- Role
- DevSecOps Engineer at NCS, Video Intelligence
- Focus
- Identity, secrets, and network access as code
- Platform
- Kubernetes, Helm, and GitOps delivery
- Delivery
- Jenkins builds, ArgoCD syncs, GitOps throughout
- Security
- HashiCorp Vault, CyberArk, LDAP
- Storage
- Personal hybrid cloud — local cluster with AWS S3
- AI
- An MCP server serving my Anki decks
- Experience
- 2+ years across DevOps and DevSecOps
joe@localhost:~$ ask --interactiveask.joe
A live terminal that answers questions about me. Type anything — experience, tooling, AI, whether I'm free for work.
Terminal's open. I'm a small knowledge base standing in for Joe — ask me about his work, the tech he runs, or how to reach him.
Heads up: this runs on a hand-written knowledge base, not a language model — so it's accurate but narrow. A real backend is coming; the transport is already swappable.
joe@localhost:~$ cat ~/work.logwork.log
2+ years of engineering experience — two full-time roles plus a part-time stint during my degree — moving from building applications to securing and running the systems that carry them.
DevSecOps Engineer
Nov 2025 — PresentNCS — Video Intelligence — identity, secrets, network access, and observability across the on-prem estate.
tools
Linux
Kubernetes
HashiCorp Vault
CyberArk
ELK Stack
Terraform
MariaDB
domains
- Identity & Access
- Secrets Management
- LDAP
- Windows Server
- IPSec VPN
- Networking
- Monitoring & Observability
- Infrastructure as Code
- Databases
- DevSecOps for the Video Intelligence platform — identity, secrets, and network access as code rather than tickets
- Managed privileged access with CyberArk and centralised service credentials in HashiCorp Vault, removing long-lived secrets from configuration
- Ran LDAP-backed authentication and group authorisation across mixed Linux and Windows Server estates
- Configured IPSec VPN tunnels so field mobile devices could reach internal systems without exposing them publicly
- Built out MariaDB on a Galera cluster — synchronous multi-master replication so the database survives a node loss without failover downtime or manual promotion
- Ran monitoring and observability on the ELK stack — cluster and systemd service logs, MariaDB among them, aggregated into dashboards and alerts so failures surface before users report them
- Provisioned the platform's infrastructure with Terraform, so environments are described in code and rebuilt from it rather than reassembled by hand
- Worked on NGINE ↗, HTX's enterprise AI infrastructure — L2 engineering across Day 1 build and Day 2 operations, as Database Engineer on schema design, tuning, and backup and recovery
joe@localhost:~$ pacman -Qe | grep -f ~/.dailytoolbox
The tools I actually operate, not the ones I have heard of.
Kubernetes
ArgoCD
Terraform
Docker
Jenkins
Ansible
Prometheus
Grafana
Linux
GitLab
Python
AWS
React
Node.js
MySQL
Git
joe@localhost:~$ ls -la ~/certs/certs
Honest status: both are in progress. Listed here because I'd rather show the plan than pad the list.
- ◌ in progressExam booked — 13 Aug 2026
Certified Kubernetes Administrator
Cloud Native Computing Foundation
Sitting the exam on 13 August 2026
- Kubernetes
- Cluster Security
- Troubleshooting
- ◌ in progressExam booked — 5 Sep 2026
AWS Certified Solutions Architect — Associate
Amazon Web Services
Sitting the exam on 5 September 2026
- AWS Architecture
- High Availability
- Cost Optimisation
joe@localhost:~$ mail -s "hello" joesay hello
Infrastructure work, GitOps, or just comparing notes — the inbox is open.
- GitHub
- @joe44824
- in/zaw-wana
- [email protected]
- Quick to reply
- Open to opportunities
- Open to remote and Singapore-based roles