03case study
Internal IT Zero-Trust & Release Automation (NirJai)
March 2025 - PresentWebsite

26security-audit findings resolved
73%release cycle cut (45 to 12 min)
37endpoints and servers hardened
Overview
Resolved 26 security-audit findings across 37 endpoints and servers by architecting a default-deny WireGuard VPN, deploying Wazuh SIEM, and automating UFW and Bash rules with Ansible for SSH GeoIP anomaly blocking. Cut release cycles 73% (45 to 12 minutes) across 6+ production apps by standardizing Jenkins and GitHub Actions pipelines with SonarQube quality gates, tuning Linux kernels via sysctl, and engineering Restic encrypted backups.
Stack map
The declared stack, sorted into the layers these tools belong to. It assembles as you scroll.
Deliverybuild & release04
AnsibleJenkinsGitHub ActionsSonarQube
Edgeingress & network02
WireGuardUFW
Datastate & storage01
Restic
Securityposture01
Wazuh SIEM
Platformcloud02
BashLinux