I will secure your cicd pipeline with devsecops
DevSecOps Cloud Security Engineer AWS, Azure
About this Gig
Your CI/CD pipeline holds the keys to production: cloud credentials, deploy tokens, secrets in old commits. Attackers target it for exactly that reason.
I'm a DevSecOps & offensive security engineer who audits architectures, configs and source code for a living. I set up pipeline security the way an attacker would test it, and tune it so your team doesn't switch it off.
What I do (GitHub Actions, GitLab CI, Azure Pipelines, Jenkins or any CI/CD platform):
- Secret scanning across your full git history (Gitleaks)
- SAST on every pull or merge request (Semgrep)
- Dependency, container and IaC scanning (Trivy)
- Gates that block real high/critical issues, with the noise tuned out
- Pipeline hardening: least-privilege tokens, pinned actions, OIDC instead of stored cloud keys
Deliverables (by package):
- Severity-ranked findings report with a fix for each
- Working pipeline config committed to your repo
- A runbook your team can maintain
Not sure which package fits? Message me your CI platform and stack before ordering.
Tools:
Docker
•
GitLab
•
Jenkins
•
GitHub
•
CircleCI
Frameworks:
Npm
•
Terraform
•
Ansible
•
Chef
•
Puppet
Cloud Provider:
Amazon Web Services
•
Microsoft Azure
Programming language:
Java
•
JavaScript
•
PHP
•
Python
Expertise:
Migration
•
Debugging
•
Configuration
Other DevOps Engineering Services I Offer
FAQ
Do you need write access?
Read access is enough for the audit. For gates I work on a branch and open a PR/MR, and you review and merge it. I never ask for long-lived production credentials; for OIDC I give you the role definition to apply.
Will scans slow my pipeline?
Usually by a few minutes. Heavier scans can run nightly instead of on every commit.
What if you find secrets in my history?
I report them only inside the order, and you rotate them first, because deleting a leaked key from history doesn't un-leak it. A history purge is available as an extra.
Which platforms and languages?
GitHub Actions, GitLab CI or Azure Pipelines. Languages: JS/TS, Python, Java, Go, C#, PHP and most other mainstream ones.
Will you fix the vulnerabilities?
Every finding comes with a fix. Hands-on remediation is quoted as a custom offer once the audit shows the scope.
Is this a penetration test?
No.
