Open to opportunities·2+ years experience

DevSecOps Engineer · Singapore

~$

~ neofetch
joe@localhost
Role
DevSecOps Engineer at NCS, Video Intelligence
Focus
Identity, secrets, and network access as code
Platform
Kubernetes, Helm, and GitOps delivery
Delivery
Jenkins builds, ArgoCD syncs, GitOps throughout
Security
HashiCorp Vault, CyberArk, LDAP
Storage
Personal hybrid cloud — local cluster with AWS S3
AI
An MCP server serving my Anki decks
Experience
2+ years across DevOps and DevSecOps
01joe@localhost:~$ ask --interactive

ask.joe

A live terminal that answers questions about me. Type anything — experience, tooling, AI, whether I'm free for work.

ask-joe — /bin/chat — 80×24
joe.kb

Terminal's open. I'm a small knowledge base standing in for Joe — ask me about his work, the tech he runs, or how to reach him.

Heads up: this runs on a hand-written knowledge base, not a language model — so it's accurate but narrow. A real backend is coming; the transport is already swappable.

02joe@localhost:~$ cat ~/work.log

work.log

2+ years of engineering experience — two full-time roles plus a part-time stint during my degree — moving from building applications to securing and running the systems that carry them.

DevSecOps Engineer

Nov 2025 — Present

NCSVideo Intelligence — identity, secrets, network access, and observability across the on-prem estate.

tools

  • Linux
  • Kubernetes
  • HashiCorp Vault
  • CyberArk
  • ELK Stack
  • Terraform
  • MariaDB

domains

  • Identity & Access
  • Secrets Management
  • LDAP
  • Windows Server
  • IPSec VPN
  • Networking
  • Monitoring & Observability
  • Infrastructure as Code
  • Databases
  1. DevSecOps for the Video Intelligence platform — identity, secrets, and network access as code rather than tickets
  2. Managed privileged access with CyberArk and centralised service credentials in HashiCorp Vault, removing long-lived secrets from configuration
  3. Ran LDAP-backed authentication and group authorisation across mixed Linux and Windows Server estates
  4. Configured IPSec VPN tunnels so field mobile devices could reach internal systems without exposing them publicly
  5. Built out MariaDB on a Galera cluster — synchronous multi-master replication so the database survives a node loss without failover downtime or manual promotion
  6. Ran monitoring and observability on the ELK stack — cluster and systemd service logs, MariaDB among them, aggregated into dashboards and alerts so failures surface before users report them
  7. Provisioned the platform's infrastructure with Terraform, so environments are described in code and rebuilt from it rather than reassembled by hand
  8. Worked on NGINE, HTX's enterprise AI infrastructure — L2 engineering across Day 1 build and Day 2 operations, as Database Engineer on schema design, tuning, and backup and recovery
03joe@localhost:~$ pacman -Qe | grep -f ~/.daily

toolbox

The tools I actually operate, not the ones I have heard of.

  • Kubernetes
  • ArgoCD
  • Terraform
  • Docker
  • Jenkins
  • Ansible
  • Prometheus
  • Grafana
  • Linux
  • GitLab
  • Python
  • AWS
  • React
  • Node.js
  • MySQL
  • Git
04joe@localhost:~$ ls -la ~/certs/

certs

Honest status: both are in progress. Listed here because I'd rather show the plan than pad the list.

  • ◌ in progressExam booked — 13 Aug 2026

    Certified Kubernetes Administrator

    Cloud Native Computing Foundation

    Sitting the exam on 13 August 2026

    • Kubernetes
    • Cluster Security
    • Troubleshooting
  • ◌ in progressExam booked — 5 Sep 2026

    AWS Certified Solutions Architect — Associate

    Amazon Web Services

    Sitting the exam on 5 September 2026

    • AWS Architecture
    • High Availability
    • Cost Optimisation
05joe@localhost:~$ mail -s "hello" joe

say hello

Infrastructure work, GitOps, or just comparing notes — the inbox is open.

GitHub
@joe44824
LinkedIn
in/zaw-wana
  • Quick to reply
  • Open to opportunities
  • Open to remote and Singapore-based roles