Skip to main content
HimalayasHimalayas logo
Deland KumeDK
Open to opportunities

Deland Kume

@delandkume

I’m a Senior DevSecOps Engineer securing AWS GovCloud with CSPM, Terraform, and compliant CI/CD automation.

United States
Message

What I'm looking for

I’m looking to help teams ship secure, compliant cloud platforms—combining CSPM remediation, IaC guardrails, and DevSecOps pipelines—where I can work across security architecture and the pipeline/platform details to reduce noise and improve time-to-fix.

I’m a Senior DevSecOps Engineer with 9+ years of experience securing AWS GovCloud (IL4/IL5) and other regulated environments, including federal, banking, and insurance workloads. I bring deep hands-on expertise across CSPM/CWPP operations, IaC, Kubernetes hardening, and pipeline security.

One of my most impactful builds is a production agentic AI security remediation system on AWS Bedrock (Claude). It ingests findings from Security Hub, GuardDuty, Wiz, SonarQube, and Checkov, then auto-generates human-reviewed fix MRs in GitLab to reduce PR noise while preserving review quality.

I consistently deliver measurable platform hardening and automation: I wrote custom Wiz policies aligned to compliance frameworks, authored modular Terraform baselines for zero trust and security guardrails, and rolled them out at scale using CloudFormation Stack Sets. I also rebuilt the GitLab CI/CD pipeline library with DAG-based stages, shared scan/sign/deploy templates, and blocking quality gates tuned to severity thresholds.

On Kubernetes and governance, I’ve managed EKS clusters with IRSA, applied Pod Security Standards and network policies, and enforced admission controls using Kyverno. I’ve also delivered runtime visibility and zero-trust workload communication with Falco and Istio mTLS, while integrating centralized observability and compliance monitoring through Splunk and AWS logs.

Experience

Work history, roles, and key accomplishments

AL
Current

Senior DevSecOps Engineer

A3 Consulting LLC

Dec 2024 - Present (1 year 6 months)

Operated Wiz CSPM/CWPP across AWS GovCloud accounts and built a production agentic AI security remediation system on AWS Bedrock that ingests Security Hub/GuardDuty/Wiz/SonarQube/Checkov findings and auto-generates human-reviewed GitLab fix merge requests. Rebuilt a GitLab CI/CD pipeline library with blocking SAST/IaC/container gates and modular Terraform security baselines deployed via CloudForma

DC

Senior DevSecOps Engineer

DecisionPoint Corp

Dec 2022 - Dec 2024 (2 years)

Operated Wiz CSPM/CWPP on AWS GovCloud and remediated IAM and exposure findings using attack path analysis to prioritize toxic combinations. Hardened EKS with CIS Benchmark controls, enforced zero-trust Istio mTLS, and owned GovCloud DoD deployments with GitLab CI/CD, ArgoCD, and parallel SAST/SCA/IaC/container scanning stages.

U.S. Bank logoUB

Cloud Security Engineer

Mar 2022 - Dec 2022 (9 months)

Hardened AWS accounts using CIS Benchmark controls and AWS Config rules, authored SCPs across AWS Organizations, and integrated Security Hub aggregations of GuardDuty/Inspector/Macie/AWS Config. Implemented regulated banking CI/CD quality gates in GitLab with SonarQube SAST, Checkov IaC scanning, and Snyk SCA, plus CloudTrail-based key usage auditing and compliance evidence collection for SOC 2 an

U.S. Bank logoUB

DevSecOps Engineer

Mar 2019 - Mar 2022 (3 years)

Built and operated Kubernetes environments on EKS and GKE, securing workload identity with IRSA on AWS and Workload Identity Federation on GCP using least-privilege service accounts. Designed hybrid connectivity with Site-to-Site VPN (BGP) and Direct Connect failover, and delivered observability with Prometheus/Grafana/ELK/Splunk and CloudWatch/CloudTrail aggregation that reduced MTTR via dashboar

EU

Cloud Engineer

ESL Federal Credit Union

Feb 2018 - Mar 2019 (1 year 1 month)

Built GitLab CI/CD pipelines using ArgoCD and Helm to deploy to EKS across dev/staging/production, integrating ECR image builds with Trivy scanning and automated base image patch workflows. Designed AWS infrastructure with CloudFormation/Terraform (VPC/ALB/RDS Multi-AZ/EC2 auto-scaling), administered Linux/Windows with Ansible for patching and CIS hardening, and supported SOC 2/PCI-HIPAA audit evi

AI

Solution Architect

American National Insurance

Jan 2017 - Jan 2018 (1 year)

Designed AWS hybrid cloud architectures with CloudFormation/Terraform and implemented Site-to-Site VPN with BGP routing between on-premises data centers and AWS VPCs. Led migration assessments using AWS CART and executed relational database migrations to AWS with DMS for minimal downtime while building multi-tier AWS environments and cross-region DR patterns for S3 and RDS.

Education

Degrees, certifications, and relevant coursework

University of Maryland Global Campus logoUC

University of Maryland Global Campus

Master of Science, Cloud Computing

Pursuing an M.S. in Cloud Computing at the University of Maryland Global Campus.

University of Buea logoUB

University of Buea

Bachelor of Science, Computer Science

Earned a B.S. in Computer Science from the University of Buea.

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan