Location: Nairobi, Kenya
Remote: Yes
Willing to relocate: Yes
I harden Kubernetes supply chains: Cosign keyless image signing, SLSA provenance, SBOM generation (SPDX/CycloneDX), and dual-layer admission enforcement (Kyverno + OPA Gatekeeper/Ratify), enforced through GitOps delivery with ArgoCD on AWS EKS. I also run production platform work with HashiCorp Vault (secrets injection, least-privilege policies) and Terraform/Terragrunt for infra-as-code.
Repos: - musaumakau/supply-chain-security -- signs, attests, and enforces: blocks unsigned images at Kubernetes admission time - musaumakau/infrastructure-live -- Terragrunt-based multi-environment AWS deployments with OIDC auth and verified CI/CD pipelines - musaumakau/kyverno-policy-pack -- tested Kyverno policies for image signing/attestation with a JMESPath test framework
Wrote up the full supply chain pipeline here: https://medium.com/@Juan_Makau/securing-the-software-supply-...
Résumé/CV: https://drive.google.com/file/d/1qd7pGaKwzHvlpWl4ntiWsfyRV4-... Email: makaujuan@gmail.com GitHub: https://github.com/musaumakau LinkedIn: https://www.linkedin.com/in/juan-musau