Seyed Taheri

DevOps · Platform · Cloud Security · Helsinki, Finland

SEYEDTAHERI

From commit to compliance, automatically.

9+ years across DevOps, cloud engineering and systems administration in healthcare and technology. I build the pipelines and platforms teams ship on, with security built in as code: container and runtime scanning, IaC checks, policy-as-code gates, and the compliance evidence that follows.

Portrait of Seyed Taheri
seyed.taheri · devops · security · fi
9+ yrs
DevOps · cloud · sysadmin
↓ sharply
Critical vulns on protected branches
6 figures
Annual cloud spend saved · FinOps
Large estate
Multi-repo CI/CD modernized

Stack

Security & Compliance

DevSecOpsShift-left securitySAST / DAST / SCA / SBOMVulnerability managementContainer & image securityImage hardening & golden AMIsPolicy as codeIaC scanningSonarQubeSonarCloudCheckovBurp SuitePrisma CloudCrowdStrike FCS CLISOC 2 / SOC 3HIPAA

Shift-left security, vulnerability management, image hardening

CI/CD & Automation

GitHub ActionsBambooBamboo Java SpecsJenkinsAnsiblePuppetRobot FrameworkBashPythonGoJavaScriptJava / Spring Boot builds

Pipelines as the enforcement point

Cloud & Infrastructure

AWSAmazon ECSCloudFormationAWS SSMCloudFrontRoute 53AzureMicrosoft Entra IDGCPDockerKubernetesFinOpsJFrog Artifactory

Golden images, IaC, cost engineering

AI & LLM Engineering

Agentic AI pipelinesMulti-agent orchestrationClaude CodeAnthropic Claude APILLM tool use / function callingPrompt engineeringSTRIDE automation

Independent projects · security-by-design

Logging & Monitoring

Amazon CloudWatchSplunkELK StackPRTGZabbix

Faster detection, shorter resolution

Ways of Working

AgileAtlassian suiteJiraJira administrationConfluenceBitbucketITIL / ITSMServiceNowGitGitHubGitLab

Delivery, not ceremony

Systems & Networking

Linux & Windows administrationCisco routing & switchingVMwareVoIP

Foundations under the platform

Database operations

MongoDBRedisMySQLFirestore

Operated and maintained, not developed against

The gate

github actions · pre-merge · illustrative

The shape of the pipeline I build: every security control is a mandatory pre-merge check, evidence is generated automatically, and nothing reaches a protected branch on a promise.

SAST

quality gate · blocking

SCA + SBOM

dependencies · attested

IaC scanning

misconfigurations caught early

Container + runtime

image and workload scan

Policy as code

audit evidence generated

Merge · deploy

hardened golden image

Selected work

open a card for the case study
01Container security as a pre-merge gateIntegrated container image and runtime scanning into CI/CD so it became a mandatory quality gate rather than an after-the-fact report.Container scanningGitHub ActionsDockerBashCASE STUDY +

Problem

Image scanning ran after the fact, so vulnerable containers landed on protected branches and were remediated late, under audit pressure.

Solution

Wrapped the scanner in a reusable workflow, made it a required status check, and surfaced findings back on the pull request with owners attached.

Tools

Container and runtime scanning, GitHub Actions, Docker, Bash, artifact registry.

Impact

Critical vulnerabilities reaching protected branches fell sharply, and scanning became invisible to developers rather than optional.

02Security tooling carried through a CI/CD migrationAs the estate moved from Bamboo to GitHub Actions, I owned the security workstream: making sure every scan, gate and report arrived as a native part of the new pipelines instead of being left behind.GitHub ActionsBambooBitbucketSAST / SCAIaC scanningPolicy as codeCASE STUDY +

Problem

A platform migration is where security tooling quietly disappears. Scanners bolted onto the old CI server have no owner on the new one, and the pressure during a move is to get builds green first and add the checks back later.

Solution

Worked alongside the wider migration rather than owning it: rebuilt each scan as a reusable workflow, made the ones that mattered required status checks, and kept findings surfacing on the pull request rather than in a separate console.

Tools

GitHub Actions, Bamboo, Bitbucket, SAST, SCA, IaC scanning, policy as code.

Impact

Security controls landed with the new pipelines instead of after them, so a passing build meant the same thing on the new platform as it did on the old one.

03Policy as code, and audit evidence that generates itselfReplaced manual compliance checks with policy enforced on every change, and reporting that produces what auditors ask for without anyone assembling it by hand.Policy as codeIaC scanningSOC 2 / SOC 3HIPAAGitHub ActionsCASE STUDY +

Problem

Compliance work was manual and repeated every cycle: collecting screenshots and spreadsheets to prove that controls had been applied consistently, long after the change that needed proving.

Solution

Encoded the controls as policy that runs on every change, and automated the security reporting so evidence is a by-product of the pipeline rather than a project of its own.

Tools

Policy as code, IaC scanning, GitHub Actions, automated security reporting.

Impact

Audit preparation stopped being a manual exercise, and control drift shows up as a failing check rather than as a finding months later.

04Hardened golden-image pipelineAutomated image pipelines with baseline hardening and unattended security-agent installation through cloud systems management.AWS SSMCloudFormationGolden imagesBashCASE STUDY +

Problem

Baselines drifted between environments and security agents were installed by hand, so coverage was never certain at audit time.

Solution

A pipeline that hardens the base, installs and configures the agents through systems management, and publishes a versioned golden image.

Tools

AWS Systems Manager, CloudFormation, Bash, Python, IaC scanning.

Impact

Image preparation went from days to hours, with full agent coverage on newly provisioned instances and fewer IaC findings once scanning gated the change.

05FinOps cleanup automationAutomated cloud resource reclamation across unused volumes, snapshots, images and idle instances as part of a FinOps initiative.AWSPythonCloudWatchFinOpsCASE STUDY +

Problem

Orphaned storage and idle compute accumulated faster than anyone reviewed it, and manual clean-up was risky without ownership data.

Solution

Scheduled jobs that identify, tag, notify owners and then reclaim resources on a delay, reporting on exactly what was removed.

Tools

AWS SDK, Python, Bash, CloudWatch, scheduled workflows.

Impact

Six-figure annual cloud savings, with clean-up running unattended.

06Shift-left workshops with development teamsRan knowledge-sharing sessions so developers could read and fix their own security findings, rather than waiting on a security review to tell them what a scanner meant.Shift-left securityDeveloper enablementSAST / DAST / SCA / SBOMCASE STUDY +

Problem

A gate only works if the people hitting it know what to do next. Findings routed to teams who have not seen the tooling before become tickets that sit, and the gate turns into something to be routed around.

Solution

Sessions with development teams on what each scanner actually checks, how to read its output, and which findings to fix now versus justify. Paired with findings surfaced on the pull request, where the context already is.

Tools

SAST, DAST, SCA, SBOM, container scanning, IaC scanning.

Impact

Teams resolved findings without escalation, and security review stopped being the bottleneck between a merge and a release.

07Socratic Duck: agentic AI coding pipelineIndependent project. A production-grade agentic pipeline on Claude Code orchestrating 15 specialized subagents from idea to working MVP, with security gates built into the workflow.Claude CodeMulti-agent orchestrationPrompt engineeringSTRIDECASE STUDY +

Problem

AI-assisted builds move fast and skip the framing and threat work, so security arrives after the code does.

Solution

Custom slash commands (/new-idea, /build-mvp, /quick-build) drive 15 subagents through a mandatory idea-framing gate, automated STRIDE threat modeling and a UX approval gate before any build stage.

Tools

Claude Code, Anthropic Claude API, structured prompt engineering, a three-tier command system separating personal and commercial workflows.

Impact

Idea-to-MVP turnaround cut from weeks to days, with shift-left security applied to AI-assisted development.

Posture

direction of travel · not a live dashboard

What the gates and automation added up to. Exact figures live in the detailed CV; what is public is the direction and the mechanism.

Open critical + high findings

Down sharply

continuous scanning across the estate

Mean time to resolution

Shorter

centralized logging · metrics · alarms

Compliance remediation

Audit-ready

HIPAA
SOC 2
SOC 3

audit findings closed within agreed timelines

Automation wins

Automated away

  • Audit-evidence preparation replaced by generated reports
  • IaC findings caught before deployment
  • Agent coverage on newly provisioned instances
  • Shift-left sessions with development teams

less manual work every quarter

Experience

  1. Nov 2024 - now

    Envista Holdings · Finland

    Development and Operations Engineer (DevSecOps)

    • Made container and runtime vulnerability scanning a mandatory pre-merge gate, sharply cutting critical findings reaching protected branches.
    • Led CI/CD modernization onto GitHub Actions across a large multi-repo estate, re-integrating build, test, and security tooling natively.
    • Automated policy-as-code enforcement and security reporting, replacing manual compliance checks.
    • Built automated cloud-resource cleanup (FinOps), delivering six-figure annual savings.
    • Standardized hardened golden-image baselines with automated security-agent installation.
    • Operated production relational and NoSQL data stores alongside the platform remit: patching, backup and restore verification, and periodic access review.
    • Integrated IaC scanning to catch misconfigurations before deployment; triaged SAST/DAST/SCA/SBOM findings with development teams.
    • Partnered with audit and security teams to strengthen SOC 2, SOC 3, and HIPAA readiness; ran shift-left knowledge-sharing sessions.
    Bamboo → GitHub ActionsBitbucketJiraConfluenceContainer scanningIaC scanningSAST / DAST / SCA / SBOMPolicy as codeAWS SSMGolden imagesDatabase operationsFinOpsSOC 2 / SOC 3HIPAA
  2. Jun 2023 - Nov 2024

    Bravori Oy · Helsinki, Finland

    DevOps Engineer

    • Led a small development team, driving collaboration and knowledge-sharing.
    • Built unit and end-to-end test automation (Jest, Mocha, Robot Framework) to raise reliability.
    • Automated cloud provisioning and security-rule management on GCP.
    GCPRobot FrameworkJestMochaJavaScript
  3. Nov 2020 - Aug 2022

    Masih Daneshvari Hospital (NRITLD) · Tehran, Iran

    DevOps Engineer

    • Built and containerized a web app for COVID-19 patient-treatment management (Docker, Git), cutting deployment time.
    • Automated infrastructure with Terraform and Ansible; implemented CI/CD with Jenkins.
    • Stood up AWS infrastructure and centralized logging/monitoring (ELK), improving reliability and visibility.
    DockerTerraformAnsibleJenkinsAWSELKGit
  4. Sep 2018 - Nov 2020

    Masih Daneshvari Hospital (NRITLD) · Tehran, Iran

    System Administrator

    • Designed and managed network architecture (BGP, VPNs, Cisco/MikroTik) for performance and security.
    • Ran virtualization on VMware and monitoring with Zabbix, reducing downtime.
    • Managed SLAs and vendor negotiations; mentored junior staff.
    BGP / VPNCiscoMikroTikVMwareZabbix
  5. Sep 2017 - Sep 2018

    Telemedicine Research Center · Tehran, Iran

    IT Specialist

    • Supported telemedicine infrastructure at high uptime; led Windows Server administration.
    • Implemented VoIP / Lync communications; produced technical documentation.
    Windows ServerVoIPLync
  6. Jul 2014 - Aug 2015

    National Iranian Oil Pipeline & Telecommunication Co. · Tehran, Iran

    Technical Support Engineer

    • Resolved TCP/IP, DNS, and DHCP issues in 24/7 production environments.
    • Automated backups with shell scripting; monitored and improved network performance.
    TCP/IPDNS / DHCPShell scripting

Education

M.Sc., Information Technology Engineering

IAU · 2015 to 2017

Certifications and courses

  • Google Project Management Certificate
  • Agile Project Management (Google)
  • Configuration Management and the Cloud (Google)
  • DevOps Culture and Mindset (UC Davis)
  • Building Cloud Computing Solutions at Scale (Duke)
  • Cloud Data Engineering (Duke)
  • Cloud Virtualization, Containers and APIs (Duke)
  • Robot Framework Test Automation L1 & L2 (LinkedIn Learning)

Let's talk.

Based in Helsinki, Finland. Open to DevOps, platform, cloud and security engineering roles. The form is the fastest route.

The public version of this CV is generalized. The detailed one, with exact figures and scope, is sent on request.