App LogoApp name
MT

Madaka Tara Kiran Nath

Open to work6 years experience

Senior DevSecOps Engineer

Visakhapatnam, Vishākhapatnam, Andhra Pradesh, INDTarget Roles: Backend Engineer • Full-Stack Developer • Frontend Specialist

Senior DevSecOps Engineer specializing in AWS Cloud Security, Terraform at Scale, EKS, and AI-powered DevOps.

GitHub

Standing Rank

Rank Not Available

Developer Badges

No badges earned yet

Skills & Technologies

47 skills
aws iamscpspermission boundariesaws organizationsleast-privilege designcis benchmarksterraformterragruntopentofucloudformationansiblegithub actionsjenkinsterraform cloudkubernetes rbaceksadmission controlnetwork policiesruntime securityimage scanningaws security hubguarddutycloudtrailcloudwatchopa/gatekeepersastdependency scanninghashicorp vaultdynamic credentialssecret rotationhardcoded credential eliminationsupply chain securitysoc 2 trust services criteriaaudit evidence collectionvulnerability managementregulatory reportingon-call (24×7)post-incident reviewsrcarunbook developmentrto/rpo managementllm-powered agentsclaude apiamazon bedrockagentic workflowsai-assisted cloud operationspython

Work Experience

Sr. DevSecOps Engineer

Umbrella Infocare Pvt. Ltd. (Client: ABSA Bank, South Africa)

Dec 2024 - Present
  • Owned AWS IAM strategy across a multi-account banking environment — authored SCPs, permission boundaries, and least-privilege access controls for service accounts, CI/CD pipelines, and developer roles; maintained cloud security posture aligned to CIS Benchmarks and ABSA regulatory requirements.
  • Designed AWS Organizations SCP guardrails enforcing data perimeter controls (aws:PrincipalOrgID), restricting unauthorized region usage, preventing root user actions, and denying disabling of CloudTrail/GuardDuty — directly contributing to SOC 2 CC6 and CC7 compliance controls.
  • Built and maintained secure CI/CD pipelines (Jenkins + GitHub Actions) with integrated SAST, dependency scanning, container image scanning, and secrets detection gates.
  • Operated and hardened EKS-based Kubernetes platform — implemented RBAC policies (Roles, ClusterRoles, RoleBindings), admission control, network policies, and namespace-level workload isolation across CI/CD service accounts.
  • Eliminated hardcoded credentials across AWS and Kubernetes environments via HashiCorp Vault dynamic secrets — enforced secret rotation and secured the software supply chain end-to-end.
  • Delivered centralized security observability using AWS Security Hub, GuardDuty, CloudTrail, and CloudWatch — supported threat detection, alert triage, and audit compliance for regulated banking workloads.
  • Authored IAM policy matrices, SCP inventories, vulnerability management trackers, and audit evidence artifacts — maintained continuous audit-readiness against SOC 2 and banking regulatory requirements.
  • Conducted OPA/Gatekeeper governance reviews to identify and remediate IAM misconfigurations; led post-incident reviews and owned follow-up remediation items.
  • Mentored junior DevOps engineers on IaC best practices, security policy authoring, and incident response procedures — contributing to team skill uplift across a 6-person platform squad.

Freelance DevSecOps & AI Engineering

Independent Consulting

Dec 2025 - Present
  • Building production-grade AI agents that automate cloud operations, cost governance, and infrastructure compliance — bridging DevSecOps expertise with emerging agentic AI capabilities.

DevOps Engineer

iGlobal Consulting Pvt. Ltd.

Sep 2020 - Dec 2024
  • Designed and owned end-to-end Terraform architecture for a 200+ account AWS estate structured into layered root modules for networking, compute, data, security, and observability.
  • Developed a library of 20+ reusable, versioned Terraform modules (published to a private module registry) covering VPC design, EKS, ECS, RDS Multi-AZ, ALB/NLB, API Gateway, Lambda, Auto Scaling, IAM, S3, CloudWatch, and SNS.
  • Implemented remote Terraform state management using S3 backends with per-environment isolation, DynamoDB locking, KMS encryption at rest, and S3 versioning + MFA-delete.
  • Built Terraform CI/CD pipelines (GitHub Actions) with automated plan, OPA/Conftest policy-as-code validation, tfsec SAST, Infracost cost estimation, and apply-on-merge gates.
  • Structured repository using an environment-segregated mono-repo with Terragrunt as the DRY orchestration layer.
  • Standardized environment parity across Dev, UAT, and Prod using Terraform workspaces and per-environment tfvars.
  • Automated RDS provisioning including Multi-AZ parameter groups, IAM database authentication, automated snapshot retention, and KMS-encrypted storage.
  • Migrated 200+ legacy manually-provisioned AWS resources to Terraform-managed state using terraform import workflows.
  • Designed multi-cloud deployment framework (AWS + GCP) using Terraform and Kubernetes (EKS/GKE).
  • Provided 24×7 production support with incident response, RCA, and post-incident reviews — developed runbooks and alerting procedures to consistently meet RTO/RPO objectives.

Projects

Kubernetes AI Troubleshooting Agent

PythonClaude APIkubectlPrometheusEKS
  • Built an agentic AI system that autonomously diagnoses Kubernetes cluster failures.
  • Implemented a multi-step tool-use loop where the agent iteratively calls kubectl describe, kubectl logs, and metrics APIs.
  • Integrated with PagerDuty and Slack.
  • Deployed as a lightweight AWS Lambda function triggered by CloudWatch alarms.

AI Cloud Cost Detective

PythonClaude APIAWS Cost ExplorerAWS BudgetsLambda
  • Designed an AI-driven cost analysis agent that ingests AWS Cost Explorer spend data, identifies anomalies and waste patterns, and generates a prioritized cost-reduction report.
  • Agent uses an LLM reasoning layer to interpret cost trend data in plain language.
  • Implemented multi-account cost aggregation using AWS Organizations and Cost Explorer APIs.
  • Scheduled weekly digest via EventBridge + Lambda.

Terraform Drift Detector

PythonClaude APITerraformAWSGitHub ActionsSNS
  • Built an automated drift detection pipeline that runs terraform plan in read-only mode across all environments on a schedule.
  • Agent reasons over drift context — distinguishing intentional manual changes from unauthorized modifications.
  • Integrated with GitHub Actions as a scheduled workflow.
  • Designed notification routing via SNS.

Leaderboard Standings

Leaderboard Position Pending

Global test scores, peer standing percentiles, and algorithm leaderboard ranks are updated dynamically.

Assessment Highlights

Assessments Not Completed

Coding evaluations, system assessment results, and conceptual score badges will appear here after taking a test.

AI Collaboration Score

AI Collaboration Score Pending

Developer coding behavior, assistant cooperation, and AI pair-programming indicators are evaluated during live coding sessions.

Role Compatibility Profile

Role Compatibility Analysis Pending

Custom matching reports, candidate role compatibility percentiles, and core engineer strength profiles are processed once conceptual code screenings are complete.

Achievements

Deployment Efficiency Improvement

Reducing deployment effort by 40–60% through IaC automation.

Vulnerability Identification Optimization

Cutting vulnerability identification time by 3× through shift-left pipeline integration.

About Details

Professional Bio

Senior DevSecOps Engineer with 5+ years securing cloud-native infrastructure in regulated financial environments. Specializes in Terraform architecture at scale, AWS IAM hardening, and EKS/Kubernetes security. Currently building AI-powered DevOps agents using LLMs and agentic frameworks.

Bachelor of Technology (B.Tech)

MVGR College of Engineering, Vizianagaram, Andhra Pradesh ( - 2019)

Languages: English, Hindi