Halil İbrahim Dürmüş

DevSecOps Engineer

Halil İbrahim Dürmüş

I run production-scale Proxmox and Docker infrastructure, and I own the defence layers that reach from pre-commit to runtime along with the GitOps-based CI/CD pipelines that carry them. My focus is secure software delivery (SAST/SCA/SBOM, signed images), durable operations (SLOs, blameless postmortems, runbook hygiene) and an offensive mindset.

About

At Ayssoft I am the company’s only DevOps engineer: the entire delivery chain from commit to production is mine. I have provisioned and now operate more than 100 virtual machines across multiple Proxmox nodes, and over 90 container-based repositories are built and deployed with GitHub Actions.

I came to infrastructure from full-stack Java and React development, and that shapes how I work: I build hardening, secret management and observability that development teams adopt rather than route around.

I lead production incident response — Proxmox LVM thin-pool exhaustion, Redis AOF corruption, MySQL 8 physical restores, Kafka offset recovery, multi-tenant Docker stack failures. I am currently preparing for OSCP+ and CKS.

Languages
Turkish — native
English — CEFR B1–B2

Experience

  1. Malatya, Türkiye

    DevSecOps Engineer

    Ayssoft Bilgi Teknolojileri

    Sole DevOps engineer; owner of the delivery chain from commit through to production.

    • Provisioned and operated 100+ virtual machines across multiple Proxmox VE nodes: Docker workloads, HAProxy and Nginx reverse proxies, database services.
    • GitHub Actions CI/CD for 90+ container-based repositories; removed duplicated pipeline code with reusable workflows and BuildKit layer caching.
    • Embedded security controls in the pipeline: SAST and software composition analysis, container image scanning with Trivy, centralised secret management with HashiCorp Vault, least-privileged registry and access tokens.
    • Led production incident response: Proxmox LVM thin-pool exhaustion, Redis AOF corruption, MySQL 8 physical restores, Kafka offset recovery, multi-tenant Docker stack failures.
    • Designed the technical hiring process for DevOps candidates: hands-on test cases and review checkpoints built on the company’s actual in-house stack.
  2. Malatya, Türkiye

    Junior DevSecOps Engineer

    İnönü Üniversitesi · Dijital Dönüşüm Ofisi

    CI/CD and server operations for applications built in-house by the university.

    • Managed CI/CD processes for applications developed in-house by the university.
    • Configured Linux application servers, Nginx reverse proxy rules and TLS termination for internal and public-facing services.
    • Carried out application deployment, systemd service management, user and permission management, and baseline server hardening.
    • Documented deployment and server configuration procedures so projects transfer cleanly between student development teams.
  3. Muğla, Türkiye

    Penetration Testing Intern

    ShiftSoft Software Technology

    The compulsory summer internship of the Software Engineering programme, in the company’s software security department.

    • Conducted penetration tests on the company’s own products: reconnaissance, authentication and authorisation testing, and common web vulnerability categories aligned with the OWASP Top 10.
    • Reported findings to the development team with reproduction steps, impact assessments and remediation recommendations.
  4. Muğla, Türkiye

    Founder & Manager

    Unity Dev Group

    Ran both delivery and business operations at a software development company I founded.

    • Customer acquisition, project scoping, pricing and delivery commitments.
    • Led the development team across task allocation, code reviews and release planning; mentored junior developers on version control and deployment practices.
    • Delivered custom web and application projects end to end, from requirements analysis through deployment.
  5. Muğla, Türkiye

    Software Engineer

    Rextabi Creative

    Full-stack development with Java (Spring Boot, JPA) on the back end and React on the front end.

    • Designed relational database schemas and REST APIs.
    • Managed features through every stage from requirements analysis to production release.

Projects

All public. Star counts and last-updated dates are pulled from GitHub when the page loads; if that fails, the last known values are shown.

Other projects

  • file-crypter(opens in a new tab)

    updated

    File and folder encryption with AES-256-CBC + PBKDF2 — a single command from the terminal, Turkish CLI.

    • Python
    • AES-256
    • PBKDF2
  • ai-dev-swarm(opens in a new tab)

    1starsupdated

    A local autonomous multi-agent development system: it ideates, plans, builds and ships projects to GitHub on its own.

    • Python
    • Multi-agent
  • A CI service that reverse-engineers de-facto API contracts by statically analysing client repositories and replaying recorded traffic, then runs evolution rules (additive vs. breaking) on every schema diff.

    • Python
    • Static analysis
    • CI
  • kurulum(opens in a new tab)

    updated

    A from-scratch walkthrough of a single-node (all-in-one) Kubernetes installation on Ubuntu 22.04.

    • Kubernetes
    • Ubuntu
    • Documentation

All repositories on GitHub → (opens in a new tab)

Skills

The tooling I use in production, grouped by area.

Languages

  • Python
  • Go
  • TypeScript
  • Bash
  • Java

Infrastructure & Platform

  • Docker
  • Kubernetes
  • Proxmox VE
  • Terraform
  • Ansible
  • Nginx
  • HAProxy
  • Linux
  • AWS

Security

  • Trivy
  • Semgrep
  • Falco
  • Cosign
  • SBOM / CycloneDX
  • HashiCorp Vault
  • kube-bench
  • OWASP Top 10
  • Threat modeling
  • Secure SDLC
  • SAST / DAST / SCA

Observability

  • Prometheus
  • Grafana
  • OpenTelemetry
  • ELK
  • Sentry

CI/CD

  • GitHub Actions
  • GitLab CI
  • Jenkins
  • Argo CD
  • GitOps

Data

  • PostgreSQL
  • MariaDB
  • MongoDB
  • Redis

Engineering principles

The short list I fall back on when making a call.

  • Self-host first, decide later

    Running a service on your own infrastructure is the shortest path to actually understanding it. Only then do you know what you depend on when it breaks.

  • Write the tool you need

    Where the off-the-shelf answer stops is where the real work starts. If you are solving a problem by hand for the second time, it is a tool.

  • Defence that does not know the attacker stays on paper

    You only learn whether a control works by trying it like an attacker. A penetration test is the verification of the checklist.

  • Every incident earns a write-up

    Blameless postmortem, updated runbook, repeatable fix. An incident that is never written down happens a second time.

  • Pragmatism > purity

    A perfect pipeline the team avoids is worse than a good one it uses. Adoption is a security property.

Education & Volunteering

Education

  1. MSc — Software Engineering

    İnönü ÜniversitesiThesis track

  2. BSc — Software Engineering

    İnönü Üniversitesi

Certifications

  • OSCP+OffSec Certified Professionalin preparation
  • CKSCertified Kubernetes Security Specialistin preparation

Volunteering

İnönü University Cyber Security Society

  1. Member

  2. Board Member

  3. President

  4. Remote support

As president I planned the community’s annual activity programme, coordinated the board, represented the community within the university, and ran hands-on technical workshops introducing students to security fundamentals. I handed the role over in September 2026 and continue to support the community remotely.

Contact

I am working towards a security architecture role in an international engineering team. You can reach me through the channels below.

Email
s.ibrahimdrms@gmail.com
GitHub
github.com/halilibrahimd27(opens in a new tab)
LinkedIn
linkedin.com/in/halil-ibrahim-durmus(opens in a new tab)
CV (PDF)
Download CV