.
Current build
Reusable GitHub Actions workflow for app tests, dependency audit, secret scanning, IaC scanning, container image scanning, and SBOM generation.
Current lab
Local Jenkins and SonarQube lab with a sample Node service, quality gate, Docker image build, Trivy scan, and remediation notes.
// github-ready work
Public project tracks designed to show practical DevSecOps depth: secure pipelines, cloud guardrails, Kubernetes hardening, code quality, container scanning, and operational response.
Ready to publish
Reusable GitHub Actions templates for building, scanning, signing, and releasing container services with security gates that engineers can copy into real repositories.
Shows practical shift-left delivery: secrets detection, SAST, IaC checks, SBOM generation, image scanning, and signed artifacts in one pipeline.
Next build
Small but realistic Azure landing zone module with identity, networking, policy, tagging, budget, logging, and least-privilege defaults.
Demonstrates cloud platform engineering, secure-by-default infrastructure, and governance-as-code for regulated teams.
Next build
AKS/EKS-ready hardening baseline with namespaces, network policies, RBAC, admission controls, image scanning, and secure Helm examples.
Shows container platform depth: workload identity, policy enforcement, runtime visibility, and deployable secure defaults.
Portfolio lab
Hands-on lab that builds a Java or Node service, runs code quality and security checks, scans the container image, and publishes findings.
Turns tutorial-style DevSecOps learning into your own working lab with screenshots, pipeline logs, and clear remediation notes.
// github activity
Public commits, project work, and contribution history connected directly to my GitHub profile.
// stack
Cloud & Platform
Security & Compliance
Infrastructure as Code
CI / CD
Containers & Orchestration
Observability
Programming
// credentials
Cloud
AWS Certified DevOps Engineer — Professional
2023
Microsoft Azure Fundamentals (AZ-900)
2024
Security
ISC² Certified in Cybersecurity (CC)
2023
Cybersecurity: Managing Risk — Harvard
2021
IaC & Data
HashiCorp Terraform Associate
2022
AWS Certified Machine Learning — Specialty
2021
// contact
Best for Lead, Principal or Staff Cloud Security / DevSecOps roles. Open to remote globally; based in Johannesburg.