I will build a secure ci cd pipeline with trivy cosign and sbom for devsecops

Pakistan

I speak Urdu, Punjabi, English, German

DevOps Engineer, DevSecOps, Kubernetes Administrator, Cloud Infrastructure, IAM

I'm a DevOps and Cloud Engineer with hands on experience in AWS, Azure, Kubernetes, and Docker. I build CI/CD pipelines with Jenkins and GitLab, deploy apps on Kubernetes using Helm, and set up monito...
About this Gig

️ Stop shipping vulnerable code. Start shipping verified releases.


Most CI/CD pipelines deploy fast but don't verify safety. One vulnerable dependency or unsigned image exposes your production.


I build security-gated CI/CD pipelines that scan for vulnerabilities, sign images, generate SBOMs, and block insecure deployments BEFORE production.


WHAT YOU GET


Trivy Vulnerability Scanning builds fail on critical CVEs automatically

Cosign Image Signing cryptographically prove image authenticity

SBOM Generation SPDX or CycloneDX for SOC 2 and ISO 27001

Gitleaks Secret Scanning no leaked keys in your repo

SonarQube Quality Gates code issues flagged before merge

Full Pipeline GitHub Actions, GitLab CI, Jenkins, or Argo CD

Documentation & Handover README + walkthrough call


PERFECT FOR

Startups preparing for SOC 2 or enterprise reviews. DevOps teams adding security without slowing down. Companies recovering from incidents.


️ TOOLS

GitHub Actions, GitLab CI, Jenkins, Argo CD, Trivy, Cosign, Gitleaks, SonarQube, Docker, Kubernetes, Helm, Terraform, Ansible, AWS, Azure.


Message me with your repo, CI tool, and compliance needs. I'll reply with a fixed quote.


Tools:

Docker

•

GitLab

•

Jenkins

•

GitHub

•

Other

Frameworks:

Terraform

•

Ansible

Cloud Provider:

Amazon Web Services

•

Microsoft Azure

Programming language:

Bash

•

C

•

Python

Expertise:

Installation

•

Development

•

Configuration

My Portfolio

Other DevOps Engineering Services I Offer