Deland Kume
@delandkume
I’m a Senior DevSecOps Engineer securing AWS GovCloud with CSPM, Terraform, and compliant CI/CD automation.
What I'm looking for
I’m a Senior DevSecOps Engineer with 9+ years of experience securing AWS GovCloud (IL4/IL5) and other regulated environments, including federal, banking, and insurance workloads. I bring deep hands-on expertise across CSPM/CWPP operations, IaC, Kubernetes hardening, and pipeline security.
One of my most impactful builds is a production agentic AI security remediation system on AWS Bedrock (Claude). It ingests findings from Security Hub, GuardDuty, Wiz, SonarQube, and Checkov, then auto-generates human-reviewed fix MRs in GitLab to reduce PR noise while preserving review quality.
I consistently deliver measurable platform hardening and automation: I wrote custom Wiz policies aligned to compliance frameworks, authored modular Terraform baselines for zero trust and security guardrails, and rolled them out at scale using CloudFormation Stack Sets. I also rebuilt the GitLab CI/CD pipeline library with DAG-based stages, shared scan/sign/deploy templates, and blocking quality gates tuned to severity thresholds.
On Kubernetes and governance, I’ve managed EKS clusters with IRSA, applied Pod Security Standards and network policies, and enforced admission controls using Kyverno. I’ve also delivered runtime visibility and zero-trust workload communication with Falco and Istio mTLS, while integrating centralized observability and compliance monitoring through Splunk and AWS logs.
Experience
Work history, roles, and key accomplishments
Senior DevSecOps Engineer
A3 Consulting LLC
Dec 2024 - Present (1 year 6 months)
Operated Wiz CSPM/CWPP across AWS GovCloud accounts and built a production agentic AI security remediation system on AWS Bedrock that ingests Security Hub/GuardDuty/Wiz/SonarQube/Checkov findings and auto-generates human-reviewed GitLab fix merge requests. Rebuilt a GitLab CI/CD pipeline library with blocking SAST/IaC/container gates and modular Terraform security baselines deployed via CloudForma
Senior DevSecOps Engineer
DecisionPoint Corp
Dec 2022 - Dec 2024 (2 years)
Operated Wiz CSPM/CWPP on AWS GovCloud and remediated IAM and exposure findings using attack path analysis to prioritize toxic combinations. Hardened EKS with CIS Benchmark controls, enforced zero-trust Istio mTLS, and owned GovCloud DoD deployments with GitLab CI/CD, ArgoCD, and parallel SAST/SCA/IaC/container scanning stages.
Hardened AWS accounts using CIS Benchmark controls and AWS Config rules, authored SCPs across AWS Organizations, and integrated Security Hub aggregations of GuardDuty/Inspector/Macie/AWS Config. Implemented regulated banking CI/CD quality gates in GitLab with SonarQube SAST, Checkov IaC scanning, and Snyk SCA, plus CloudTrail-based key usage auditing and compliance evidence collection for SOC 2 an
Built and operated Kubernetes environments on EKS and GKE, securing workload identity with IRSA on AWS and Workload Identity Federation on GCP using least-privilege service accounts. Designed hybrid connectivity with Site-to-Site VPN (BGP) and Direct Connect failover, and delivered observability with Prometheus/Grafana/ELK/Splunk and CloudWatch/CloudTrail aggregation that reduced MTTR via dashboar
Cloud Engineer
ESL Federal Credit Union
Feb 2018 - Mar 2019 (1 year 1 month)
Built GitLab CI/CD pipelines using ArgoCD and Helm to deploy to EKS across dev/staging/production, integrating ECR image builds with Trivy scanning and automated base image patch workflows. Designed AWS infrastructure with CloudFormation/Terraform (VPC/ALB/RDS Multi-AZ/EC2 auto-scaling), administered Linux/Windows with Ansible for patching and CIS hardening, and supported SOC 2/PCI-HIPAA audit evi
Solution Architect
American National Insurance
Jan 2017 - Jan 2018 (1 year)
Designed AWS hybrid cloud architectures with CloudFormation/Terraform and implemented Site-to-Site VPN with BGP routing between on-premises data centers and AWS VPCs. Led migration assessments using AWS CART and executed relational database migrations to AWS with DMS for minimal downtime while building multi-tier AWS environments and cross-region DR patterns for S3 and RDS.
Education
Degrees, certifications, and relevant coursework
University of Maryland Global Campus
Master of Science, Cloud Computing
Pursuing an M.S. in Cloud Computing at the University of Maryland Global Campus.
University of Buea
Bachelor of Science, Computer Science
Earned a B.S. in Computer Science from the University of Buea.
Tech stack
Software and tools used professionally
Splunk
AWS IAM
Microsoft Azure
GitHub
GitLab
SonarQube
Kubernetes
kaniko
Amazon EKS
Jenkins
GitHub Actions
GitLab CI
Gmail
Okta
Terraform
Jira
PowerShell
Istio
Grafana
Kibana
Prometheus
etcd
Ubuntu
Linux
Windows
Falco
Prisma
OpenSearch
AWS WAF
CrowdStrike
Ansible
AWS Lambda
sso
VMware vSphere
GuardRails
Root Cause
SQL
AWS KMS
Snyk
Trivy
Kyverno
Wiz
ArgoCD
Evidence
Bash
Checkov
Gitleaks
Agentic
Remote
Namespace
Falcon
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Deland?
You can contact Deland and 90k+ other talented remote workers on Himalayas.
Message DelandFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
