Varun Bhandari — Security Engineer
I write about: • DevSecOps fundamentals • Cloud security (AWS, GCP) • CI/CD at scale • Kubernetes (EKS, GKE) • Platform engineering • Python automation • SRE practices and observability • Secure SDLC and policy-as-code **** DevSecOps Engineer || Cloud Security || CI/CD & Kubernetes || AWS | GCP || Python Automation. **** Bio: Experienced DevSecOps and Cloud Security engineer with 9+ years building secure, reliable delivery platforms across AWS and GCP, with deep hands-on experience in EKS/GKE, GitHub Actions, ADO Pipelines, Jenkins, and GitLab CI. Focus areas include defence-in-depth for pipelines, least‑privilege IAM, Kubernetes hardening, IaC-driven consistency, and progressive delivery for safer, faster releases. Writes and speaks about practical platform patterns, scaling DevSecOps in real teams, and balancing velocity with compliance. Actively maintains a technical blog on Kubernetes, CI/CD, and cloud security, sharing repeatable playbooks and reference architectures. Highlights: • Built resilient multi-stage CI/CD with automated testing, policy gates, and rollout strategies to cut lead time for changes while improving change failure rate. • Operated high-availability EKS/GKE clusters with cluster hardening, workload isolation, and standardised release workflows using Helm and GitOps. • Embedded security in delivery via policy-as-code, SAST/DAST where appropriate, SBOMs, signing/verification, and secrets hygiene integrated from commit to deploy. • Reduced operational risk with strong security baselines, HTTPS/HSTS, and edge protections; aligned controls to least privilege and continuous posture improvement. • Automated with Python to remove toil, enforce guardrails, and uplift developer experience; built internal tools that standardise environments and reduce drift. • Invested in observability (metrics, logs, traces) to tighten feedback loops, improve MTTR, and guide pragmatic automation based on data. What to expect here: • Practical guides on CI/CD patterns, secure supply chain, and platform engineering • Kubernetes production tips (multi-env strategy, tenancy, cost and reliability trade-offs). • Cloud security primers for AWS/GCP with actionable guardrails. • Python tooling for ops automation and compliance. • Career notes for DevSecOps/SRE roles: interviews and upskilling roadmaps. If you’re scaling delivery, hardening cloud workloads, or building a developer platform that teams love, let’s connect and collaborate. ** Opinions expressed are personal and don’t reflect my employer’s positions. **
Stackforce AI infers this person is a DevSecOps and Cloud Security expert in the Fintech industry.
Location: Pune, Maharashtra, India
Experience: 8 yrs 9 mos
Skills
- Devsecops
- Cloud Security
- Devops
- Cloud Migration
- Ci/cd
Career Highlights
- Built resilient multi-stage CI/CD pipelines.
- Operated high-availability EKS/GKE clusters.
- Automated processes using Python to enhance developer experience.
Work Experience
Crypto.com
Senior Security Engineer (9 mos)
letsbloom
Head of DevSecOps (6 mos)
DevSecOps Lead (2 yrs 4 mos)
CloudCover
DevOps Technical Lead (1 yr 7 mos)
Senior DevOps Engineer (1 yr 2 mos)
DevOps Engineer (11 mos)
Reflex Software Solutions Ltd
DevOps Engineer (1 yr 6 mos)
DevOps Engineer (5 mos)
Education
Master of Computer Applications (MCA) at Bharati Vidyapeeth's Institute of Computer Applications and Management
Bachelor Of Computer Application at Amrapali Institute