DevSecOps & Platform Engineer | Cloud Security

Jason Achkar Diab

CompTIA Security+ · AZ-900 · SC-500 (In Progress) · MSc Cybersecurity — Georgia Tech

Platform and DevSecOps engineer with a software engineering foundation and production experience building secure CI/CD pipelines, infrastructure-as-code, and multi-tenant cloud systems on Microsoft Azure. Solo-built and deployed SecureObs, a security SaaS unifying seven scanners with cross-tool deduplication, CI/CD build gating, and credential-free IaC attack-path analysis.

Current Focus

Azure DevOps & GitHub platform administration and access governance (Genetec)
Secure CI/CD with build gates: SAST, DAST, secrets scanning, IaC scanning
Infrastructure-as-Code security: Terraform, Checkov, HCL static analysis
SecureObs: production multi-tenant security SaaS (secureobs.com)
security.profile
Active
0
Certifications

Security+, AZ-900, Google Cybersecurity, SC-500 in progress

0+yrs
Experience

Platform engineering, DevSecOps, full-stack secure development

0+
MITRE Techniques

Covered across detection rules, tooling, and cloud controls

Security Toolkit
AzureSentinelEntra IDDefenderOWASPKQLTerraformGitHub

Open to Opportunities

Cloud Security Engineer, Security Consultant, DevSecOps roles in Canada or remote

Initializing threat feed…
About Me

About Me

Platform & DevSecOps engineer building secure systems from the ground up.

I'm a platform and DevSecOps engineer at Genetec, where I administer and secure the R&D engineering platform (Azure DevOps Server/Services and GitHub), enforce access governance, and build internal tooling in C#, Go, and PowerShell to automate configuration and compliance across shared developer systems.

I hold a Bachelor of Computer Science from Concordia University (2025), am pursuing an MSc in Cybersecurity (Information Security) at Georgia Tech (2026–2028), and hold CompTIA Security+, AZ-900, and Google Cybersecurity certifications, with SC-500 in progress. I approach problems from both a builder and defender perspective.

Outside of my day job, I solo-built SecureObs — a production-deployed, multi-tenant security SaaS at secureobs.com — that unifies seven open-source scanners with an IaC attack-path engine, cross-tool deduplication, SARIF export, and CI/CD build gating. My goal is to work in security engineering, cloud security architecture, or DevSecOps roles where I can help teams build secure systems at scale.

Focus Areas

Platform Engineering & Developer Security (Azure DevOps, GitHub)
Secure CI/CD Pipeline Design & Build Gates
Infrastructure-as-Code Security (Terraform, Checkov)
Cloud Security Architecture (Azure, defense-in-depth)
Application Security (SAST, DAST, RBAC/IAM, OWASP)
Detection Engineering & Security Automation

Core Strengths

Platform Security

Securing developer platforms, pipeline policies, and access governance at scale

Secure CI/CD

Build gates with SAST, DAST, secrets scanning, SCA, and IaC validation

Cloud Architecture

Azure defense-in-depth: Key Vault, Managed Identities, private networking, RBAC

Security Engineering

Threat modeling, secure SDLC, OWASP/CWE mitigations, least privilege

IaC Automation

Terraform, HCL static analysis, ephemeral sandboxed runners, config governance

SaaS Product Development

Solo-built production multi-tenant security SaaS with defense-in-depth architecture

Security Domain Coverage

Career Journey

Professional Experience

Secure software development with a focus on building resilient systems and integrating security throughout the SDLC

Platform Engineer — Software Configuration Management & Tools (Engineering Efficiency)

Genetec Inc.

Montreal, QC (Hybrid)May 2026 – Presentfull-time

Key Achievements

  • Administer and secure the R&D ALM platform (Azure DevOps Server/Services and GitHub) for engineering teams, enforcing secure configurations, branch/pipeline policies, and access governance
  • Build and maintain internal tooling and libraries in C#, Go, and PowerShell that automate configuration, governance, and reporting across shared developer applications
  • Design, configure, and maintain build and release pipelines with conditional gates and environment promotion logic; provision supporting infrastructure as code with Terraform on Azure
  • Develop data export and reporting tooling that surfaces configuration, compliance, and pipeline health across teams to support governance decisions

Security Highlights

  • Enforcing secure-by-default configurations and access governance across shared source-control and build systems
  • Standardizing pipeline policies and branch protections across the R&D platform
  • Provisioning least-privilege infrastructure-as-code on Azure

Technologies

Azure DevOpsGitHubC#.NETGoPowerShellTerraformAzure

Full-Stack Developer, DevSecOps

SES & Technologies Ltd.

Laval, QCJune 2025 – May 2026full-time

Key Achievements

  • Built and integrated a DevSecOps toolchain into Azure DevOps pipelines (Semgrep SAST, OWASP ZAP DAST, Gitleaks secrets scanning), containerized with Docker, with gates that block promotion on high-severity findings
  • Designed and implemented RBAC/IAM from scratch across enterprise applications: authentication flows, role/permission scoping, and access-group management via Angular + NgRx administration panel
  • Architected and delivered .NET backend services and REST APIs following Clean Architecture, DDD, CQRS, and Repository patterns, plus Angular frontends, across the full SDLC
  • Engineered pipeline-as-code (YAML) build, test, and release stages with conditional gates and environment promotion across multi-repository codebases

Security Highlights

  • Integrated SAST, DAST, and secrets scanning into production CI/CD pipelines with hard security gates
  • Designed RBAC/IAM architecture from zero for enterprise applications
  • Applied least-privilege and secure-by-design patterns throughout delivery

Technologies

Azure DevOpsSemgrepOWASP ZAPGitleaksDockerAngularNgRx.NETC#TypeScriptYAML

Software Developer Intern — AutoVu

Genetec Inc.

Montreal, QCDec 2023 – May 2024internship

Key Achievements

  • Delivered backend services in .NET and C# for the AutoVu platform, a system serving law-enforcement agencies handling sensitive data
  • Integrated REST and SignalR APIs for real-time communication in a microservices ecosystem
  • Wrote unit and integration tests to reduce regression risk ahead of releases in a security-critical environment

Security Highlights

  • Worked in a security-critical production environment handling law-enforcement sensitive data
  • Contributed to testing practices that reduce regression risk in a sensitive-data context

Technologies

.NETC#REST APIsSignalRMicroservices

Applications Engineer Intern

Matrox Graphics Inc.

Dorval, QCMay 2023 – Sep 2023internship

Key Achievements

  • Built diagnostic automation tooling in Python and C# to surface misconfigurations, insecure defaults, and overly permissive access settings in customer deployments — improving time-to-resolution by 55–65% for enterprise support cases
  • Performed configuration audits and log analysis to identify root causes and security gaps
  • Authored hardening recommendations and standardized triage documentation across support teams

Security Highlights

  • Built tooling specifically targeting misconfiguration detection, insecure defaults, and overly permissive access in enterprise deployments
  • Delivered hardening recommendations and standardized security documentation

Technologies

PythonC#Log AnalysisConfiguration Auditing
Featured Work

Featured Projects

Cybersecurity projects demonstrating security architecture, threat detection, and secure development practices

Featured ProjectDeployed · Private beta

SecureObsDevSecOps Security Observatory

A deployed, multi-tenant DevSecOps SaaS that unifies seven open-source security scanners into a centralized triage and enforcement platform. SecureObs provides normalized findings, cross-tool correlation, CI/CD build gates, pull-request feedback, and Terraform-based Azure attack-path analysis through a .NET 8 Clean Architecture backend, Angular 21 SPA, and PostgreSQL with defense-in-depth tenant isolation.

Visit SecureObs
7
Security scanners

SAST, SCA, secrets, container, IaC, Python, and JavaScript security analysis through one versioned scanner image.

240+
Backend tests

Unit, HTTP integration, and PostgreSQL Testcontainers coverage for authorization, RLS, ingestion, billing, deduplication, and build gates.

2
CI/CD platforms

Managed integrations for GitHub Actions and Azure DevOps, including repository discovery, generated pipeline changes, and first-run verification.

2
Tenant-isolation layers

Application-level authorization backed by PostgreSQL FORCE row-level security under a restricted runtime database role.

Multi-scanner aggregation and enforcement

Runs seven security scanners through one versioned container, normalizes heterogeneous outputs into a unified finding model, correlates repeated and cross-tool results, and enforces project-specific build-gate policies.

IaC attack-path analysis

Processes Terraform plan data inside customer-controlled CI, uploads only a sanitized topology model, and maps findings onto Azure resource relationships to surface infrastructure exposure and attack paths without receiving cloud credentials, state files, or raw plans.

Defense-in-depth multi-tenancy

Combines tenant-scoped application authorization with PostgreSQL FORCE row-level security, separate migration and runtime database roles, fail-closed tenant context, and real PostgreSQL isolation regression tests.

Managed CI/CD integrations

Connects GitHub and Azure DevOps repositories, discovers Terraform roots, generates reviewable pipeline changes, provisions project-scoped API keys into encrypted CI secret stores, and verifies the resulting integration.

Identity, secrets, and auditability

Uses Microsoft Entra ID with PKCE, hashed and revocable pipeline API keys, Azure Key Vault with Managed Identity, append-only administrative audit records, security headers, rate limiting, and Application Insights telemetry.

Self-verifying release pipeline

Builds, versions, signs, and publishes scanner images with SBOM and provenance attestations, updates deployed scanner configuration, scans SecureObs with its own release artifact, and validates ingestion and build-gate behavior through automated canaries.

Backend
.NET 8Clean ArchitectureEF Core 8PostgreSQL 16Row-Level Security
Frontend
Angular 21TypeScriptCytoscape
Cloud
Azure App ServiceAzure Static Web AppsPostgreSQL Flexible ServerKey VaultEntra ID
DevSecOps
GitHub ActionsAzure DevOpsTerraformDockerCosignPython

More projects and labs in development. Check my GitHub for the latest updates.

Credentials

Certifications & Education

Structured learning path combining industry certifications with formal academic study in cybersecurity

Certifications

Earned 2025

CompTIA Security+

CompTIA

Industry-standard certification covering core cybersecurity principles, threat analysis, risk management, and security controls across networks, applications, and cloud environments.

Key Skills

Threat Detection & ResponseSecurity OperationsGovernance & ComplianceNetwork Security+2 more
In progress

SC-500: Microsoft Cloud & AI Security Engineer

Microsoft

Advanced certification for implementing Microsoft cloud security controls, AI security, Microsoft Defender, and compliance solutions across Azure environments.

Key Skills

Microsoft Security CopilotAI SecurityCloud SecurityEntra ID+2 more
Earned 2025

Microsoft Azure Fundamentals (AZ-900)

Microsoft

Foundational certification demonstrating knowledge of cloud services, Azure architecture, security, privacy, compliance, and trust in Microsoft Azure.

Key Skills

Cloud ConceptsAzure ServicesSecurity & ComplianceIdentity & Governance+2 more
Earned 2025

Google Cybersecurity Professional Certificate

Google / Coursera

Comprehensive program covering security foundations, network security, Linux, Python automation, threat detection with SIEM tools, and incident response procedures.

Key Skills

SIEM ToolsPython for SecurityIncident ResponseLinux Administration+2 more

Education

In Progress

Master of Science in Cybersecurity, Information Security Specialization

Georgia Institute of Technology

Online2026 – 2028 (In Progress)

Highlights

  • Secure software development
  • Identity and access management
  • Network security and intrusion detection
  • Applied cryptography
  • Software vulnerability analysis

Bachelor of Computer Science

Concordia University

Montreal, QCGraduated April 2025

Highlights

  • Software architecture
  • Computer networks
  • Database systems
  • Secure software development
  • Operating systems
SOC Live

SIEM Detection Console

A quick look at the event stream and detections — the full console with the query builder, timeline, and MITRE-mapped detection rules lives on its own page.

SOC Detection Stream

Latest correlated security events

Live

Investigate the complete dataset

Query builder · timeline · MITRE rules · export

Open the full SOC console
Adversary Coverage

MITRE ATT&CK Coverage

Techniques covered across detection rules, tooling, and cloud controls — click any tile to see how it's covered and where it's implemented

12 of 33 mapped techniques covered36%
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command & Control
Detected & Mapped Not yet covered
Open Threat Intel

Recent CVE Intelligence

Live feed of recent Common Vulnerabilities and Exposures — I track this because attackers do.

cve-feed --last 10

Powered by CIRCL CVE · Scores are CVSS base scores · Links open the NVD entry

Get In Touch

Get In Touch

Interested in cloud security, cybersecurity consulting, or DevSecOps roles? Let's connect. Open to opportunities in Canada and remote positions.

Security Engineer

Cloud & application security architecture, threat modeling, secure code review, and security posture uplift for Azure-first teams.

DevSecOps Engineer

Embedding security into CI/CD pipelines, automating SAST/SCA/container scanning gates, and building shift-left security culture.

Cloud Security Consultant

Azure security posture review, landing zone hardening, Sentinel detection pack deployment, and Zero Trust IAM advisory.

Drop a line

Links

Prefer async? Reach out via email or socials. Resume is available to preview or download.

Email
email
LinkedIn
linkedin
GitHub
github
SecureObs
website