Built an Amazon EKS platform with Infrastructure as Code and Helm, assembling cloud-native platform engineering and DevSecOps capabilities into a repeatable AWS deployment.
Designed a GitHub Actions-first supply-chain pipeline that mirrors upstream container images to GHCR, scans them, and attaches standards-based compliance evidence to immutable digests.
Developed a Chef InSpec overlay for applying the DISA Kubernetes STIG to Amazon EKS, with EKS-specific inputs, helper resources, and documented managed-control-plane exemptions.
Built a TypeScript Kubernetes offensive-security framework for controlled simulation of adversarial behavior using modular techniques mapped to MITRE ATT&CK.