Hire Me
Senior DevSecOps and platform engineer. Fourteen years across cloud, Kubernetes, CI/CD and security, contracting from NSW, Australia.
I build and secure the platforms that other engineers ship on. Kubernetes, cloud networking, delivery pipelines and the security controls that sit across all of them. Available for contract work.
The pitch#
I have been doing this since 2011, starting in backend development and datacentre hardware and moving through systems engineering into what is now called DevSecOps. That path matters: I have written the services, racked the servers they ran on, built the pipelines that deployed them, and then been on call when they broke. I speak developer, operator and security in the same conversation, which is usually where platform work succeeds or fails.
Most of my last decade has been senior contract roles for banks, fintechs and large enterprises, often as the person brought in to make Kubernetes, CI/CD and cloud security actually work for the teams using them. I like simple solutions to complicated problems, I like removing red tape, and I like leaving a team more self-sufficient than I found it.
What I do#
Platform and cloud. Design, build and run cloud platforms and the networking around them: ingress, WAF, load balancing, service mesh, VPCs and VPNs. Infrastructure as code with Terraform, Pulumi, Ansible and CloudFormation. AWS, Azure, GCP and Alibaba Cloud in production.
Delivery and developer tooling. CI/CD design and implementation on Jenkins, GitHub Actions, GitLab CI, Buildkite, Bamboo and Drone. Golang developer self-service tooling so teams can deploy, debug and provision without a ticket. Training and documentation so the process survives after I leave.
Security across the toolchain. Pipeline security compliance (Twistlock, Snyk, Sonatype, SourceClear), cloud posture remediation, AWS penetration testing, secrets and encryption design, secure logging pipelines, and the policy and documentation that make it auditable.
How I work#
- GitOps by default: issue, branch, PR, review. Documentation lives next to the code and is fixed in the same change.
- Evidence over assumption. When something is broken I want the data point, not the folk theory.
- I run my own lab infrastructure and treat it seriously, so I arrive already fluent in the failure modes.
Experience#
- Maintained and extended a proprietary cloud platform and its networking.
- Built and supported deployment pipelines and the product trade, distribution and logistics platform behind them.
- Backend code support for developer self-service tooling in Golang, plus training and on-call support for the teams using it.
- Database and messaging build-out and incident response on the on-call rotation.
- Designed and implemented AKS deployments and kept the clusters patched and secure.
- Python CI/CD pipeline development and maintenance of Bamboo Specs pipelines.
- Application connectivity (load balancing, WAF, VPC) and maintenance of the Terraform stacks.
- Built, redesigned and uplifted Jenkins CI/CD pipelines.
- Pipeline security compliance with Twistlock and Sonatype; cluster ingress security with Kong, WAF and ELB.
- Kubernetes and ECS infrastructure automation with Ansible and Terraform.
- Process and training improvements aimed squarely at removing red tape and increasing self-service.
- Cloud Conformity remediation and AWS security penetration testing.
- Automated security testing designed into the pipelines; Terraform orchestration.
- Security policy, encryption and secure logging (Firehose, Kinesis, Athena, CloudWatch, S3, ELK): design, implementation and training.
- EKS deployment, orchestration and security; Terraform orchestration.
- Developer tooling in Golang with Telepresence.
- CI/CD and orchestration design, implementation and training; GitHub organisation setup.
- EKS and Elastic Beanstalk deployment and orchestration; cluster networking with WAF, ELB and Istio.
- Python and Pulumi orchestration; GitLab and GitLab CI setup.
- CI/CD design, implementation and training.
- EKS deployment and security including spot-instance orchestration.
- AWS cloud networking; Ansible and Terraform IaC and migration; Jenkins CI/CD; container builds.
- EKS and ECS deployment and orchestration; AWS networking; CloudFormation to Terraform migration.
- Golang tooling, Buildkite CI/CD, container builds.
- DevSecOps controls: Twistlock, Snyk, SourceClear, WAF, CloudFront.
- Kubernetes and EC2 deployment and orchestration; Terraform platform deployment.
- VPN and Flannel networking across AWS and GCP; Golang tooling.
- Docker, Swarm and Kubernetes orchestration on Alibaba Cloud (Alibaba Cloud MVP).
- Cloud, VPN, Flannel, on-site Ubiquiti and Shadowsocks networking.
- Golang developer tools; Ansible and Terraform platform deployment; Drone, Jenkins and GitHub CI/CD.
- AWS orchestration with CloudFormation and Desired State Configuration; environment deployment automation.
- Bash, Python and PowerShell; Atlassian stack maintenance; cloud network engineering.
- Python and Perl development; Linux server and cloud orchestration.
- Windows systems administration and Cisco network engineering.
- Integration, platform, API and web development in C#, JavaScript, XAML and Razor; mobile app development.
- Azure cloud service engineering; release, debugging and monitoring; office network engineering.
- Datacentre build engineer: rack preparation, cabling, fibre runs, power, temperature and humidity management.
- Troubleshooting automated provisioning, IPMI and out-of-band management, and faulty server and network hardware.
- Backend services development and datacentre hosting.
- User database security and hot-fixing; Bitcoin transaction security; hardware troubleshooting.
Stack#
- Languages
- Containers
- Cloud
- IaC
- CI/CD
- Security
- Networking
- Data
- Virtualisation
- Operating systems
Education#
- 2008 to 2012: Advanced Diploma, Computer Systems Engineering.
- 2007: Certificate of General Education.
Get in touch#
Hiring enquiries go to james.griffis@atlasdigitalengineering.com.au. Tell me the problem, the stack and the timeframe and I will come back to you quickly. A PDF resume with referees is available on request.
If you use GPG, my key fingerprint is FA92 9DF3 2F5B EA3F DBBD A2A8 6740 B732 D350 7B5E.