I will secure your cicd pipeline with devsecops

Morocco

I speak English, Arabic, French

DevSecOps Cloud Security Engineer AWS, Azure

DevSecOps and cloud engineer who designs, secures, and deploys production infrastructure on AWS and Azure. I build CI/CD pipelines with security gates (GitLab CI, Semgrep, Trivy, Gitleaks), automate i...
About this Gig

Your CI/CD pipeline holds the keys to production: cloud credentials, deploy tokens, secrets in old commits. Attackers target it for exactly that reason.


I'm a DevSecOps & offensive security engineer who audits architectures, configs and source code for a living. I set up pipeline security the way an attacker would test it, and tune it so your team doesn't switch it off.

What I do (GitHub Actions, GitLab CI, Azure Pipelines, Jenkins or any CI/CD platform):

- Secret scanning across your full git history (Gitleaks)

- SAST on every pull or merge request (Semgrep)

- Dependency, container and IaC scanning (Trivy)

- Gates that block real high/critical issues, with the noise tuned out

- Pipeline hardening: least-privilege tokens, pinned actions, OIDC instead of stored cloud keys


Deliverables (by package):

- Severity-ranked findings report with a fix for each

- Working pipeline config committed to your repo

- A runbook your team can maintain


Not sure which package fits? Message me your CI platform and stack before ordering.


Tools:

Docker

•

GitLab

•

Jenkins

•

GitHub

•

CircleCI

Frameworks:

Npm

•

Terraform

•

Ansible

•

Chef

•

Puppet

Cloud Provider:

Amazon Web Services

•

Microsoft Azure

Programming language:

Java

•

JavaScript

•

PHP

•

Python

Expertise:

Migration

•

Debugging

•

Configuration

Other DevOps Engineering Services I Offer