I will secure your ci cd pipeline and stop secrets and bad code shipping
Lead Security Architect for Hybrid Cloud, IAM and Zero Trust
Vetted by Fiverr Pro
Marlon Costa was selected by the Fiverr Pro team for their expertise.
Vetted for
Cloud Computing
Cybersecurity
Data Governance & Protection
DevOps Engineering
Regulatory Compliance Consulting
Support & IT
About this Gig
Vetted Pro
Your pipeline can deploy to production. So can anything that gets into it.
CI/CD holds every credential and reaches every environment, and it grew without anyone owning its security. I do not send a scan report. I build the controls in.
You are probably here because
- A secret was found in a repo and you want to know what else
- Anyone can deploy and you cannot reconstruct who did what
- Scanning exists and everyone ignores it, because it flags everything
What I change
- Secrets out of plain variables into a vault, rotation that works
- Runner and job permissions cut to what each step needs
- Scanning as gates, tuned so a blocked build is worth blocking
- Branch protection, so nobody ships to production alone
How it works
- You give me read on one repo and say where it deploys
- I harden the pipeline and add gates, without breaking builds
- You get the documentation and a walkthrough
What you can count on
Changes arrive as pull requests your team reviews. Nothing lands without approval.
Works with
GitHub Actions, GitLab CI, Jenkins, Docker, Kubernetes.
Aligned to OWASP, NIST SSDF and CIS Benchmarks.
Tell me what you run and I will say which fits.
My Portfolio
Other DevOps Engineering Services I Offer
FAQ
Do you need direct access to our CI/CD environment?
No. In many cases, I can work from documentation, screenshots, exported configurations, workflow files, architecture diagrams, and live walkthroughs. If limited read-only access is available, we can define an appropriate review model.
What kinds of issues can this assessment identify?
This assessment can highlight risks related to repository controls, branch protections, approval workflows, secrets handling, build security, runner exposure, artifact integrity, deployment controls, and pipeline traceability.
Is this a penetration test or a formal compliance audit?
No. This project is a security review and advisory assessment. It is designed to identify control gaps, delivery risks, and practical hardening priorities, but it is not a penetration test or an official audit unless separately defined.
What will I receive at the end of the project?
Depending on the selected tier, you will receive a structured assessment with findings, risk observations, practical recommendations, and, in higher tiers, a more detailed roadmap and executive-ready summary.
Can this assessment cover platforms like GitHub, GitLab, or Azure DevOps?
Yes. This project can be applied to common DevSecOps and CI/CD platforms as long as the scope, workflows, and available evidence are clearly defined.

