Where Security Meets Scale — DevOps for Mission-Critical Systems
I have industry experience of over 10+ years and focus on DevOps for the past 5+ years in areas such as cloud-native operations, DevOps, and infrastructure automation. I have successfully migrated sophisticated monolithic legacy systems to modern Kubernetes microservice architectures and have operated over 120 microservices in production for critical sectors including fintech, telecom, FMCG, and government.
I played a key role in designing, deploying, and operationalizing large-scale fintech platforms including TeleCash, LenDen, MyCash, and UPAY, ensuring high availability, regulatory compliance, and operational resilience in mission-critical financial systems.
I implement comprehensive DevSecOps pipelines with SAST, DAST, image scanning, cosign image verification, RBAC, image signing, TLS-secured connections, and encrypted secrets stored in Vault and Kubernetes Secrets. I enforce compliance with CIS Benchmarks, OWASP, and PCI DSS standards, performing OS layer to application layer hardening.
In addition, I utilize the ELK stack, Prometheus, Grafana, and Fluent Bit to deploy observability stacks with real-time proactive alerting for automated rapid response. I go beyond implementation to participate in infrastructure design, tender documentation drafting, and strategic interdepartmental collaboration to integrate security and reliability with overarching business objectives.
I am interested in a position of IT Infrastructure & Cloud Chartered Engineer to spearhead infrastructure operations that are secure, compliant, and strategically built to curb enterprise scaling and bolster resilience — building a proactive, effective organization that enhances the customer and user experience.
Experience
Lead DevOps Engineer
Red Dot Digital IT Ltd. · Dhaka, Bangladesh
August 2024 – Present
Current roleOverseeing and refining Kubernetes-based infrastructures to maintain system reliability, scalability, and performance. Leading legacy-to-Kubernetes migrations with stringent security standards and deploying enterprise-grade observability and DevSecOps pipelines for mission-critical fintech and telecom platforms.
- ▸Oversee and refine Kubernetes-based infrastructures to maintain system reliability, scalability, and performance
- ▸Improved a legacy project's operational efficiency and maintainability by migrating it to Kubernetes
- ▸Deploy and manage core cluster services requiring high availability, stringent security, and smooth operations
- ▸Led the design and integration of enterprise logging and monitoring systems with Fluent Bit, ELK Stack, Prometheus, Grafana, cAdvisor, and Node Exporter
- ▸Pre-deployment vulnerability assessment of container images using Trivy and code scanning with SonarQube
- ▸Verification of container image integrity and authenticity with image signing using cosign
- ▸Integrating SAST and DAST into CI/CD pipelines for proactive vulnerability assessment
- ▸Network security with proper Kubernetes network policies, RBAC, and namespace isolation
- ▸Kubernetes Secrets, Vault, and other external secret stores for secure secrets management
- ▸TLS encryption for both internal and external communications
- ▸Adopted CIS Benchmarks, OWASP, and PCI DSS for secure and compliant operations
- ▸Assist in infrastructure planning and drafting of tender documentation for future projects
- ▸Key Projects: Deployment and management of core MFS services TeleCash, LenDen, MyCash in Kubernetes cluster; Calling and messaging app for Joint Command Center - Bangladesh Police; IoT Project revamp and migration to Kubernetes; Support for Robi and other external projects
DevOps Engineer
UPAY (UCB Fintech Company Ltd.) · Dhaka, Bangladesh
August 2023 – August 2024
Oversaw sophisticated Kubernetes cluster ecosystems and managed enterprise CI/CD pipelines with image and code security scanning. Configured full-stack observability, enforced fintech-grade PCI DSS compliance, and managed PostgreSQL databases and RookCeph clustered storage for UPAY's large-scale MFS platform.
- ▸Managed enterprise CI/CD pipelines with image security scanning via Trivy and code scanning via SonarQube
- ▸Configured ELK Stack alongside Prometheus, Grafana, Fluent Bit, cAdvisor, and node-exporter for proactive monitoring and logging
- ▸Enabled real-time alerting automation through Slack alerting integrations on Grafana and Kibana with custom scripts
- ▸Managed PostgreSQL databases in PGO (Crunchy Postgres Operator) and oversaw Erasure Coding on RookCeph storage
- ▸Maintained protective boundary deployment, RBAC, and sensitive data encryption for fintech-grade security
- ▸Enforced local regulations and PCI DSS compliance across the platform
- ▸Provided SAST and DAST on running applications and source code, integrating security checks into CI/CD pipelines
- ▸Key Projects: Migrated full system from old Kubernetes version to new Kubernetes with full setup including Crunchy Postgres cluster and RookCeph cluster; Deployment and management of core MFS service in Kubernetes cluster with over 120 microservices
DevOps Engineer
Penta Global Ltd. · Dhaka, Bangladesh
March 2021 – July 2023
Managed application availability, audit logs, security, and build-deployment pipelines. Participated in system design, improved application performance component by component, and ensured high availability. Contributed to nationally critical platforms including the National Data Integration Platform and BEZA's One-Stop Service Center.
- ▸Managed application availability, audit logs, security, and build-deployment pipelines
- ▸Shared application-related errors with developers and improved services continuously
- ▸Improved application performance by optimizing component by component to ensure high availability
- ▸Participated in system design meetings to determine best architecture for new services
- ▸Key Project - Data Integration Platform: Supports law enforcement by consolidating disparate data repositories into a unified case data system using deep learning models. Includes API and socket communication, Redis, real-time data processing with Elasticsearch, Krakend API Gateway, and Kubernetes-based deployment with ELK and Grafana
- ▸Key Project - One-Stop Service Center for BEZA: Assists foreign and local investors in the application process and manages permit issuance and export activities for economic zones in Bangladesh. Deployed on Kubernetes with Redis, Elasticsearch, Postgres, and socket. Includes Mayan for document management and integration with multiple government agencies via API
Software Engineer
Penta Global Ltd. · Dhaka, Bangladesh
March 2019 – March 2021
Core R&D team member responsible for organizing meetings, conducting requirement analysis, and overseeing development and delivery timelines. Enforced secure design, development, and deployment practices throughout the project lifecycle.
- ▸Core R&D team member organizing meetings, conducting requirement analysis, and overseeing delivery timelines
- ▸Aligned business process automation planning and solution integration with organizational objectives
- ▸Managed resource setup, environment setup, and auditing
- ▸Enforced secure design, development, and deployment practices throughout the project lifecycle
- ▸Key Project - Election Management System for the Bangladesh Election Commission: Handled the full election cycle from nomination submission to result declaration using PHP (Lumen) in a microservice architecture
- ▸Key Project - Utility Billing System for a German company: Managed water, wastewater, and electricity billing with payment gateway integration, built with Node.js (Express) and MongoDB
- ▸Key Project - HR and File Management System: Enabled file search by name/category, location tracking, and QR code-based file access
Assistant Manager, Software Division
Summit Communications · Dhaka, Bangladesh
August 2018 – March 2019
Core development team member and ERP receiving and implementation team member. Arranged meetings and summarized requirements for stakeholders, coordinated team delivery, and adapted to corporate structures and culture.
- ▸Core member of the development team and ERP receiving and implementation team
- ▸Arranged meetings and summarized requirements for stakeholders
- ▸Developed with the team and ensured timely delivery
- ▸Key Project - Core billing application developed with ASP.NET and MS SQL Database
- ▸Key Project - Rent management application for sub-offices, POPs, and hubs built with Laravel and MySQL
Apprentice → Software Engineer
Business Accelerate Bd. Ltd. · Dhaka, Bangladesh
January 2015 – July 2018
Progressed from apprentice to software engineer across FMCG, Cement, Beverage, and Mobile sectors. Focused on business process automation, SLA-based workflows, and performance tracking systems. Led a small team integrating tech solutions with core business strategies.
- ▸Progressed from apprentice to software engineer across multiple industry verticals
- ▸Implemented SLA-based workflows and performance tracking systems
- ▸Contributed to system dependability through load balancing and code optimization
- ▸Led a small team and integrated tech solutions with core business strategies encompassing reporting, innovation, and cross-system integration
- ▸Key Project - Smart Sales: All-in-one sales management system covering order taking, delivery, sales force tracking, route planning, promotions, merchandising, and inventory. Implemented at Meghna Group, Abul Khayer Group, Arla Foods (Dano), Edison Group (Symphony), Transcom Beverage (Pepsi), Nestlé Bangladesh, and BEOL
- ▸Key Project - Fixed Asset Management System for City Bank Ltd.
- ▸Key Project - Annual Performance Agreement Management System up to Union Level for the Government of Bangladesh
- ▸Key Project - Weight Bridge Automation deployed in Meghna Group of Industries: reads weight data from device using C# and sends to a central database
Extraordinary Performance Benchmark
Key achievements and high-impact contributions across enterprise, fintech, and nationally critical systems.
Fintech Platform Operations
Played a key role deploying and managing mission-critical MFS platforms — UPAY, TeleCash, LenDen, and MyCash — ensuring high availability and operational resilience in production Kubernetes clusters.
Legacy-to-Kubernetes Migrations
Led full-stack migrations at Red Dot and UPAY from legacy systems to Kubernetes, including Crunchy Postgres clusters and RookCeph storage, improving scalability, reliability, and maintainability across 120+ microservices.
Full-Stack Observability
Deployed enterprise-grade observability stacks using ELK, Prometheus, Grafana, Fluent Bit, cAdvisor, and Node Exporter — enabling proactive system health monitoring and rapid incident response.
Security-First DevSecOps Pipelines
Built CI/CD pipelines enforcing CIS Benchmarks, OWASP, and PCI DSS compliance — integrating SAST, DAST, image scanning (Trivy), image signing (cosign), TLS encryption, and strict Kubernetes network policies.
Supply Chain & Image Integrity
Enforced container image signing with cosign and image scanning with Trivy to uphold integrity and mitigate supply chain risks across all deployment pipelines.
OS & Infrastructure Hardening
Managed hardware and OS security through kernel hardening, patch management, SSH hardening, and secure boot — reducing attack surfaces at the OS layer through to the application layer.
Cross-Functional Leadership
Facilitated cross-functional collaboration across engineering, security, and business teams through daily standups, infrastructure planning, and tender documentation drafting aligned with strategic objectives.
Nationally Critical Platforms
Contributed to the National Data Integration Platform supporting law enforcement and BEZA's One-Stop Service Center for economic zone investors — advancing national security and economic development in Bangladesh.
Technical expertise
Container & Orchestration
Container lifecycle management and orchestration at scale
CI/CD Pipelines
Automated build, test, and deployment workflows
Infrastructure as Code
Declarative infrastructure provisioning and management
Cloud Platforms
Multi-cloud architecture and services
Observability & Monitoring
End-to-end system visibility and alerting
Networking & API Gateway
Reverse proxies, ingress controllers, and service mesh
Databases
Relational, NoSQL, and clustered database management
Storage & Messaging
Clustered storage, event streaming, and distributed coordination
Security & Compliance
DevSecOps pipelines, vulnerability assessment, and regulatory compliance
Systems & Scripting
Linux administration, automation scripting, and virtualization
Application Development
Backend development across monolithic and microservice architectures
Credentials & Certifications
Industry-recognized certifications validating cloud and DevOps expertise.
The Linux Foundation
Certified Kubernetes Administrator (CKA)
Credential ID: LF-u2i1yoyayp
Red Hat
Red Hat Certified System Administrator (RHCSA)
Credential ID: 210-132-692
Institute of Business Administration, University of Dhaka (IBA DU)