
Thanh, Nguyen Ky
Senior DevSecOps Engineer
Professional Summary
With extensive experience in system and infrastructure engineering, I have developed a strong focus on cybersecurity, risk mitigation, and secure system design. My expertise lies in building and managing resilient architectures, implementing security best practices, and ensuring compliance with industry standards such as ISO 27001. I excel at integrating security into DevSecOps workflows, enabling real-time monitoring, threat detection, and incident response. As a trusted technical advisor, I am committed to delivering secure, scalable, and high-performance systems.
Employment History
Nov 2024 — Present
As a Senior DevOps Engineer at Fundiin, taking on key responsibilities in system operations and infrastructure development, with a strong focus on security, reliability, and continuous readiness.
- Infrastructure Management: Managed and maintained infrastructure on Google Cloud Platform (GCP) using Terraform (IaC) and ArgoCD for GitOps-based continuous delivery. Operated and secured production systems, ensuring high availability, scalability, and reliability. Optimized cloud cost by over 20% through service audits and decommissioning of non-essential components such as VLB, Filestore, and excessive log monitoring.
- Security & Integration: Integrated systems with banking partners to support critical financial transactions, ensuring secure and stable connectivity across environments. Collaborated across departments to support and successfully achieve ISO 27001:2022 certification.
- Team Leadership: Led a small IT team consisting of one infrastructure/network engineer and one operations support staff. Oversaw internal infrastructure and end-user support, as well as production support for the platform. Designed and implemented clear workflows and SLAs for handling unexpected system issues — filling a critical gap that previously lacked defined processes.
2020 — 2024
Formerly employed as an Engineer at VNG Corporation, where I was responsible for ensuring the reliability and performance of the company's infrastructure and applications.
- Infrastructure Management: Designed and managed scalable infrastructure on AWS, Azure, GCP and VNGCLOUD across hybrid cloud and on-premise setups. Deployed EKS with Rancher for multi-cluster Kubernetes management, using AWS Secret Manager and S3 for secure data handling. Automated server provisioning and configuration with Ansible and Python, optimizing deployment times. Built and maintained Kubernetes clusters, achieving high performance and reliability across diverse workloads.
- GitOps Pipeline and Automation Tools: Built a secure and stable pipeline using GitLab, Runner, SonarQube, Harbor, and ArgoCD, streamlining the product release process in a Kubernetes environment, leading to increased efficiency.
- AI Infrastructure and Performance Optimization: Applied high-performance GPU systems for AI workloads such as OCR, handling millions of requests daily with GPU utilization consistently above 80%, positioning the company as a leader in AI, with applications used both domestically and internationally in the banking sector.
- Proactive Monitoring and Incident Response: Monitored and swiftly responded to incidents, conducting root cause analysis to prevent future issues. Utilized tools like Splunk, Grafana, Prometheus, Loki, and Uptime to ensure system availability, and tracked progress through Jira for effective incident management.
- Capacity Planning and Scalability: Designed and executed capacity planning strategies aligned with the company’s budget and objectives. Consolidated infrastructure across multiple products within the department, achieving a 40% reduction in platform costs.
- Collaboration and Solution Design with Development Teams: Worked closely with product teams to ensure smooth go-live processes, providing critical solutions and system designs for high-load Kubernetes deployments, managing dozens of products with over 10,000 IoT devices and supporting more than 300,000 users. Implemented optimal authentication solutions such as SAML and OAuth for enhanced security.
- Security and Auditing: Conducted thorough reviews and maintained strict adherence to ISO 27001 and SOX standards. Implemented robust change management and incident management processes to achieve and sustain security certifications over multiple years.
2018 — 2019
Here, as a young and enthusiastic engineer, I have contributed to the success of numerous company projects.
- Researched and Deployed Business Solutions: Conducted comprehensive research on IT solutions like Symantec, ManageEngine, SOPHOS, VMware, Mail Server... providing consulting and deploying them for enterprise clients.
- Prepared Technical Documentation: Authored detailed technical reports and customized guidelines for tailoring solution features to meet specific client requirements.
- Infrastructure Planning & Supplier Coordination: Designed and developed extensive infrastructure plans, including Bill of Materials (BOM), working with suppliers to finalize optimal solutions for resolving client challenges.
- Penetration Testing and Early Issue Detection: Performed penetration testing, identified system vulnerabilities, and proactively addressed issues, ensuring early detection and prevention of potential security threats.
- Onsite Achievement: Monitored and operated critical data center infrastructure (Palo Alto Firewall, NetApp Storage, Printer Server, Exchange...) at PetroVietnam Domestic Exploration Production Operating Company Limited (PVEP-POC). Detected and mitigated system issues and cyberattacks, ensuring seamless operations and uninterrupted service for over 100 users.
Education
August 2014 — February 2019
At the University of Information Technology in Ho Chi Minh City, I pursued a Bachelor of Science in Cybersecurity with a focus on Network and Information Security.
Relevant Coursework:
- Cyberattacks and Defenses
- Cryptography
- Risk Management
- Web Architecture
- Access Control and Intrusion Detection Technology
- System Architecture Security
- Wireless and Mobile Networks Security
- Risk and Security Management in Enterprise
- Digital Forensics
- Intrusion Detection and Prevention Systems
- Malware Analysis Techniques