βββββββ βββ βββββββββ βββ ββββββ βββββββ ββββββ βββββββ
βββββββββββ βββββββββ βββββββββββββββββββ ββββββββββββββββ
βββ βββββββββββββββββ ββββββββββββββ ββββββββββββββββββββ
βββ ββββββββββββββββββ βββββββββββββββ βββββββββββββββββββ
βββββββββββ ββββββ βββββββ βββ βββββββββββββββ ββββββ βββ
βββββββ βββ ββββββ βββββ βββ βββ βββββββ βββ ββββββ βββ
$ ssh visitor@github.com/dhivagar29
> negotiating cipher suite .......... TLS 1.3 β
> verifying host identity ........... signature valid β
> scanning session for anomalies .... clean β
> ACCESS GRANTED β entering the secure pipeline.identity:
name: "Dhivagar Kamaraj"
role: "Infrastructure Specialist β DevSecOps"
org: "IBM"
location: "π Bengaluru, Karnataka, India"
experience: "10+ years across regulated cloud environments"
domain: "Financial Services | Cloud Security | Platform Engineering"
operating_principles:
- "Shift security left β every commit is a control point"
- "If it isn't codified, it isn't compliant: IaC + policy-as-code"
- "Least privilege by default β IAM is the real perimeter"
- "Pipelines should fail fast on vulnerabilities, not in production"
- "Observability is a security control, not just an SRE tool"
current_focus:
- "Hardened CI/CD: SAST, SCA, secrets scanning, image signing"
- "Zero-trust AWS architectures for customer-facing FinServ workloads"
- "Automated compliance & drift detection in regulated environments"
contact:
linkedin: "linkedin.com/in/dhivagar-kamaraj"
github: "github.com/dhivagar29"
education: "B.E. Computer Science β SRM Valliammai Engineering College, 2013"
philosophy: "Automate everything. Secure by default. Trust nothing, verify all."2014 ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββΊ Present
[M-Square] [Sanmina SCI] [Cognizant] [Infosys] [IBM]
Network Admin Programmer Associate Consultant Infra Spec.
May'14-Apr'16 May'16-Aug'18 Aug'18-Jun'20 Dec'20-Mar'22 Mar'22-Now
β β β β β
Hardened OS & Multi-cloud Containerized Automated Zero-trust
network admin AWS/GCP/OnPrem CI/CD on K8s secure AWS for UK
foundations + monitoring for healthcare releases for banking at
(HIPAA-bound) Citi (FinServ) Nationwide
βββββββββββββββββββββββββ SHIFT LEFT ββββββββββββββββββββββββ
ββββββββββββ ββββββββββββ ββββββββββββ ββββββββββββ ββββββββββββ
β CODE ββββΊβ COMMIT ββββΊβ BUILD ββββΊβ DEPLOY ββββΊβ RUN β
ββββββ¬ββββββ ββββββ¬ββββββ ββββββ¬ββββββ ββββββ¬ββββββ ββββββ¬ββββββ
β β β β β
π IDE lint π secrets π§ͺ SAST + π policy- π‘ runtime
+ threat scanning, SCA, image as-code monitoring,
modeling signed scan & gates, IaC CloudWatch /
commits SBOM drift checks CloudTrail
β β β β β
ββββββββββββββββ΄βββββββΊ FAIL FAST βββββββββββ΄βββββββββββββββ
vulnerabilities stop here, not in prod
|
π Security & Compliance |
π§ͺ Pipeline Security Toolchain |
βοΈ Cloud Platforms |
|
βοΈ CI/CD & DevOps |
ποΈ Infrastructure as Code |
π³ Containers & Orchestration |
|
π» Languages & Scripting |
π‘ Detection & Observability |
ποΈ Databases & SCM |
Zero-trust AWS infrastructure for one of the UK's largest financial institutions
- π Enforced least-privilege IAM roles & policies meeting FCA-grade regulatory compliance and protecting sensitive customer data
- ποΈ Architected scalable, security-hardened AWS solutions for customer-facing workloads
- π‘οΈ Embedded security gates into CI/CD β vulnerabilities caught at commit, not in production
- π Real-time threat-aware monitoring with CloudWatch, CloudTrail & Lambda auto-remediation
Securing and accelerating releases for a critical global banking platform
- β‘ Cut deployment cycle from ~5 days β 2 days without bypassing a single security control
- π€ Replaced error-prone manual ops with auditable open-source automation
- π Authored SOPs & runbooks around failure and incident-response scenarios
- π₯οΈ Maintained hardened high-availability clustered environments in a regulated FinServ landscape
Compliant CI/CD automation for healthcare cloud infrastructure
- π Built fully automated Jenkins / GitLab pipelines for HIPAA-sensitive workloads
- ποΈ Delivered Infrastructure as Code with Terraform, CloudFormation & Ansible β reviewable, auditable, repeatable
- π³ Containerized workloads with Docker & Kubernetes on AWS/GCP, managing the full image lifecycle
- π¦ Governed Docker Hub & private registry hygiene β no stale, unscanned images in production
| π Certification | π’ Issuer | π Year |
|---|---|---|
| βοΈ AWS Certified Solutions Architect β Associate | Amazon Web Services | 2019 |
| βοΈ AWS Certified Developer β Associate | Amazon Web Services | 2020 |
| βοΈ AWS Certified Cloud Practitioner | Amazon Web Services | 2019 |
| π· Microsoft Certified: Azure Fundamentals | Microsoft | 2020 |
| π§ Microsoft Certified: Azure AI Engineer Associate | Microsoft | 2024 |
| π€ Microsoft Certified: Azure AI Fundamentals | Microsoft | 2024 |
| π Microsoft Certified: Azure Data Fundamentals | Microsoft | 2024 |
| πΌ IBM Consulting Way | IBM | 2023 |
| π¦ IBM Banking Industry Jumpstart | IBM | 2023 |
- β Closed PR #6 in dhivagar29/beagle
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β β
β PLAN βββΊ CODE βββΊ BUILD βββΊ TEST βββΊ RELEASE βββΊ DEPLOY βββΊ RUN β
β β β β β β β β β
β threat secrets SAST DAST signed policy runtime β
β model scan + SCA + pen artifacts gates defense β
β β β β β β β β β
β ββββββββββ΄βββββββββ΄βββββΊ SEC ββββββββββ΄ββββββββββββ΄βββββββββ β
β β β
β feedback loops βββ every stage reports back β
β β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
$ echo "10+ years of secure cloud infrastructure, one signed commit at a time."
# IBM Infrastructure Specialist | DevSecOps | AWS Certified
# Nationwide Β· Citi Group Β· Cigna Β· Sanmina β regulated, audited, automated π€
$ exit 0 # zero vulnerabilities, zero excuses"Shift left. Automate the toil. Sign everything. Trust nothing."
β Dhivagar Kamaraj, DevSecOps Β· Infrastructure Specialist @ IBM