I'm a DevOps Engineer building toward the next generation of cloud and platform engineering.
My focus isn't simply on deploying applications.
It's on engineering environments where:
CODE
↓
AUTOMATION
↓
INFRASTRUCTURE
↓
CLOUD
↓
SECURITY
↓
IDENTITY
↓
OBSERVABILITY
↓
RESILIENCE
Everything should be automated, reproducible, observable, secure and scalable.
I work across the boundary between development, infrastructure and cybersecurity, using DevOps and DevSecOps principles to transform manual infrastructure into reliable engineering platforms.
If it can be automated → automate it. If it can be measured → observe it. If it can be secured → secure it by design. If it can fail → engineer for resilience.
|
Azure AWS Cloud Architecture Networking Storage |
CI/CD Git Automation Release Engineering Platform Engineering |
Terraform Infrastructure Provisioning Configuration Automation |
DevSecOps IAM Zero Trust Secrets Cloud Security |
Monitoring Logging Observability Reliability Resilience |
I think beyond individual deployments.
The goal is to create repeatable engineering platforms that allow teams to ship faster without sacrificing security or reliability.
┌─────────────────────┐
│ DEVELOPERS │
└──────────┬──────────┘
│
▼
┌─────────────────────┐
│ DEVELOPER │
│ PLATFORM │
└──────────┬──────────┘
│
┌────────────────┼────────────────┐
▼ ▼ ▼
┌─────────┐ ┌─────────┐ ┌─────────┐
│ CI/CD │ │ IaC │ │ CLOUD │
└────┬────┘ └────┬────┘ └────┬────┘
│ │ │
└────────────────┼────────────────┘
▼
┌─────────────────┐
│ DEVSECOPS │
└────────┬────────┘
▼
┌─────────────────┐
│ IAM • SECURITY │
└────────┬────────┘
▼
┌─────────────────┐
│ OBSERVABILITY │
└────────┬────────┘
▼
┌─────────────────┐
│ RESILIENCE │
└─────────────────┘
Cloud • Containers • Kubernetes • IaC • CI/CD • Automation • Linux • Scripting
Infrastructure should be versioned, repeatable and reproducible.
Infrastructure as Code
│
├── Terraform
├── Configuration
├── Networking
├── Identity
├── Security
└── Deployment
│
▼
Git-based workflow
│
▼
CI/CD
│
▼
Automated validation
│
▼
Cloud deployment
Terraform · Azure · AWS · GitHub Actions · Azure DevOps · Automation
Security isn't a final pipeline stage.
It's part of the architecture.
PLAN
↓
CODE
↓
BUILD
↓
TEST
↓
SECURITY
↓
PACKAGE
↓
DEPLOY
↓
OBSERVE
↓
IMPROVE
↺
🔐 Secrets Management 🛡️ Vulnerability Management 🔎 Security Testing 🐳 Container Security ☁️ Cloud Security 🔑 IAM 📦 Dependency Security ⚙️ Secure CI/CD 📊 Security Monitoring
Modern infrastructure requires modern identity.
My IAM focus includes:
Microsoft Entra ID
→ Identity & Access → RBAC → Conditional Access → Managed Identities → Service Principals → Authentication → Authorization → Least Privilege → Identity Governance → Zero Trust
USER
↓
IDENTITY
↓
AUTHENTICATION
↓
AUTHORIZATION
↓
POLICY
↓
RESOURCE
↓
AUDIT
Azure DevOps · Azure Networking · Azure Monitor · Azure Container Apps · Azure Storage · Entra ID
IAM · EC2 · VPC · S3 · CloudWatch · Cloud-native architecture
I'm interested in the evolution from:
Servers → Virtual Machines → Containers → Kubernetes → Platforms
🐳 Docker ☸️ Kubernetes ☁️ Azure Container Apps 🏗️ Terraform ⚙️ CI/CD 🔐 Container Security 📊 Observability
You can't operate what you can't see.
My observability mindset:
┌────────────┐
│ METRICS │
└─────┬──────┘
│
┌──────────┐ ▼ ┌──────────┐
│ LOGS │ → SYSTEM ← │ TRACES │
└──────────┘ │ └──────────┘
▼
ALERTING
│
▼
INCIDENT RESPONSE
│
▼
IMPROVEMENT
Azure Monitor • Log Analytics • Metrics • Logs • Alerts • Dashboards
My engineering interests are strongly influenced by the security and resilience requirements of banking and financial technology environments.
Financial systems require infrastructure that is:
Secure
Highly available
Auditable
Observable
Resilient
Automated
Controlled
That means DevOps cannot operate independently from security and governance.
DEVOPS
│
▼
SECURITY
│
▼
IAM
│
▼
RESILIENCE
│
▼
AUDITABILITY
│
▼
TRUST
Areas of interest include:
Cloud Security · IAM · DORA · ISO 27001 · NIST · PCI DSS · Operational Resilience
Building cloud environments using:
Terraform + Azure + CI/CD + IAM + Monitoring
Experimenting with:
GitHub Actions → Security Checks → Container Build → Deployment → Monitoring
Exploring:
IAM → Cloud Security → Risk → Controls → Auditability → Resilience
I contribute to public cloud, FinOps and DevOps projects. My changes go through the normal fork → feature branch → pull request → review → merge workflow.
An open-source, provider-neutral FinOps data platform with Arrow-based pipelines, SQL-first governance policies, and DuckDB, Postgres and BigQuery destinations.
- Added a
reportcommand to the CLI that writes cost findings as an HTML report. - Added Slack/webhook notifications so findings can be pushed to team channels.
- Added PyPI package metadata and a PyPI publish step to the GitHub Actions release workflow.
- Wrote three new SQL cost policies that detect idle Azure API Management, Azure Kubernetes Fleet Manager and Azure Managed HSM resources.
- Covered every change with
pytesttests: 8 new test files across the policies, the report, notifications, packaging and the release workflow. - +417 lines across 13 files. Reviewed, approved and merged by the maintainer.
🔗 Pull Request: raphgm/cloudcost-cli#24
An open-source, context-aware digital workspace that works with any AI provider, with Azure OpenAI preferred.
- Added myself to
CONTRIBUTORS.mdas a project contributor. - Added a standard
.gitignoreso that local environment variables and OS-generated files are not committed. - Reviewed, approved and merged by the maintainer.
🔗 Pull Request: raphgm/pinpointpro#46
- 2 merged pull requests, both reviewed and approved by the project maintainer.
- Delivered features, cost-governance policies, CI/CD release automation and test coverage to a real FinOps codebase.
- Comfortable with the full open-source collaboration workflow: issues, forks, branches, PRs, code review and merges.
Looking forward to contributing more to open-source Cloud, DevOps, FinOps and DevSecOps projects.
🔎 Explore Applied Skills
| Area | Applied Skill | Credential |
|---|---|---|
| 🤖 AI | Resolve GitHub issues by using GitHub Copilot | View Skill |
| 🏢 Infrastructure | Administer Active Directory Domain Services | View Skill |
| ⚙️ DevOps | Implement security through a pipeline using Azure DevOps | View Skill |
| ☁️ Cloud | Deploy cloud-native apps using Azure Container Apps | View Skill |
| 🔐 Identity | Get started with identities and access using Microsoft Entra | View Skill |
| 🌐 Networking | Configure secure access to your workloads using Azure networking | View Skill |
| 🛡️ Security | Get started with cloud security and monitoring tasks | View Skill |
| 📊 Monitoring | Deploy and configure Azure Monitor | View Skill |
| ⚙️ Management | Get started with Azure management tasks | View Skill |
| 💾 Storage | Secure storage for Azure Files and Azure Blob Storage | View Skill |
📜 View credentials
- ISO/IEC 27001:2022 Lead Implementer
- ISO 27001 Lead Auditor
- ISO 42001 Lead Auditor
- ISO 27701 Lead Auditor
- ISO 31000 Risk Management
- CompTIA Security+
- CompTIA CySA+
- Proofpoint Certified Security Awareness Specialist
- Certified Cybersecurity & Privacy Professional
- Certified Governance, Risk & Compliance Auditor
- Certified Privacy & Protection Specialist
┌───────────────┐
│ DEVELOPER │
│ EXPERIENCE │
└───────┬───────┘
│
▼
┌──────────────────┐
│ PLATFORM ENGINEER│
└────────┬─────────┘
│
┌─────────────┼─────────────┐
▼ ▼ ▼
CLOUD SECURITY DATA
│ │ │
└─────────────┼─────────────┘
▼
┌──────────────────┐
│ INTELLIGENT │
│ AUTOMATION │
└────────┬─────────┘
▼
┌──────────────────┐
│ SELF-HEALING & │
│ RESILIENT SYSTEMS│
└──────────────────┘
The long-term goal is to move beyond simply managing infrastructure toward engineering intelligent, secure and increasingly autonomous platforms.
AUTOMATE
↓
SECURE
↓
DEPLOY
↓
OBSERVE
↓
LEARN
↓
IMPROVE
↺
Infrastructure should be reproducible.
Security should be continuous.
Identity should be explicit.
Observability should be built in.
Automation should remove friction.
Resilience should be engineered — not assumed.
Engineering the infrastructure behind the next generation of secure digital platforms.
STEЕVE.DEVOPS
