Devops Engineer
Purplle.comJan, 2023 - Present3 yr 2 months
Automated GCP infrastructure provisioning using Terraform and Ansible, cutting manual setup time from 2 hours to under 10 minutes and ensuring identical environments across GCP and AWS. Engineered agentic MongoDB provisioning and lifecycle management using Ansible, Terraform, Jenkins, and n8n, reducing manual setup time from ~2 hours to under 15 min and standardizing deployments across 10+ environments. Hardened container security by implementing Kubernetes RBAC, Secure Boot, automated IAM role minimization using Python, SAST, DAST to detect and remediate vulnerable code, adhering to zero-trust architecture and DevSecOps principles resulting 70% reduction in Vulnerabilities. Migrated 15+ MySQL 5.7 legacy databases to 8.0 in production with minimal downtime, improving query performance by 20%. Optimized Jenkins CI/CD pipelines for applications serving 5M+ users, cutting production deployment times by 25% and enabling 50+ weekly zero-downtime rollouts. Reduced GCP monthly spend by 30% by automating resource scaling and implementing cost-optimized storage strategies for 100+ microservices. Owned on-call and incident response for production Kubernetes workloads supporting 5M+ users, leading P0/P1 incident triage, RCA, and remediation, and implementing automated recovery and preventive fixes that reduced MTTR by 35%. Engineered a scalable API-based secret management system (Go/Gin) handling 7M+ monthly requests for 250K+ active users, reducing access latency by 40% and eliminating unauthorized breaches. Built real-time monitoring solutions with Grafana, Prometheus, and Datadog, processing 2M+ daily metrics and reducing MTTR by 30% for incidents impacting 5M+ users. Deployed security automation in CI/CD using Trivy and GCP Security Command Center, reducing container and cloud vulnerabilities by 30% across production workloads. Collaborated with 20+ developers to standardize CI/CD pipelines and monitoring practices, reducing build failures by 30% and improving deployment consistency across projects. Implemented Single Sign-On (SSO) authentication & IP Whitelisting for multiple internal URLs, centralising access control and improving security posture.