Python
- Deploy cloud infrastructure, infrastructure as code on AWS/Azure with Terraform and Ansible for configurations
- Continuous Integration and Continuous Delivery (CI/CD - Jenkins/Bitbucket Actions)
- Build client's environments(test, acc, production) from scratch in VPC architecture, and deployed the application and the microservices with multiple Docker containers which communicated with each other to create the app ecosystem
- Cloud architecture design
- DevSecOps (SSL certificates for WEB and for the FIX connection, accountability for DAST and on the findings)
- Conducted large scale operations and provided guidance for the rest of the project team in the most critical situations
- Assumed critical operations decisions for releases/deployments
- Guided team members in their tasks
- Worked on behalf of the project for the biggest banks in Europe and had direct contact with the stakeholders within those banks
- Had direct alignments with the stakeholders of the project for the technical problems/improvements of the project and acted also as Team Leader/PO for DevSecOps & Software Automation areas in multiple ocassions
- designed the job interviews plan and interviewed candidates for DevOps & Software Automation positions
- Monitoring tools: Zabbix, Wazuh, Grafana, Opensearch
Top researches done:
[Snapshots-AMIs] Instance recovery procedure
[Snapshots-AMIs] Automatic backup procedure
[Snapshots-AMIs] Recovery-Restore procedure
FIX connection TLS certificate monitoring using EC2 extraction
FIX connection TLS certificate monitoring using EC2 extraction and Jenkins
FIX connection TLS certificate monitoring using EC2 extraction and Jenkins with Zabbix integration
IAM – Keycloak TLS Monitoring Over Single Sign On Certificates Using EC2 Extraction
IAM – Keycloak TLS Monitoring Over Single Sign On Certificates | Jenkins Integration
IAM – Keycloak TLS Monitoring Over Single Sign On Certificates | Jenkins & Zabbix Integration
First Mobile Application Build On Custom MacOS Docker OSX Image – CI/CD Integration With Jenkins
End to End Protractor tests Jenkins-Docker infrastructure – with Keycloak
ERP Connection for retrieving financial orders – Integration using a custom Python client
Jenkins Integration Architecture for Jmeter Performance tests and results data plotting in Python
FIX Connection integration in AWS – VPC infrastructure using a NLB
Optimisations in backup procedure using ZIP and S3 upload for big files - Ansible and Jenkins
Analysis on backup procedure (Zip and S3 upload) – spikes in I/O CPU Usage - Ansible and Jenkins
Infrastructure as a code with AWS WAF and Ansible – Managed Rules & Custom Whitelisting Rules
Jenkins jobs using slaves through AWS – Auto Scaling with Launch Configurations/Launch Templates
•Implementation of an automated structure of testing from scratch based on Protractor framework, integrated with an Angular + Spring Boot financial application
•Building the entire testing architecture from stage 0 to a stable solution which was executed in a automated way on every production version;
•The Angular testing concept was based mainly on OOP paradigm, through Typescript & JavaScript. Using page objects to separate the test specs from the framework backend part.
•Built the entire deployment testing pipeline using virtualisation focused on Docker containers, and orchestrate it by Jenkins shell scripts
•Built the solution for performance automated testing of the application's APIs. Every endpoint was treated in isolation and was measured to see if there are some performance leaks. Here were used tools like JMeter and Taurus framework on top, and embed all in a Jenkins deployment job through scripts
•Analysed and validated the security of the Spring Boot application API's in terms of field validation, business segregation of roles, error handling on different request injection approaches. Proposed new solutions where there were possible security vulnerabilities
•Analysis of the authentication part through an IAM solution, based on Keycloak. Improving the authentication flow within the application on the technical side that involves the generation of access tokens, their persistence and their business interpretation through the application.
•Conducted data migration tasks in code written in Java.
•Designing and creating integrations in the ERP module to work for different finance clients and discussing them directly with the stakeholders and clients
Working part time for an intern project and for the license thesis:
Modelation, and real time simulation of a DC Motor with LabVIEW; Built from the mathematical equations to a virtual modelation a Proportional Integral controller,to control the speed of the motor;
•Testing of the DC Motor through real time sequences, using Stimulus ProfileEditor;
AWS
AZURE
Jenkins
Serverless
Security Engineering
Linux
Python
Java
C
C
Bash
Criptography I - Stanford
DataIceberg
Personal project in Data Research https://dataiceberg.com/blog
Top researches:
- Custom autoscaling for Earthquake notification system with Confluent Kafka and AWS Lambda
- Serverless Earthquake notification system with Confluent Kafka and AWS Lambda using
multithreading and custom Dynamo concurrency control -> Presented at multiple cloud conferences
- Data streaming using Kiwi data with Confluent Kafka and SocketIO for a Flask Consumer – Broadcast topics data per socket room
- Data streaming using Kiwi data with Confluent Kafka and SocketIO for a Flask Consumer – Broadcast same data
- Trains Data extraction service – Consumers – Flask | Messaging Bots
- Trains Data extraction service in Serverless – Lambda | S3| ECR | EventBridge | SNS Part 2 - Data extraction from a train ticket platform – Part 1
- Flight Tickets Data extraction and price engine service – Consumers – Flask | Messaging Bots
- Flight Tickets Data extraction and price engine service in Serverless – Lambda | S3| ECR | EventBridge | SNS Part 2
- Data extraction from a flight ticket platform - Part 1
CYBOV
Personal project in cyber security http://cybov.com/blog
Top researches:
- Analysis of a bank card smishing attack using Posta Romana – Obfuscated JS and real time API Calls -> Presented at DefCamp Cluj-Napoca 2024
- Analysis on 3D Secure for top Romanian Banks
- Analysing 'missed voicemails' phishing attack with Python
- Anatomy of a WP-VCD backdoor malware attack
- Card theft with phishing email scheme using Netflix
XNEURON
Personal project in Data Research https://xneuron.com
Top researches:
- Anomaly detection for AWS WAF Events using Machine Learning – LSTM in SageMaker and AWS Lambda
- Flights prices predictions using LSTM and SageMaker with Lambda
- Anomaly detection for AWS WAF Events using Machine Learning – Isolation Forest
- Volunteer at Romanian Cyber Security Directorate from 01.09.2023
CertiPort IT Specialist - CyberSecurity
Kubernetes for the Absolute Beginners - Hands-on Tutorial - KodeKloud
Cisco - Cybersecurity Essentials
Unlocking Information Security I - Tel Aviv University & EDX
Unlocking Information Security II - Tel Aviv University & EDX
Criptography I - Stanford