Portfolio
Seyed Taheri
DevSecOps Engineer
Securing CI/CD, cloud infrastructure, and AI-assisted development with shift-left practices.
Profile
About
DevSecOps Engineer with 9+ years of experience across DevOps, cloud engineering, and systems administration in healthcare and technology environments. Specialized in securing CI/CD pipelines (GitHub Actions, Jenkins, Bamboo), container and runtime security, Infrastructure-as-Code (AWS CloudFormation) scanning, and vulnerability management (SAST, DAST, SCA, SBOM) using CrowdStrike Falcon Cloud Security, Prisma Cloud, SonarQube, and Checkov. Proven record of embedding shift-left security practices across development teams, remediating audit findings across HIPAA, SOC 2, and SOC 3 assessments, and delivering ~$110K in annual AWS cost savings through FinOps automation. Hands-on applied AI/LLM engineering through independent projects, including building multi-agent coding pipelines on Claude Code with security-by-design gates such as automated STRIDE threat modeling.
Career
Experience
DevSecOps Engineer
Envista Holdings Corporation · Finland
Nov 2024 — Present
- Integrated CrowdStrike Falcon Cloud Security (FCS) CLI into CI/CD pipelines, automating container image and runtime vulnerability scanning as a mandatory pre-merge quality gate; cut critical vulnerabilities reaching protected branches by ~85%.
- Led the migration of CI/CD pipelines from Atlassian Bamboo to GitHub Actions across 28 repositories, re-integrating build, test, and security tooling natively into workflows and reducing pipeline maintenance effort by ~40%.
- Embedded policy-as-code enforcement and automated security report generation into the CI/CD pipeline, replacing manual compliance checks and cutting audit-evidence preparation time by ~60%.
- Developed and fully automated AWS resource cleanup scripts (unused EBS volumes, snapshots, AMIs, and idle instances) as part of a FinOps initiative, saving ~$110K in annual cloud spend.
- Built and fully automated custom AMI and custom image pipelines with integrated hardening using AWS Systems Manager (SSM), standardizing secure golden-image baselines across environments and reducing image preparation time from days to hours.
- Automated the installation and configuration of security and monitoring agents — SentinelOne, CrowdStrike, ServiceNow, Tenable, and Splunk (on selected images) — within the golden image pipeline via AWS SSM, eliminating manual agent deployment and ensuring 100% agent coverage on newly provisioned instances.
- Integrated Checkov Infrastructure-as-Code (IaC) scanning into GitHub Actions to detect AWS CloudFormation misconfigurations before deployment, reducing IaC-related security findings by ~50%.
- Triaged and remediated vulnerabilities surfaced by Prisma Cloud, SonarQube, and SAST / DAST / SCA / SBOM scans, coordinating fixes with the corresponding development teams; reduced open critical- and high-severity findings by ~70% within six months.
- Monitored and troubleshot production workloads using Amazon CloudWatch (logs, metrics, alarms, and dashboards), accelerating root-cause analysis and reducing mean time to resolution (MTTR) by ~30%.
- Resolved security and compliance gaps raised by external auditors, driving cross-team remediation to meet HIPAA requirements and closing 100% of audit findings within agreed timelines.
- Partnered with audit and security teams to remediate SOC 2 and SOC 3 assessment findings and generated compliance and security reports for stakeholders, accelerating finding resolution by ~35% and strengthening audit readiness.
- Designed and delivered 2 knowledge-sharing sessions on shift-left security for development teams, accelerating adoption of secure coding and early-stage scanning practices.
DevOps Engineer
Bravori Oy · Helsinki, Finland
Jun 2023 — Nov 2024
- Led a team of 6 developers, fostering collaboration through regular team meetings and knowledge-sharing initiatives.
- Built automated test coverage using Jest and Mocha for JavaScript unit testing and Robot Framework for end-to-end test automation, ensuring code reliability.
- Automated cloud provisioning and security rule management on GCP, improving resource management efficiency by 40%.
DevOps Engineer
Masih Daneshvari Hospital (NRITLD) · Tehran, Iran
Nov 2020 — Aug 2022
- Designed a web application to oversee the treatment of COVID-19 patients, using Docker for efficient containerization and Git for streamlined source-code management, resulting in a 30% reduction in deployment time.
- Executed integration, version control, and deployment workflows, combining Python automation scripts with Terraform for infrastructure management; reduced deployment-related errors by 25%.
- Set up cloud infrastructure on AWS, enhancing system reliability and scalability by 50%.
System Administrator
Masih Daneshvari Hospital (NRITLD) · Tehran, Iran
Sep 2018 — Nov 2020
- Led the review and management of Service Level Agreements (SLAs) and drove contract negotiations with third-party vendors for new devices and services.
- Designed and implemented network architectures, optimizing performance, security, and scalability.
- Orchestrated virtualization initiatives on VMware, optimizing resource utilization and reducing hardware costs.
IT Specialist
Telemedicine Research Center · Tehran, Iran
Sep 2017 — Sep 2018
- Directed workshops explaining technical concepts to non-technical stakeholders, building understanding and support for projects.
- Oversaw root-cause analysis for network issues, lowering downtime by 15%.
- Produced and maintained technical documentation, supporting continuous improvement and compliance.
Technical Support Engineer
National Iranian Oil Pipeline and Telecommunication Company · Tehran, Iran
Jul 2014 — Aug 2015
- Resolved 95% of support tickets regarding TCP/IP, DNS, and DHCP.
- Provided 24/7 support for production environments, maintaining high availability.
- Automated backup processes using shell scripting, safeguarding data integrity and reducing manual effort by 25%.
Selected work
AI Projects
Socratic Duck — Agentic AI Coding Pipeline
Solo Founder · Personal Side Project
Production-grade agentic AI coding pipeline on Claude Code with security-by-design gates.
- Designed and built a production-grade agentic AI coding pipeline on Claude Code, orchestrating 15 specialized subagents through custom slash commands (/new-idea, /build-mvp, /quick-build) that take a software idea from concept to working MVP.
- Engineered security-by-design into the AI workflow: a mandatory idea-framing gate, automated STRIDE threat modeling, and a UX approval gate before build stages — applying shift-left security principles to AI-assisted development.
- Implemented a three-tier command system separating personal and commercial project workflows, using structured prompt engineering and multi-agent orchestration patterns for reliable, repeatable outputs; cut idea-to-MVP turnaround from weeks to days.
Capabilities
Skills
Security & Compliance
AI & LLM Engineering
CI/CD & Automation
Programming & Scripting
Cloud & Infrastructure
Version Control
Databases
Logging & Monitoring
Project & IT Service Management
Systems & Networking
Soft Skills
Languages
Academic
Education
Master's Degree, Information Technology Engineering
IAU
Sep 2015 — Sep 2017
Credentials
Certifications & Courses
Google Project Management Certificate
Agile Project Management
Configuration Management and the Cloud
DevOps Culture and Mindset
University of California, Davis
Building Cloud Computing Solutions at Scale Specialization
Duke University
Cloud Data Engineering
Duke University
Cloud Virtualization, Containers and APIs
Duke University
Robot Framework Test Automation: Level 1 (Selenium)
LinkedIn Learning
Robot Framework Test Automation: Level 2
LinkedIn Learning
Connect
Contact
Open to DevSecOps, cloud security, and applied AI engineering conversations.