Hi there! π Iβm O Jegede, a passionate and hands-on DevOps & DevSecOps Engineer and Cybersecurity Analyst with a growing portfolio of real-world projects focused on secure cloud infrastructure, CI/CD automation, identity and access management (IAM), and threat detection.
With a background in both cloud engineering and cybersecurity, I build systems that are not only scalable and automated β but also secure by design.
From automating pipelines to hardening infrastructure, I approach DevOps with a cybersecurity lens. Whether itβs integrating static code analysis into a Jenkins pipeline or deploying an intrusion detection system (IDS) alongside a Kubernetes cluster β I ensure that security is baked into every layer.
- DevOps & CI/CD Pipelines: Jenkins, GitHub Actions, Docker, Terraform, Kubernetes (EKS), AWS
- DevSecOps: SAST/DAST, container scanning, compliance-as-code, shift-left security
- Identity & Access Management: Role-based access control, SSO, MFA, policies using Okta, AWS IAM, and OAuth 2.0
- Cybersecurity Operations: Vulnerability management, SIEM, IDS/IPS, malware analysis, threat detection
- Monitoring & Logging: Prometheus, Grafana, Wazuh, Elastic Stack
Here's a curated list of projects Iβve completed as part of my DevOps and DevSecOps professional journey. Each project is built to replicate enterprise environments and solve real-world infrastructure, security, and automation challenges β using cutting-edge tools and best practices.
Automated provisioning and configuration of cloud-native resources using reusable, version-controlled IaC templates.
- Terraform Modules β Modularized VPCs, EC2s, IAM policies, ALBs, RDS, and S3 across environments
- CloudFormation Templates β Scalable infrastructure stacks using YAML and cross-stack references
- Secure IaC Pipelines β Policy-as-code integration with tools like OPA and Checkov for early IaC scanning
Cloud-native development and infrastructure orchestration for high availability, scalability, and resilience.
- 3-Tier Architecture β Web/App/DB stack deployed on AWS using Terraform and EC2/RDS/ALB
- IAM & Role-Based Access β Secure IAM roles, policies, and MFA enforcement
- Secrets Management β Using AWS Secrets Manager + environment-specific configurations
End-to-end pipelines for automated builds, testing, security checks, and multi-env deployments.
- Declarative multi-stage pipelines for container builds, vulnerability scanning, and multi-environment deployments
- Integrated SonarQube for SAST, Snyk for SCA, and Trivy for container scans
- Slack and email notifications on pipeline events and failures
- Secure GitLab runners executing IaC validation, container builds, and Helm/Kustomize-based Kubernetes rollouts
- Integrated Vault secrets injection and DAST testing for web applications
- GitOps-style workflows for merging changes into staging β production via protected branches
Hands-on experience deploying secure, production-grade workloads on Kubernetes using GitOps and IaC strategies.
- Helm Charts β Package, version, and release microservices with dynamic configuration
- Kustomize Overlays β Managed multi-environment deployments (dev, stage, prod) using overlays and patching
- EKS Clusters β Deployed and managed AWS EKS clusters using Terraform
- RBAC Policies β Controlled access per namespace and role using Kubernetes RoleBindings
Security-first automation ensuring security is not an afterthought.
- Pre-Commit Hooks β Enforced secret detection and linting before PRs are merged
- Container Security β Docker image scanning with Trivy, Grype, and Clair
- Policy-as-Code β OPA & Rego used to define and enforce deployment and RBAC policies in CI
- Audit Logging β Kubernetes audit logs and AWS CloudTrail for traceability and compliance
Built full-stack observability pipelines to monitor applications and infrastructure health.
- Prometheus + Grafana β Monitored Kubernetes pods, node health, and custom app metrics
- ELK Stack β Centralized log analysis from EKS, Lambda, and EC2
- AlertManager β Real-time alerts on resource exhaustion, failed deployments, or SLA violations
| Category | Tools & Platforms |
|---|---|
| Infrastructure | Terraform, CloudFormation, AWS CLI |
| CI/CD Automation | Jenkins, GitLab CI, GitHub Actions |
| Kubernetes | EKS, Helm, Kustomize, ArgoCD |
| Security & Scanning | SonarQube, Snyk, Trivy, OPA |
| Monitoring & Logs | Prometheus, Grafana, ELK Stack, Loki |
| OS & Virtualization | Linux, macOS, Windows, VirtualBox, VMware |
| Source Control | Git, GitHub, GitLab |
| Scripting & Docs | Bash, Python, Markdown |
| Project | Description | Link |
|---|---|---|
infrastructure |
Highly scalable and available infrastructure using Terraform on EC2 and ECS | View Repo |
microservices-project |
Deploying microservices to AWS EKS | View Repo |
cicd-pipeline |
CI/CD pipeline infrastructure using Jenkins | View Repo |
3-tier-infrastructure |
Terraform project building a full 3-tier architecture on AWS | View Repo |
lambda-project |
Serverless Python project using AWS Lambda and API Gateway | View Repo |
cloudformation-project |
End-to-end infrastructure automation using AWS CloudFormation | View Repo |
Here's a curated list of projects Iβve completed as part of my cybersecurity learning journey. Each project is designed to replicate real-world scenarios, using industry tools and best practices.
- β Setting Up a Virtual Home Lab (on macOS and Windows)
- βοΈ Cloud Home Lab Setup (for scalable, remote testing)
- π₯ Active Directory Deployment (user/privilege simulation)
- π Footprinting β Passive and active info gathering
- π Phishing Email Analysis β Identifying spoofed domains, headers, and payloads
- π§« Vulnerability Assessment β Using OpenVAS, Nessus, Nmap
- π SIEM Setup with Wazuh β Centralized log analysis and alerting
- π Elastic SIEM β Kibana dashboards and threat hunting
- π‘ Suricata IDS Setup β Intrusion detection using signature-based rules
- π§² Honeypot Deployment β Detecting and analyzing attacker behavior
- π§Ύ Malicious PDF Analysis β Dissecting payloads and embedded scripts
- π§ Malware Analysis β Using Ghidra, VirusTotal, and sandboxes
- π Setting Up a Personal VPN Server β Secure remote connections using WireGuard/OpenVPN
- π₯ VirtualBox, VMware, AWS Free Tier
- π§ͺ Wireshark, Nmap, Metasploit
- π Wazuh, Suricata, Elastic Stack
- π§ Linux, macOS, Windows
- π Markdown, Git, GitHub
| Project | Description | Link |
|---|---|---|
virtual-home-lab |
Setting up a local cyber lab on macOS/Windows | View Repo |
cloud-home-lab |
Building a cloud-based home lab for cybersecurity practice | View Repo |
footprinting-techniques |
Info gathering via open-source intelligence and active scanning | View Repo |
vulnerability-assessment |
Scan and assess network vulnerabilities using security tools | View Repo |
phishing-email-analysis |
Analyzing phishing emails and spotting key red flags | View Repo |
wazuh-siem-lab |
End-to-end guide for setting up Wazuh SIEM | View Repo |
elastic-siem-setup |
Configuring Elastic Stack for threat hunting | View Repo |
suricata-ids-lab |
Step-by-step IDS setup using Suricata | View Repo |
honeypot-deployment |
Deceptive traps to attract and analyze cyber attackers | View Repo |
pdf-malware-analysis |
Reverse engineering malicious PDFs | View Repo |
malware-analysis-basics |
Using Ghidra and online sandboxes to inspect malware | View Repo |
vpn-server-setup |
Create a personal VPN on the cloud | View Repo |
Thanks for stopping by my GitHub!
Feel free to β star any repo that helps you, and connect if youβd like to collaborate or chat about DevOps x Security π»π₯
