control-plane - bash
$ whoami
Satnam - DevSecOps Engineer
$ cat mission.txt
Helping teams ship with confidence through secure automated processes.
$ echo $STACK
AWS · Terraform · Kubernetes · Bitbucket · Snyk · Python
$

# deployments.list

System Deployments

Production systems engineered for resilience, security, and scale.

control-plane - deployments
01 / 06
$./describe-deployment.shdeploy-001

Multi-Account AWS Cloud Platform

Production

Architected a secure, scalable multi-account AWS environment at Screenrights using Control Tower and Terraform - Zero Trust networking between Production, Non-Production, and On-Prem.

IaC:Terraform + CDK
Security:Control Tower, IAM Identity Center, Security Hub
Platform:AWS Multi-Account
AWSTerraformControl TowerIAM Identity CenterSecurity HubAWS Config

use ← → arrow keys to navigate

# work.logs

Experience

Jul 2024 - PresentDevSecOps Engineer
@ Screenrights - Sydney, AU

Architected a multi-account AWS cloud environment using Control Tower, IAM Identity Center, and Terraform - implementing Zero Trust networking between Production, Non-Production, and On-Prem.

Built Bitbucket CI/CD pipelines with shift-left security scanning (Checkov, Semgrep, Snyk, Trivy) and serverless sandbox environments for developer autonomy.

Improved delivery cycle time by 30% as Scrum Master through automated release pipelines and deployment tooling.

Established monitoring with AWS CloudWatch and Sentry; authored E2E test suite with Cypress for screenrights.app.

Jul 2023 - Jul 2024Senior Reliability Engineer
@ ANZ Bank - Auckland, NZ

Led end-to-end migration of Marketing team AWS workloads to the new ANZ platform - standardised CI/CD pipelines in Codefresh for IaC, EKS, and Lambda releases.

Provisioned EKS clusters with Helm and delivered a Terraform/Terragrunt Lambda + DynamoDB Unsubscribe API for marketing email compliance.

Embedded security in the pipeline with Twistlock (Prisma Cloud), IAM least-privilege, and continuous vulnerability scanning.

Established team-wide observability standards via CloudWatch and Splunk dashboards; led incident post-mortems and mentored engineers.

May 2022 - Jul 2023Cloud Support Engineer - Containers
@ Amazon Web Services - Auckland, NZ

Maintained top 5% global standing in incident management across EKS, ECS, Fargate, ECR, Batch, and Cloud Map portfolios.

Performed deep root-cause analysis on complex container service issues, collaborating with AWS engineers on time-sensitive enterprise escalations.

Upheld SLAs through proactive issue detection; authored support procedures and mentored new engineers on container services.

Sep 2021 - May 2022DevOps Engineer - Deployment & Automation
@ The Warehouse Group - Auckland, NZ

Product Owner for the Observability Squad - delivered Elastic, New Relic, and PagerDuty dashboards and alerts, reducing MTTD and MTTR.

Integrated Snyk into the SDLC to embed a security-first approach for microservices; supported AKS and EKS clusters with Terraform and Ansible.

Enabled CI/CD adoption with Jenkins and drove DevOps best practices across cross-functional teams.

verified.credentials

Certifications

⚙️Terraform Associate (003) - HashiCorp
☸️Certified Kubernetes Administrator (CKA) - The Linux Foundation
🐳Certified Kubernetes Application Developer (CKAD) - The Linux Foundation
🏆Wise Guru Award - Amazon Web Services
☁️AWS Certified Cloud Practitioner - Amazon Web Services
🎓Cloud Computing for Business Professionals - The University of Auckland
🏛️AWS Academy Graduate - Cloud Foundations - Amazon Web Services

# system.pipeline

DevSecOps Lifecycle

Security integrated at every stage. Continuous feedback from plan to monitor.

Plan

Threat modeling & security reqs

SEC

Code

SAST, linting & secure standards

DEV

Build

CI pipelines, SCA & signing

DEV

Secure

DAST, container scan & gates

SEC

Deploy

GitOps, IaC & immutable infra

OPS

Monitor

SIEM, runtime & incident response

OPS

# initiate_contact

Let's Work Together

contact - form
$ initiate_contact
Name:
Email:
Message: