Security & Compliance
Shift-left security, vulnerability management, image hardening
From commit to compliance, automatically.
9+ years across DevOps, cloud engineering and systems administration in healthcare and technology. I build the pipelines and platforms teams ship on, with security built in as code: container and runtime scanning, IaC checks, policy-as-code gates, and the compliance evidence that follows.

Shift-left security, vulnerability management, image hardening
Pipelines as the enforcement point
Golden images, IaC, cost engineering
Independent projects · security-by-design
Faster detection, shorter resolution
Delivery, not ceremony
Foundations under the platform
Operated and maintained, not developed against
The shape of the pipeline I build: every security control is a mandatory pre-merge check, evidence is generated automatically, and nothing reaches a protected branch on a promise.
SAST
quality gate · blocking
SCA + SBOM
dependencies · attested
IaC scanning
misconfigurations caught early
Container + runtime
image and workload scan
Policy as code
audit evidence generated
Merge · deploy
hardened golden image
Image scanning ran after the fact, so vulnerable containers landed on protected branches and were remediated late, under audit pressure.
Wrapped the scanner in a reusable workflow, made it a required status check, and surfaced findings back on the pull request with owners attached.
Container and runtime scanning, GitHub Actions, Docker, Bash, artifact registry.
Critical vulnerabilities reaching protected branches fell sharply, and scanning became invisible to developers rather than optional.
A platform migration is where security tooling quietly disappears. Scanners bolted onto the old CI server have no owner on the new one, and the pressure during a move is to get builds green first and add the checks back later.
Worked alongside the wider migration rather than owning it: rebuilt each scan as a reusable workflow, made the ones that mattered required status checks, and kept findings surfacing on the pull request rather than in a separate console.
GitHub Actions, Bamboo, Bitbucket, SAST, SCA, IaC scanning, policy as code.
Security controls landed with the new pipelines instead of after them, so a passing build meant the same thing on the new platform as it did on the old one.
Compliance work was manual and repeated every cycle: collecting screenshots and spreadsheets to prove that controls had been applied consistently, long after the change that needed proving.
Encoded the controls as policy that runs on every change, and automated the security reporting so evidence is a by-product of the pipeline rather than a project of its own.
Policy as code, IaC scanning, GitHub Actions, automated security reporting.
Audit preparation stopped being a manual exercise, and control drift shows up as a failing check rather than as a finding months later.
Baselines drifted between environments and security agents were installed by hand, so coverage was never certain at audit time.
A pipeline that hardens the base, installs and configures the agents through systems management, and publishes a versioned golden image.
AWS Systems Manager, CloudFormation, Bash, Python, IaC scanning.
Image preparation went from days to hours, with full agent coverage on newly provisioned instances and fewer IaC findings once scanning gated the change.
Orphaned storage and idle compute accumulated faster than anyone reviewed it, and manual clean-up was risky without ownership data.
Scheduled jobs that identify, tag, notify owners and then reclaim resources on a delay, reporting on exactly what was removed.
AWS SDK, Python, Bash, CloudWatch, scheduled workflows.
Six-figure annual cloud savings, with clean-up running unattended.
A gate only works if the people hitting it know what to do next. Findings routed to teams who have not seen the tooling before become tickets that sit, and the gate turns into something to be routed around.
Sessions with development teams on what each scanner actually checks, how to read its output, and which findings to fix now versus justify. Paired with findings surfaced on the pull request, where the context already is.
SAST, DAST, SCA, SBOM, container scanning, IaC scanning.
Teams resolved findings without escalation, and security review stopped being the bottleneck between a merge and a release.
AI-assisted builds move fast and skip the framing and threat work, so security arrives after the code does.
Custom slash commands (/new-idea, /build-mvp, /quick-build) drive 15 subagents through a mandatory idea-framing gate, automated STRIDE threat modeling and a UX approval gate before any build stage.
Claude Code, Anthropic Claude API, structured prompt engineering, a three-tier command system separating personal and commercial workflows.
Idea-to-MVP turnaround cut from weeks to days, with shift-left security applied to AI-assisted development.
What the gates and automation added up to. Exact figures live in the detailed CV; what is public is the direction and the mechanism.
Down sharply
continuous scanning across the estate
Shorter
centralized logging · metrics · alarms
Audit-ready
audit findings closed within agreed timelines
Automated away
less manual work every quarter
M.Sc., Information Technology Engineering
IAU · 2015 to 2017
Based in Helsinki, Finland. Open to DevOps, platform, cloud and security engineering roles. The form is the fastest route.
The public version of this CV is generalized. The detailed one, with exact figures and scope, is sent on request.