Name : Su
Role : DevSecOps & Cloud Security Engineer
Focus : Zero-Trust Architecture · Cloud Security Automation· Supply-Chain Security
Growing Into: AI Security, LLM guardrails, prompt injection defense, policy enforcement
Available : Open to DevSecOps | Platform | Cloud Security roles | open to relocation 🌍- 🔐 I design and ship zero-trust cloud platforms, signed and verified container images, policy enforced at admission time.
- 🛡️ I believe security should be shifted left and automated, not bolted, on every project I ship has scanning, signing, and policy gates built into CI/CD from day one.
- 🤖 Currently expanding into AI security, hands-on with prompt injection testing and LLM policy enforcement pipelines, applying the same automation-first instincts to a new attack surface.
- 👯 Open to collaborating on open-source DevSecOps and cloud security tooling.
- 💬 Ask me about zero-trust networking, Kubernetes hardening, supply-chain security, or AI/LLM security.
- 🧭 The best security team is the one that makes it easier to do the right thing than the wrong thing.
Cloud & Infrastructure
Containers & Kubernetes
Zero-Trust & Kubernetes Security
Application & Supply-Chain Security
CI/CD & GitOps
Languages & Scripting
Monitoring & Observability
AWS
Security & Cloud-Native
| Project | Description | Stack |
|---|---|---|
| online-boutique-aaws-pf | Zero-trust 11-microservice platform on AWS ECS Fargate, zero NAT gateways, 7 PrivateLink endpoints, Cognito JWT authorization, fully OIDC-federated CI/CD. Live and verified end-to-end. | AWS ECS Fargate · PrivateLink · Cognito · API Gateway · OIDC |
| online-boutique-doks-pf | GitOps security platform on DigitalOcean Kubernetes, Argo CD managing 17 child apps, Kyverno CEL policy enforcement, Falco eBPF runtime detection, Linkerd mTLS, full observability stack. | Kubernetes · Argo CD · Kyverno · Falco · Linkerd |
| online-boutique-app | Application/CI repo for the boutique platform series, every image scanned, Cosign-signed, and cryptographically verified before deployment. | GitHub Actions · Trivy · TruffleHog · Cosign |
| ai-security-lab | CI/CD policy enforcement pipeline for LLM inputs/outputs, plus hands-on prompt injection testing. Documents real limitations of regex-based AI guardrails. | Python · Ollama · CI/CD Policy Gating |
| 3tier-k8s-Hardening | NSA/CISA-aligned Kubernetes hardening lab, documented before/after moving from Privileged to Restricted Pod Security Standards, with asciinema recordings. | Kubernetes · Pod Security Standards · NetworkPolicies |
| online-boutique-pf | Single-droplet zero-trust deployment on DigitalOcean, Tailscale instead of a bastion host, signed images, 3-stage CI security gate. | Docker Compose · Tailscale · Cosign · Terraform |


