Skip to content
View dhivagar29's full-sized avatar

Block or report dhivagar29

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
dhivagar29/README.md

β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•—β–ˆβ–ˆβ•—β–ˆβ–ˆβ•—   β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—
β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•β•β• β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—
β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•
β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—
β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘
β•šβ•β•β•β•β•β• β•šβ•β•  β•šβ•β•β•šβ•β•  β•šβ•β•β•β•  β•šβ•β•  β•šβ•β• β•šβ•β•β•β•β•β• β•šβ•β•  β•šβ•β•β•šβ•β•  β•šβ•β•

> DevSecOps Engineer Β· Infrastructure Specialist @ IBM Β· 10+ Years Β· Bengaluru, India


Typing SVG


DevSecOps Shift Left Zero Trust Pipeline


$ ssh visitor@github.com/dhivagar29
> negotiating cipher suite .......... TLS 1.3 βœ”
> verifying host identity ........... signature valid βœ”
> scanning session for anomalies .... clean βœ”
> ACCESS GRANTED β€” entering the secure pipeline.

🧬 whoami --verified


identity:
  name: "Dhivagar Kamaraj"
  role: "Infrastructure Specialist β€” DevSecOps"
  org: "IBM"
  location: "πŸ“ Bengaluru, Karnataka, India"
  experience: "10+ years across regulated cloud environments"
  domain: "Financial Services | Cloud Security | Platform Engineering"

operating_principles:
  - "Shift security left β€” every commit is a control point"
  - "If it isn't codified, it isn't compliant: IaC + policy-as-code"
  - "Least privilege by default β€” IAM is the real perimeter"
  - "Pipelines should fail fast on vulnerabilities, not in production"
  - "Observability is a security control, not just an SRE tool"

current_focus:
  - "Hardened CI/CD: SAST, SCA, secrets scanning, image signing"
  - "Zero-trust AWS architectures for customer-facing FinServ workloads"
  - "Automated compliance & drift detection in regulated environments"

contact:
  linkedin: "linkedin.com/in/dhivagar-kamaraj"
  github: "github.com/dhivagar29"

education: "B.E. Computer Science β€” SRM Valliammai Engineering College, 2013"
philosophy: "Automate everything. Secure by default. Trust nothing, verify all."

πŸ›°οΈ Mission Log β€” Career Timeline


2014 ─────────────────────────────────────────────────────────────► Present

 [M-Square]      [Sanmina SCI]    [Cognizant]     [Infosys]        [IBM]
 Network Admin   Programmer       Associate       Consultant       Infra Spec.
 May'14-Apr'16   May'16-Aug'18    Aug'18-Jun'20   Dec'20-Mar'22    Mar'22-Now
      β”‚                β”‚                β”‚               β”‚               β”‚
  Hardened OS &   Multi-cloud      Containerized   Automated       Zero-trust
  network admin   AWS/GCP/OnPrem   CI/CD on K8s    secure          AWS for UK
  foundations     + monitoring     for healthcare  releases for    banking at
                                   (HIPAA-bound)   Citi (FinServ)  Nationwide

πŸ›‘οΈ The Pipeline I Build β€” Security at Every Gate


        ◄──────────────────────── SHIFT LEFT ────────────────────────

 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚   CODE   │──►│  COMMIT  │──►│  BUILD   │──►│  DEPLOY  │──►│   RUN    β”‚
 β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜
      β”‚              β”‚              β”‚              β”‚              β”‚
  πŸ” IDE lint    πŸ”‘ secrets     πŸ§ͺ SAST +      πŸ“œ policy-     πŸ“‘ runtime
  + threat       scanning,      SCA, image     as-code        monitoring,
  modeling       signed         scan &         gates, IaC     CloudWatch /
                 commits        SBOM           drift checks   CloudTrail
      β”‚              β”‚              β”‚              β”‚              β”‚
      └──────────────┴──────► FAIL FAST β—„β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                     vulnerabilities stop here, not in prod

βš”οΈ Tech Arsenal


πŸ” Security & Compliance

IAM KMS AWS Shield AWS Config Secrets Manager Vault

πŸ§ͺ Pipeline Security Toolchain

SonarQube Snyk Trivy OWASP ZAP Checkov OPA

☁️ Cloud Platforms

AWS Azure GCP

βš™οΈ CI/CD & DevOps

Jenkins GitHub Actions Buildkite Harness TeamCity UrbanCode

πŸ—οΈ Infrastructure as Code

Terraform CloudFormation Ansible Chef

🐳 Containers & Orchestration

Kubernetes Docker

πŸ’» Languages & Scripting

Python Bash Go

πŸ“‘ Detection & Observability

CloudWatch CloudTrail New Relic Nagios

πŸ—„οΈ Databases & SCM

RDS DynamoDB Git GitLab Bitbucket


πŸš€ Key Missions


🏦 Nationwide Building Society β€” Assisted Service (IBM, 2022–Present)

Zero-trust AWS infrastructure for one of the UK's largest financial institutions

  • πŸ” Enforced least-privilege IAM roles & policies meeting FCA-grade regulatory compliance and protecting sensitive customer data
  • πŸ—οΈ Architected scalable, security-hardened AWS solutions for customer-facing workloads
  • πŸ›‘οΈ Embedded security gates into CI/CD β€” vulnerabilities caught at commit, not in production
  • πŸ“Š Real-time threat-aware monitoring with CloudWatch, CloudTrail & Lambda auto-remediation

🏦 Citi Group β€” Treasury & Trade Solutions (Infosys, 2020–2022)

Securing and accelerating releases for a critical global banking platform

  • ⚑ Cut deployment cycle from ~5 days β†’ 2 days without bypassing a single security control
  • πŸ€– Replaced error-prone manual ops with auditable open-source automation
  • πŸ“‹ Authored SOPs & runbooks around failure and incident-response scenarios
  • πŸ–₯️ Maintained hardened high-availability clustered environments in a regulated FinServ landscape

πŸ₯ Cigna & Health Care Service Corporation (Cognizant, 2018–2020)

Compliant CI/CD automation for healthcare cloud infrastructure

  • πŸ”„ Built fully automated Jenkins / GitLab pipelines for HIPAA-sensitive workloads
  • πŸ—οΈ Delivered Infrastructure as Code with Terraform, CloudFormation & Ansible β€” reviewable, auditable, repeatable
  • 🐳 Containerized workloads with Docker & Kubernetes on AWS/GCP, managing the full image lifecycle
  • πŸ“¦ Governed Docker Hub & private registry hygiene β€” no stale, unscanned images in production

πŸ† Credentials β€” Cryptographically Earned


πŸ… Certification 🏒 Issuer πŸ“… Year
☁️ AWS Certified Solutions Architect – Associate Amazon Web Services 2019
☁️ AWS Certified Developer – Associate Amazon Web Services 2020
☁️ AWS Certified Cloud Practitioner Amazon Web Services 2019
πŸ”· Microsoft Certified: Azure Fundamentals Microsoft 2020
🧠 Microsoft Certified: Azure AI Engineer Associate Microsoft 2024
πŸ€– Microsoft Certified: Azure AI Fundamentals Microsoft 2024
πŸ“Š Microsoft Certified: Azure Data Fundamentals Microsoft 2024
πŸ’Ό IBM Consulting Way IBM 2023
🏦 IBM Banking Industry Jumpstart IBM 2023

πŸ“‘ Live Activity Feed


  1. ❌ Closed PR #6 in dhivagar29/beagle

πŸ“ˆ Telemetry


🟒 This repo's own pipeline β€” secured & monitored

Markdown Lint Link Checker README Validation OpenSSF Scorecard



GitHub Streak


Metrics dashboard
Contribution snake animation

♾️ The DevSecOps Loop I Live By


 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚                                                                       β”‚
 β”‚   PLAN ──► CODE ──► BUILD ──► TEST ──► RELEASE ──► DEPLOY ──► RUN     β”‚
 β”‚     β”‚        β”‚        β”‚         β”‚          β”‚           β”‚        β”‚     β”‚
 β”‚   threat   secrets   SAST     DAST     signed       policy   runtime  β”‚
 β”‚   model    scan      + SCA    + pen    artifacts    gates    defense  β”‚
 β”‚     β”‚        β”‚        β”‚         β”‚          β”‚           β”‚        β”‚     β”‚
 β”‚     └────────┴────────┴────► SEC β—„β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β”‚
 β”‚                               β”‚                                       β”‚
 β”‚              feedback loops β—„β”€β”˜ every stage reports back              β”‚
 β”‚                                                                       β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

🌐 Open a Secure Channel


LinkedIn GitHub Location



$ echo "10+ years of secure cloud infrastructure, one signed commit at a time."
# IBM Infrastructure Specialist | DevSecOps | AWS Certified
# Nationwide Β· Citi Group Β· Cigna Β· Sanmina β€” regulated, audited, automated 🀝
$ exit 0  # zero vulnerabilities, zero excuses

Profile Views


"Shift left. Automate the toil. Sign everything. Trust nothing."

β€” Dhivagar Kamaraj, DevSecOps Β· Infrastructure Specialist @ IBM

Popular repositories Loading

  1. Leo Leo Public

    Forked from virejdasani/InYourFace

    In Your Face shows you Doom 'Ouch Faces' that correlate to the number of errors in your code!

    TypeScript

  2. chatbot-ui chatbot-ui Public

    Forked from mckaywrigley/chatbot-ui

    An open source ChatGPT UI.

    TypeScript

  3. naval-gpt naval-gpt Public

    Forked from mckaywrigley/naval-gpt

    AI search & chat for Naval Ravikant's Twitter thread "How To Get Rich."

    TypeScript

  4. ai-code-translator ai-code-translator Public

    Forked from mckaywrigley/ai-code-translator

    Use AI to translate code from one language to another.

    TypeScript

  5. Auto-GPT Auto-GPT Public

    Forked from Significant-Gravitas/AutoGPT

    An experimental open-source attempt to make GPT-4 fully autonomous.

    Python

  6. chatgpt-retrieval-plugin chatgpt-retrieval-plugin Public

    Forked from openai/chatgpt-retrieval-plugin

    The ChatGPT Retrieval Plugin lets you easily search and find personal or work documents by asking questions in everyday language.

    Python