π·ββοΈ DevSecOps Engineer with over a decade of IT experience and 5+ years designing and operating secure CI/CD pipelines across banking and enterprise environments. Specialist in implementing DevSecOps strategy end-to-end β planning, building, and upgrading pipelines with Git, GitHub, OpenShift, Helm, Kafka, and Istio β and embedding security throughout the SDLC. Experienced in code analysis and code-review feedback to development teams, ALM-driven continuous delivery, and building the tooling and infrastructure that support component development. Complementary background in adversarial smart-contract security research (Ethereum / EVM, Solidity). Fluent in English and Italian. π οΈ Core Technical Stack (Consolidated Matrix): β Blockchain: Solidity, EVM, Foundry, Slither, Fuzzing, OpenZeppelin, Hardhat, Rust, Solana. β DevSecOps: Kubernetes (RKE2/AKS/EKS), Terraform, GitHub Actions, Jenkins, Azure DevOps. β Security: SAST/DAST (ZAP, SonarQube, Trivy), Pentesting, ISO 27001, SOC2, NIST. β Cloud/Data: Azure, AWS, GCP, OpenStack, Prometheus, Grafana, Python, Go, Bash.
β¨ Professional Experience β¨
π’ Web3 Security Researcher - HCLTech (Financial Intermediaries) β Bucharest, May 2023 β Present
β’ Conduct adversarial security research on Ethereum / EVM smart-contract systems (Solidity), identifying criticalvulnerability classes across pre-deployment and production codebases.
β’ Apply static and dynamic analysis (Slither, Foundry, custom fuzzing harnesses) and produce reproducible proof-of-concept exploits with severity classification and remediation guidance.
β’ Analyze code and communicate review findings to protocol engineering teams, embedding secure developmentpatterns throughout the SDLC.
β’ Build internal security tooling and automation to scale vulnerability discovery and standardize research methodology.
ο»Ώ
π’ DevSecOps Expert (Deutsche Bank UK) HCLTech β Bucharest, Oct 2022 β Apr 2023
β’ Operated enterprise Kubernetes clusters for deployment and scaling of containerized banking applications, ensuringhigh availability and zero-downtime rolling updates across Production and DR environments.
β’ Designed and maintained complete CI/CD pipelines using GitHub Actions (multi-stage, reusable workflows, matrixbuilds) for Java Spring Boot (Maven) and Rust (Cargo + musl) microservices, integrating security gates automatically.
β’ Integrated SAST across Java and Rust codebases and DAST using OWASP ZAP (baseline, active scan, API scripting)directly in pipelines, with fail-fast enforcement and automated reporting to the security team.
β’ Configured SCA for Maven and Cargo dependencies (OWASP Dependency-Check, Trivy, Dependabot) with automaticblocking of vulnerable artifacts (CVSS β₯ 7.0).
β’ Developed modular Infrastructure-as-Code with Terraform (remote state in S3 + DynamoDB) for Kubernetes clusters,VPC networking, ingress-nginx, cert-manager, and policy enforcement (Kyverno / OPA Gatekeeper).
β’ Implemented container and Kubernetes hardening: image scanning (Trivy / Grype), Pod Security Admission, NetworkPolicies, RBAC, External Secrets Operator + HashiCorp Vault, and runtime protection with Falco.
β’ Advanced DevSecOps maturity to an βAdvancedβ level per OWASP SAMM and NIST SSDF, including policy-as-code,supply-chain security (Sigstore/cosign), and SBOM generation (Syft).
β’ Ensured compliance with banking standards (PCI-DSS 4.0, ISO 27001, GDPR, National Bank requirements) through automated reporting, evidence collection, and full audit trails.
ο»Ώ
π’ DevSecOps Engineer (UniCredit S.p.A., Italy) Axsys Romania β Bucharest, Mar 2022 β Sep 2022
β’ Built and administered private-cloud infrastructure on Red Hat OpenStack and deployed containerized workloads via Red Hat OpenShift, creating and managing pods and clusters across the platform.
β’ Packaged and deployed applications to OpenShift using Helm charts, standardizing templated, versioned releases across environments.
β’ Deployed and configured Istio service mesh for secure service-to-service communication (mTLS), traffic management, and observability across microservices.
β’ Managed OpenShift / OpenStack node lifecycle on Red Hat Enterprise Linux (RHEL) and CoreOS, including OS patching, user access controls (PAM / sudoers), and kernel-parameter tuning for high-performance private-cloud networking.
β’ Secured the container ecosystem at the Linux-kernel level β configuring cgroups and namespaces for strict process isolation and auditing file permissions to prevent privilege escalation on host nodes.
β’ Led DevSecOps activities across vulnerability scanning, certificate management, password-policy management, and remediation/patching coordination.
β’ Analyzed code and communicated code-review findings to development teams; enforced shift-left compliance for the Spring Boot stack via Maven-integrated SCA in Jenkins pipelines, blocking vulnerable transitive dependencies before packaging.
ο»Ώ
π’ Senior DevOps Engineer (LEGO Group, Denmark) Arnia Software β Bucharest, Sep 2021 β Feb 2022
β’ Managed the lifecycle of OpenShift clusters, ensuring seamless upgrades and patching of the underlying CoreOS nodes.
β’ Optimized the developer experience with OpenShift Source-to-Image (S2I) workflows, letting teams push code directly from Git while OpenShift built secure, versioned container images β streamlining code-commit to deployment without complex Dockerfile management.
β’ Managed application deployments with Helm charts, enabling repeatable, parameterized releases across OpenShift environments.
β’ Provisioned Azure infrastructure with Terraform and Ansible, writing reusable, well-tested infrastructure code.
β’ Designed and maintained SIEM use cases within Splunk ES, focusing on high-fidelity alerting and compliance reporting.
β’ Worked with AWS services (EKS, CloudFormation, CloudWatch, Lambda, API Gateway, Aurora) and monitoring stacks (Prometheus, Grafana).
ο»Ώ
π’ DevSecOps Specialist (Nordic RSC, Denmark) GE Digital β Bucharest, Jul 2019 β Aug 2021
β’ Developed and maintained backend services in Go (net/http, gRPC/REST APIs), handling high concurrency, request routing, and robust error handling.
β’ Maintained critical backend components for Longhorn and the Kubernetes CSI storage provider in Go, focusing on high-availability volume attach/detach/recovery workflows and CSI compliance.
β’ Built observability into all services with Prometheus (client_golang), distributed tracing, and structured logging.
β’ Operated Kafka (via Strimzi) on Kubernetes to support event-driven microservice architectures, and integrated SonarQube quality gates into Maven pipelines for Quarkus / JBoss services.
β’ Managed ingestion, normalization, and correlation of security data into Microsoft Sentinel; conducted threat hunting and tuned automated investigation and response via Microsoft Defender.
β’ Embedded shift-left security into Spring Boot microservices via Maven build profiles triggering SAST and SCA during compilation, before artifacts reached the Nexus Repository.
β’ Architected multi-stage Azure DevOps YAML pipelines with mandatory security gates (SAST, secret scanning, dependency checks) deploying to Azure Kubernetes Service (AKS).
β’ Performed security risk assessments and application/network vulnerability scanning; mentored team members and drove security awareness across the organization.
ο»Ώ
π’ IT System Engineer / Cloud Engineer BullGuard β Bucharest, Apr 2018 β Jun 2019
β’ Served as Cloud Engineer for a global B2C cybersecurity vendor, migrating critical backend infrastructure to Microsoft Azure and adopting modern DevOps practices.
β’ Provided architectural recommendations to improve efficiency, reliability, and performance while reducing cost.
β’ Deployed Prometheus and Grafana for advanced monitoring, enabling proactive resolution of performance bottlenecks.
β’ Contributed to Agile ceremonies and collaborated with architects to define secure, scalable enterprise cloud products.
ο»Ώ
π’ Linux System Administrator StarTechTeam β Bucharest, Apr 2014 β Mar 2018
β’ Administered a complex RHEL6 environment, performing kernel upgrades, security patching, and driver integration to ensure 99.9% availability.
β’ Managed VMware ESXi virtualization (VM lifecycle, snapshots, resource allocation) and improved the virtualization stack.
β’ Used Puppet for configuration management to enforce desired state and compliance across systems.
β’ Executed backup/restore procedures and monitored system health to ensure business continuity.
ο»Ώ
π’ Help Desk Support Specialist (Italian) Genpact β Bucharest, Jan 2009 β Mar 2014
β’ Managed the end-to-end incident lifecycle for complex telecom faults (VoIP, MPLS, Fiber), bridging enterprise clients and T3 network engineers.
β’ Resolved T1/T2 technical and product support inquiries via ticketing, live chat, and phone; escalated and tracked faults through resolution.
ο»Ώ
β¨ Education β¨
π Master's Degree, Law Spiru Haret University, Bucharest | 2008 β 2010
π Bachelor's Degree, Law Spiru Haret University, Bucharest | 2004 β 2008
ο»Ώ
β¨ Certifications β¨
π Web3 & Blockchain
ο»ΏRust Programming Basicsο»Ώ
π Cloud & DevSecOps
ο»Ώο»Ώο»ΏLFS262: Implementing DevSecOpsο»Ώ
ο»ΏDevSecOps Engineerο»Ώ
π AI & Data
ο»ΏCertified LLM Developerο»Ώ
ο»ΏMongoDB for SQL Expertsο»Ώ
π Projects
