I build secure, audit-ready software delivery platforms in air-gapped, sovereign environments. With ~21 years across finance, defence and regulated industries, I turn scattered tools into a platform-as-a-product: GitOps (Argo CD + Kustomize), service mesh (Istio), supply-chain security (SBOM, Nexus IQ, Trivy, OPA Conftest), and full observability (Prometheus, Grafana, Loki, Jaeger). The goal: make the secure path the easy path.
What I’m known for
• Standing up compliant pipelines that developers actually want to use.
• Moving teams from ticket-driven releases to paved roads/golden paths with guardrails.
• Making audits boring: policy-as-code, provenance/SBOM, and traceable change.
Core strengths
• GitOps at scale: Argo CD + Kustomize across multi-env deployments; artifact promotion and end-to-end traceability.
• Service mesh: Istio for zero-trust comms, traffic policy, and mTLS; Kiali/Jaeger for troubleshooting.
• Supply-chain security: SBOM generation & enforcement; Nexus IQ/Trivy gating; OPA Conftest policies.
• Observability: Prometheus/Grafana/Loki with actionable SLOs and runbooks in disconnected networks.
• Platform as a product: roadmaps, SLAs, and onboarding that accelerate delivery without compromising assurance.
DevSecOps: SAST & DAST: Kubesec, Kube-bench, Falco, AppArmor, Tracee, CIS Benchmarks, SonarQube, Trivy, OPA Conftest & Gatekeeper, OWASP ZAP, Talisman, PIT
undefinedWorked for Centene which provides managed health care services in US. Was heavily involved in migration of EMBARK Application(s) from Centene's local datacentre to AWS, GCP and Azure. As part of this following tasks were completed:
Held various internal roles during this long tenure:
https://github.com/ashwinbittu
https://medium.com/@ashwin.bittu