Thanh, Nguyen Ky

Thanh, Nguyen Ky

Senior DevSecOps Engineer

nguyenkythanh71@gmail.com(+84) 966 421 096

Tan Phu Ward, District 7, Ho Chi Minh City

Professional Summary

With extensive experience in system and infrastructure engineering, I have developed a strong focus on cybersecurity, risk mitigation, and secure system design. My expertise lies in building and managing resilient architectures, implementing security best practices, and ensuring compliance with industry standards such as ISO 27001. I excel at integrating security into DevSecOps workflows, enabling real-time monitoring, threat detection, and incident response. As a trusted technical advisor, I am committed to delivering secure, scalable, and high-performance systems.

Employment History

Senior DevOps Engineer

Nov 2024 — Present

Fundiin Corporation

As a Senior DevOps Engineer at Fundiin, taking on key responsibilities in system operations and infrastructure development, with a strong focus on security, reliability, and continuous readiness.

  • Infrastructure Management: Managed and maintained infrastructure on Google Cloud Platform (GCP) using Terraform (IaC) and ArgoCD for GitOps-based continuous delivery. Operated and secured production systems, ensuring high availability, scalability, and reliability. Optimized cloud cost by over 20% through service audits and decommissioning of non-essential components such as VLB, Filestore, and excessive log monitoring.
  • Security & Integration: Integrated systems with banking partners to support critical financial transactions, ensuring secure and stable connectivity across environments. Collaborated across departments to support and successfully achieve ISO 27001:2022 certification.
  • Team Leadership: Led a small IT team consisting of one infrastructure/network engineer and one operations support staff. Oversaw internal infrastructure and end-user support, as well as production support for the platform. Designed and implemented clear workflows and SLAs for handling unexpected system issues — filling a critical gap that previously lacked defined processes.
Site Reliability Engineering (SRE)

2020 — 2024

VNG Corporation

Formerly employed as an Engineer at VNG Corporation, where I was responsible for ensuring the reliability and performance of the company's infrastructure and applications.

  • Infrastructure Management: Designed and managed scalable infrastructure on AWS, Azure, GCP and VNGCLOUD across hybrid cloud and on-premise setups. Deployed EKS with Rancher for multi-cluster Kubernetes management, using AWS Secret Manager and S3 for secure data handling. Automated server provisioning and configuration with Ansible and Python, optimizing deployment times. Built and maintained Kubernetes clusters, achieving high performance and reliability across diverse workloads.
  • GitOps Pipeline and Automation Tools: Built a secure and stable pipeline using GitLab, Runner, SonarQube, Harbor, and ArgoCD, streamlining the product release process in a Kubernetes environment, leading to increased efficiency.
  • AI Infrastructure and Performance Optimization: Applied high-performance GPU systems for AI workloads such as OCR, handling millions of requests daily with GPU utilization consistently above 80%, positioning the company as a leader in AI, with applications used both domestically and internationally in the banking sector.
  • Proactive Monitoring and Incident Response: Monitored and swiftly responded to incidents, conducting root cause analysis to prevent future issues. Utilized tools like Splunk, Grafana, Prometheus, Loki, and Uptime to ensure system availability, and tracked progress through Jira for effective incident management.
  • Capacity Planning and Scalability: Designed and executed capacity planning strategies aligned with the company’s budget and objectives. Consolidated infrastructure across multiple products within the department, achieving a 40% reduction in platform costs.
  • Collaboration and Solution Design with Development Teams: Worked closely with product teams to ensure smooth go-live processes, providing critical solutions and system designs for high-load Kubernetes deployments, managing dozens of products with over 10,000 IoT devices and supporting more than 300,000 users. Implemented optimal authentication solutions such as SAML and OAuth for enhanced security.
  • Security and Auditing: Conducted thorough reviews and maintained strict adherence to ISO 27001 and SOX standards. Implemented robust change management and incident management processes to achieve and sustain security certifications over multiple years.
System Engineer

2018 — 2019

Sao Bac Dau Technologies Group

Here, as a young and enthusiastic engineer, I have contributed to the success of numerous company projects.

  • Researched and Deployed Business Solutions: Conducted comprehensive research on IT solutions like Symantec, ManageEngine, SOPHOS, VMware, Mail Server... providing consulting and deploying them for enterprise clients.
  • Prepared Technical Documentation: Authored detailed technical reports and customized guidelines for tailoring solution features to meet specific client requirements.
  • Infrastructure Planning & Supplier Coordination: Designed and developed extensive infrastructure plans, including Bill of Materials (BOM), working with suppliers to finalize optimal solutions for resolving client challenges.
  • Penetration Testing and Early Issue Detection: Performed penetration testing, identified system vulnerabilities, and proactively addressed issues, ensuring early detection and prevention of potential security threats.
  • Onsite Achievement: Monitored and operated critical data center infrastructure (Palo Alto Firewall, NetApp Storage, Printer Server, Exchange...) at PetroVietnam Domestic Exploration Production Operating Company Limited (PVEP-POC). Detected and mitigated system issues and cyberattacks, ensuring seamless operations and uninterrupted service for over 100 users.

Education

BS in Cybersecurity (Network and Information Security)

August 2014 — February 2019

University of Information Technology, Ho Chi Minh

At the University of Information Technology in Ho Chi Minh City, I pursued a Bachelor of Science in Cybersecurity with a focus on Network and Information Security.

Relevant Coursework:

  • Cyberattacks and Defenses
  • Cryptography
  • Risk Management
  • Web Architecture
  • Access Control and Intrusion Detection Technology
  • System Architecture Security
  • Wireless and Mobile Networks Security
  • Risk and Security Management in Enterprise
  • Digital Forensics
  • Intrusion Detection and Prevention Systems
  • Malware Analysis Techniques

Skills

Technical Skills

Cloud Platforms: GCP, AWS, Azure, VNGCLOUD
IaC & GitOps: Terraform, ArgoCD
Containerization & Orchestration: Kubernetes (EKS, Rancher), Docker
CI/CD & DevOps Tools: GitLab, GitLab Runner, SonarQube, Harbor, Ansible
Monitoring & Logging: Splunk, Grafana, Prometheus, Loki, Uptime, Jira
Scripting & Automation: Python
Security Standards & Practices: ISO 27001:2022, SOX, SAML, OAuth, Penetration Testing, AWS Secret Manager, Symantec, SOPHOS, Palo Alto Firewall, Secure System Design, Risk Mitigation
AI & HPC: GPU systems for AI (OCR)
Infrastructure & Systems: Server Provisioning, Data Center Ops (NetApp, Exchange), VMware, Mail Server, ManageEngine, Cloud Cost Optimization
Networking: Network Security, Secure Connectivity
Other: IoT, Bill of Materials (BOM), IT Team Leadership, Workflow Design, SLA Implementation

Soft Skills & Methodologies

Research and Problem-Solving
Critical Thinking and Issue Identification
Innovation and Team Collaboration
System Reliability & Performance Optimization
Automation Strategy & Implementation
Security Protocol Enforcement & DevSecOps Integration
Resilient Architecture Design & Management
Real-time Monitoring & Incident Response
Continuous Improvement Culture
Scalable & High-Performance System Design
Capacity Planning & Cost Optimization
Technical Documentation & Reporting
Client Consultation & Solution Deployment
Change Management Processes
Threat Detection
Compliance Management