Sitemap
Petru Lucian Giurca
Petru Lucian Giurca
he/him

πŸ‘·β€β™‚οΈ DevSecOps Engineer with over a decade of IT experience and 5+ years designing and operating secure CI/CD pipelines across banking and enterprise environments. Specialist in implementing DevSecOps strategy end-to-end β€” planning, building, and upgrading pipelines with Git, GitHub, OpenShift, Helm, Kafka, and Istio β€” and embedding security throughout the SDLC. Experienced in code analysis and code-review feedback to development teams, ALM-driven continuous delivery, and building the tooling and infrastructure that support component development. Complementary background in adversarial smart-contract security research (Ethereum / EVM, Solidity). Fluent in English and Italian. πŸ› οΈ Core Technical Stack (Consolidated Matrix): βœ… Blockchain: Solidity, EVM, Foundry, Slither, Fuzzing, OpenZeppelin, Hardhat, Rust, Solana. βœ… DevSecOps: Kubernetes (RKE2/AKS/EKS), Terraform, GitHub Actions, Jenkins, Azure DevOps. βœ… Security: SAST/DAST (ZAP, SonarQube, Trivy), Pentesting, ISO 27001, SOC2, NIST. βœ… Cloud/Data: Azure, AWS, GCP, OpenStack, Prometheus, Grafana, Python, Go, Bash.

✨ Professional Experience ✨

🏒 Web3 Security Researcher - HCLTech (Financial Intermediaries) β€” Bucharest, May 2023 – Present

β€’ Conduct adversarial security research on Ethereum / EVM smart-contract systems (Solidity), identifying criticalvulnerability classes across pre-deployment and production codebases.

β€’ Apply static and dynamic analysis (Slither, Foundry, custom fuzzing harnesses) and produce reproducible proof-of-concept exploits with severity classification and remediation guidance.

β€’ Analyze code and communicate review findings to protocol engineering teams, embedding secure developmentpatterns throughout the SDLC.

β€’ Build internal security tooling and automation to scale vulnerability discovery and standardize research methodology.

ο»Ώ

🏒 DevSecOps Expert (Deutsche Bank UK) HCLTech β€” Bucharest, Oct 2022 – Apr 2023

β€’ Operated enterprise Kubernetes clusters for deployment and scaling of containerized banking applications, ensuringhigh availability and zero-downtime rolling updates across Production and DR environments.

β€’ Designed and maintained complete CI/CD pipelines using GitHub Actions (multi-stage, reusable workflows, matrixbuilds) for Java Spring Boot (Maven) and Rust (Cargo + musl) microservices, integrating security gates automatically.

β€’ Integrated SAST across Java and Rust codebases and DAST using OWASP ZAP (baseline, active scan, API scripting)directly in pipelines, with fail-fast enforcement and automated reporting to the security team.

β€’ Configured SCA for Maven and Cargo dependencies (OWASP Dependency-Check, Trivy, Dependabot) with automaticblocking of vulnerable artifacts (CVSS β‰₯ 7.0).

β€’ Developed modular Infrastructure-as-Code with Terraform (remote state in S3 + DynamoDB) for Kubernetes clusters,VPC networking, ingress-nginx, cert-manager, and policy enforcement (Kyverno / OPA Gatekeeper).

β€’ Implemented container and Kubernetes hardening: image scanning (Trivy / Grype), Pod Security Admission, NetworkPolicies, RBAC, External Secrets Operator + HashiCorp Vault, and runtime protection with Falco.

β€’ Advanced DevSecOps maturity to an β€œAdvanced” level per OWASP SAMM and NIST SSDF, including policy-as-code,supply-chain security (Sigstore/cosign), and SBOM generation (Syft).

β€’ Ensured compliance with banking standards (PCI-DSS 4.0, ISO 27001, GDPR, National Bank requirements) through automated reporting, evidence collection, and full audit trails.

ο»Ώ

🏒 DevSecOps Engineer (UniCredit S.p.A., Italy) Axsys Romania β€” Bucharest, Mar 2022 – Sep 2022

β€’ Built and administered private-cloud infrastructure on Red Hat OpenStack and deployed containerized workloads via Red Hat OpenShift, creating and managing pods and clusters across the platform.

β€’ Packaged and deployed applications to OpenShift using Helm charts, standardizing templated, versioned releases across environments.

β€’ Deployed and configured Istio service mesh for secure service-to-service communication (mTLS), traffic management, and observability across microservices.

β€’ Managed OpenShift / OpenStack node lifecycle on Red Hat Enterprise Linux (RHEL) and CoreOS, including OS patching, user access controls (PAM / sudoers), and kernel-parameter tuning for high-performance private-cloud networking.

β€’ Secured the container ecosystem at the Linux-kernel level β€” configuring cgroups and namespaces for strict process isolation and auditing file permissions to prevent privilege escalation on host nodes.

β€’ Led DevSecOps activities across vulnerability scanning, certificate management, password-policy management, and remediation/patching coordination.

β€’ Analyzed code and communicated code-review findings to development teams; enforced shift-left compliance for the Spring Boot stack via Maven-integrated SCA in Jenkins pipelines, blocking vulnerable transitive dependencies before packaging.

ο»Ώ

🏒 Senior DevOps Engineer (LEGO Group, Denmark) Arnia Software β€” Bucharest, Sep 2021 – Feb 2022

β€’ Managed the lifecycle of OpenShift clusters, ensuring seamless upgrades and patching of the underlying CoreOS nodes.

β€’ Optimized the developer experience with OpenShift Source-to-Image (S2I) workflows, letting teams push code directly from Git while OpenShift built secure, versioned container images β€” streamlining code-commit to deployment without complex Dockerfile management.

β€’ Managed application deployments with Helm charts, enabling repeatable, parameterized releases across OpenShift environments.

β€’ Provisioned Azure infrastructure with Terraform and Ansible, writing reusable, well-tested infrastructure code.

β€’ Designed and maintained SIEM use cases within Splunk ES, focusing on high-fidelity alerting and compliance reporting.

β€’ Worked with AWS services (EKS, CloudFormation, CloudWatch, Lambda, API Gateway, Aurora) and monitoring stacks (Prometheus, Grafana).

ο»Ώ

🏒 DevSecOps Specialist (Nordic RSC, Denmark) GE Digital β€” Bucharest, Jul 2019 – Aug 2021

β€’ Developed and maintained backend services in Go (net/http, gRPC/REST APIs), handling high concurrency, request routing, and robust error handling.

β€’ Maintained critical backend components for Longhorn and the Kubernetes CSI storage provider in Go, focusing on high-availability volume attach/detach/recovery workflows and CSI compliance.

β€’ Built observability into all services with Prometheus (client_golang), distributed tracing, and structured logging.

β€’ Operated Kafka (via Strimzi) on Kubernetes to support event-driven microservice architectures, and integrated SonarQube quality gates into Maven pipelines for Quarkus / JBoss services.

β€’ Managed ingestion, normalization, and correlation of security data into Microsoft Sentinel; conducted threat hunting and tuned automated investigation and response via Microsoft Defender.

β€’ Embedded shift-left security into Spring Boot microservices via Maven build profiles triggering SAST and SCA during compilation, before artifacts reached the Nexus Repository.

β€’ Architected multi-stage Azure DevOps YAML pipelines with mandatory security gates (SAST, secret scanning, dependency checks) deploying to Azure Kubernetes Service (AKS).

β€’ Performed security risk assessments and application/network vulnerability scanning; mentored team members and drove security awareness across the organization.

ο»Ώ

🏒 IT System Engineer / Cloud Engineer BullGuard β€” Bucharest, Apr 2018 – Jun 2019

β€’ Served as Cloud Engineer for a global B2C cybersecurity vendor, migrating critical backend infrastructure to Microsoft Azure and adopting modern DevOps practices.

β€’ Provided architectural recommendations to improve efficiency, reliability, and performance while reducing cost.

β€’ Deployed Prometheus and Grafana for advanced monitoring, enabling proactive resolution of performance bottlenecks.

β€’ Contributed to Agile ceremonies and collaborated with architects to define secure, scalable enterprise cloud products.

ο»Ώ

🏒 Linux System Administrator StarTechTeam β€” Bucharest, Apr 2014 – Mar 2018

β€’ Administered a complex RHEL6 environment, performing kernel upgrades, security patching, and driver integration to ensure 99.9% availability.

β€’ Managed VMware ESXi virtualization (VM lifecycle, snapshots, resource allocation) and improved the virtualization stack.

β€’ Used Puppet for configuration management to enforce desired state and compliance across systems.

β€’ Executed backup/restore procedures and monitored system health to ensure business continuity.

ο»Ώ

🏒 Help Desk Support Specialist (Italian) Genpact β€” Bucharest, Jan 2009 – Mar 2014

β€’ Managed the end-to-end incident lifecycle for complex telecom faults (VoIP, MPLS, Fiber), bridging enterprise clients and T3 network engineers.

β€’ Resolved T1/T2 technical and product support inquiries via ticketing, live chat, and phone; escalated and tracked faults through resolution.

ο»Ώ

✨ Education ✨

πŸŽ“ Master's Degree, Law Spiru Haret University, Bucharest | 2008 – 2010

πŸŽ“ Bachelor's Degree, Law Spiru Haret University, Bucharest | 2004 – 2008

ο»Ώ

✨ Certifications ✨

πŸš€ Web3 & Blockchain

πŸš€ Cloud & DevSecOps

ο»ΏDevSecOps Engineerο»Ώ

πŸš€ AI & Data

πŸš€ Projects

Medium member since December 2022