I will audit kubernetes and openshift clusters for security vulnerabilities
About this Gig
I audit Kubernetes and OpenShift clusters for security vulnerabilities and compliance gaps following CIS Benchmark, NSA/CISA Hardening Guidelines, and NIST 800-190 standards.
My Background:
- 5+ years DevOps engineering in production telecommunications environments
- Certified Kubernetes Administrator (CKA)
- Hands-on experience with Kubernetes, OpenShift, observability stacks (Prometheus, Grafana, Loki)
- Ethical hacking and bug bounty background
What I Audit:
RBAC & privilege escalation risks
Secrets management & etcd encryption
Pod security standards & privileged containers
Image vulnerabilities & supply chain security
Network policies & segmentation
Admission controllers & policy enforcement
Audit logging & incident response readiness
Runtime security & container hardening
Authentication & identity management
Node security & kubelet hardening
Deliverables:
- Comprehensive security scorecard across 10 domains
- Prioritized findings (Critical/High/Medium severity)
- Actionable remediation steps with YAML examples
- Compliance mapping (SOC2, ISO27001, PCI-DSS)
Industries: Telecommunications, Finance, Healthcare, SaaS
Tools:
Docker
•
Hashicorp Vault
•
Kubernetes
•
OpenShift
Frameworks:
Terraform
•
Ansible
Cloud Provider:
VMware Cloud
Programming language:
Bash
Expertise:
Installation
•
Debugging
•
Configuration
