О себе
Application Security / DevSecOps Engineer with practical experience integrating security into CI/CD pipelines, configuring security gates, and making vulnerability results usable for engineering teams. Strong in SAST, SCA, secrets scanning, SBOM review, container scanning, Docker security, Kubernetes security basics, and GitLab CI/CD automation. I help teams detect security issues earlier, reduce unsafe merge and deployment risks, triage scanner results, separate real vulnerabilities from false positives, and provide clear remediation guidance for developers. 4 years in technical roles, with focused AppSec/DevSecOps experience since 2025.
Опыт работы
AST Cyber Lab
AppSec & DevSecOps Engineer
Integrated security checks into GitLab CI/CD pipelines to help engineering teams detect vulnerabilities earlier in the development lifecycle. Configured SAST, SCA, DAST, secrets scanning, dependency scanning, container scanning, and IaC validation workflows using Semgrep, Gitleaks, Trivy, OWASP Dependency-Check, Sonatype Lifecycle, and Checkov. Implemented severity-based security gates for High and Critical findings and leaked secrets, reducing the risk of unsafe code reaching merge or deployment stages. Improved vulnerability review by triaging scanner results, separating real issues from false positives, and preparing developer-friendly remediation guidance. Standardized security report publishing through CI artifacts and reusable pipeline patterns, making security checks repeatable across repositories. Added Trivy checks for Docker images and Kubernetes manifests, improving visibility into container and cloud-native security risks. Supported secure SDLC workflows through automated scanning, developer feedback, and risk-based prioritization.
- Integrated security checks into GitLab CI/CD pipelines to help engineering teams detect vulnerabilities earlier in the development lifecycle.
- Configured SAST, SCA, DAST, secrets scanning, dependency scanning, container scanning, and IaC validation workflows using Semgrep, Gitleaks, Trivy, OWASP Dependency-Check, Sonatype Lifecycle, and Checkov.
- Implemented severity-based security gates for High and Critical findings and leaked secrets, reducing the risk of unsafe code reaching merge or deployment stages.
- Improved vulnerability review by triaging scanner results, separating real issues from false positives, and preparing developer-friendly remediation guidance.
- Standardized security report publishing through CI artifacts and reusable pipeline patterns, making security checks repeatable across repositories.
- Added Trivy checks for Docker images and Kubernetes manifests, improving visibility into container and cloud-native security risks.
- Supported secure SDLC workflows through automated scanning, developer feedback, and risk-based prioritization.
Shaya Kazakhstan
System Administrator
Administered Linux-based servers and internal IT systems, supporting stable corporate infrastructure and daily operations. Managed user accounts, access permissions, workstations, and internal services with focus on availability, reliability, and fast incident resolution. Resolved hardware, software, network, and Linux server-related issues; worked with system configuration, basic service monitoring, troubleshooting, and access control. Built a strong foundation for later DevSecOps work, including Linux administration, automation, CI/CD environments, and secure infrastructure practices.
- Administered Linux-based servers and internal IT systems, supporting stable corporate infrastructure and daily operations.
- Managed user accounts, access permissions, workstations, and internal services with focus on availability, reliability, and fast incident resolution.
- Resolved hardware, software, network, and Linux server-related issues; worked with system configuration, basic service monitoring, troubleshooting, and access control.
- Built a strong foundation for later DevSecOps work, including Linux administration, automation, CI/CD environments, and secure infrastructure practices.
Avtor24 / Freelance
Technical Content Specialist
Reviewed and improved technical materials for clarity, logical consistency, terminology accuracy, and client requirements. Prepared structured documentation and reports, strengthening technical writing, analytical thinking, and clear communication skills later applied to developer-focused security remediation guidance.
- Reviewed and improved technical materials for clarity, logical consistency, terminology accuracy, and client requirements.
- Prepared structured documentation and reports, strengthening technical writing, analytical thinking, and clear communication skills later applied to developer-focused security remediation guidance.
Проекты
secure-gitlab-pipeline
GitLab CI/CD security pipeline with Semgrep, Gitleaks, dependency scanning, Sonatype checks, Trivy, CI artifacts, reusable jobs, and blocking gates. Demonstrates how to turn security tools into a repeatable DevSecOps workflow for detecting vulnerabilities before merge or deployment.
docker-build-sign
Secure container build pattern with non-root runtime, Dockerfile hardening, SBOM generation, image scanning, and Cosign verification workflow. Demonstrates container hardening and software supply chain visibility.
k8s-secure-deploy
Kubernetes secure deployment baseline with RBAC, NetworkPolicy, probes, securityContext, resource limits, and deployment hardening practices. Demonstrates secure Kubernetes configuration and cloud-native security fundamentals.
AI-assisted SAST triage platform
Local vulnerability analysis prototype combining scanner results with AI-assisted triage, deduplication, false-positive review, risk prioritization, and remediation guidance. Demonstrates an automation-focused approach to reducing scanner noise and improving developer understanding of security findings.
Образование
International University of Information Technologies (IITU)
— 2026Cybersecurity
БакалаврОжидаемая зарплата
1 000 000 KZT