Skip to content
View officialsangdavid's full-sized avatar

Block or report officialsangdavid

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
officialsangdavid/README.md

Hi πŸ‘‹πŸΏ, I am Sang David

A DevSecOps Engineer with experience using Cloud-native Applications, integrating security into Software Developement Life Cycles, Threat Modelling for System Architectures, DevOps, Technical Writing, and Public Speaking.

πŸ§‘πŸΏβ€πŸ’» Proffessional Journey

Throughout my career as a DevSecOps Engineer with hands-on experience in building secure, scalable, and production-ready applications, I have:

  • Integrated Secret Management, Image Scanning, SAST, and DAST tools like Trufflehog, Trivy, Snyk, SonarQube, and OWASP ZAP respectively into CI/CD pipelines to scan codebases, Docker images, and dependencies for vulnerabilities and poor coding practices.
  • Implemented pre-commit hooks to validate developer code before Git commits locally.
  • Facilitated cross-team communication between Design, Development, and Security teams, ensuring smooth collaboration and timely bug fixes.
  • Managed QA processes and updated management on test results, backlogs, and deployment readiness for applications.
  • Implemented security policies for GitHub branch; This is to enforce access control and ensure CIA of codebase.
  • Conducted integration and unit tests for applications via the CI/CD Pipeline and manually as well.
  • Deployed applications on Deployment Platforms like DigitalOcean, AWS, Railway, and Render.
  • Led Vulnerability Assessments across applications and proactively mitigating security risks.
  • Containerized microservices using Docker and managed organizational image registries.
  • Delivered DevSecOps training to 50–70 job seekers and interns, covering CI/CD, containerization, secure SDLC, infrastructure as code, etc.
  • Learned and applied technical writing skills, including creating FAQs, user manuals, documentation, and guides for some projects I have worked on and my personal projects as well.
  • Mastered technical writing tools, style guides, active voice, and proper verb usage to ensure clarity and professionalism.

πŸ’» Current Most Used Tools

Docker Kubernetes AWS Snyk SonarQube Ubuntu Terraform Bash YAML Render Prometheus GitHub Actions GitLab SonarQube Grafana Git OWASP ZAP Trivy Gitleaks Trufflehog VSCode Markdown Jam.dev Hashnode Linux HackMD NGINX Nmap Nessus Jenkins Burp Suite Checkmarx

How to Reach Me

LinkedIn Twitter

Read My Technical Documentations

Hashnode Medium

Popular repositories Loading

  1. m4z3 m4z3 Public

    JavaScript

  2. hng13-stage0-devops hng13-stage0-devops Public

    Forked from hngprojects/hng13-stage0-devops

    Repository for HNG13 stage0 devops task

    HTML

  3. hng13-stage1-devops hng13-stage1-devops Public

    Shell

  4. hng13-stage1-devops-app hng13-stage1-devops-app Public

    HTML

  5. hng-stage2-devops hng-stage2-devops Public

    Shell

  6. officialsangdavid officialsangdavid Public