
Timeline
About me
Senior DevOps Engineer at VMO Group
Education

Foreign trade university
2017 - 2021Bachelor's degree international business economics very good
Experience

Fpt software
Sept 2018 - Feb 2019Machine learning supportTrained Artificial Intelligence with personalized data, enabling AI to identify identity cards, automatically retrieve information and enter data into archives.

Wesports
Mar 2019 - Jun 2020• Worked with Wordpress to create and maintain dynamic websites and web applications• Deployed Wordpress on Apache servers and used jQuery for front-end interactivity• Developed software solutions using PHP frameworks, SQL databases, and object-oriented programming• Managed multi-tenant web applications with security and scalability in mind• Used Git for version control and collaboration• Applied HTML5, CSS, JavaScript and other web technologies to design and implement user interfaces and front-end features Show less
PHP Web Developer
Apr 2019 - Jun 2020Sales Marketing Support
Mar 2019 - Dec 2019

Vnpt-media
Aug 2019 - Dec 2019General administrative assistant- Process invoice documents and finance report- Help company get tax information- Manage content posted on media channels

グローバル戦略室 - グラビティ株式会社 - global strategy office - gravity corporation
Dec 2020 - Feb 2021Intern of global strategy officeThis internship was approved by the METI Japan Internship program, organized by METI Government of Japan-Acquired knowledge about Blockchain, Web 3.0, Smart contract through internal training conferences-Learned deeply about Scrum and Agile software development methods. -Worked under the supervision of CTO-Contributed to the company's first product in the education sector
.webp)
Saltlux (솔트룩스)
May 2021 - Jul 2022- Personal Agent Desktop: Part of the Personal Agent project, personalized data mining, using resources from the user's own computer. Personal Agent desktop is in the presentation layer to manage the collected data, statistics and all source to collect of user. (hybrid app with Personal Agent web with more personal functions)- Personal Agent windows services: Part of the Personal Agent project, personalized data mining, using resources from the user's own computer. The windows service will be responsible for checking the collection schedule and conducting highly personalized data collection. Show less • Used Google Kubernetes Engine (GKE) to deploy and manage a crawler system with 800 nodes on Google Cloud Platform (GCP)• Used Kafka to stream and process large amounts of data from the crawler system• Used Redis to store and access data in memory for fast performance• Used MongoDB to store and query structured and unstructured data• Used Loki, Promtail, and Grafana to monitor and visualize the logs and metrics of the crawler system and other components• Used best practices and tools to automate, secure, and optimize the DevOps workflow on GCP Show less - Account control extension: Chromium-core extension for obtaining account-based cookies for the collection of data that requires login authentication such as social networks. Collect facebook full access token of account.- Personal Agent web-frontend: Part of the Personal Agent project, personalized data mining, using resources from the user's own computer. Personal Agent web-frontend is in the application layer to manage the collected data, statistics and all source to collect of user. + Tool: Vue, Bootstrap- Blocking paywall extension: Chromium-core extension for blocking the payment required in some Newspaper (for data collection module) Show less Backend modules: - All about Data Extraction module (Worker, manager, queue, document parser, ...): Collecting all kinds of data on social networks on demand. Manage the workers to collect. Data stored at MongoDB and managed data at Postgree. Workers, using http, selenium depend on Rule template sepecified, are given the option to use proxies to avoid problems with blocking requests. + Full responsibility (develop, manage source code, deploy) + Tools: MongoDB, Postgree, Kafka, Selenium. - Realtime metasearch: Quickly search results related to keywords on search systems. Handles blocking requests (Redis cache, autohealing), automatically scaling according to requests received and resources used. + Full responsibility (develop, manage source code, GKE deploy) + Tools: Kafka, Redis, K8s, Jetty - Personal Agent web-backend: Part of the Personal Agent project, personalized data mining, using resources from the user's own computer. Personal Agent web is in the application layer to manage the collected data, statistics and all source to collect of user. + Full responsibility (develop, manage source code, deploy): + Tool: Spring boot, Kafka Show less
C# Software Engineer
Oct 2021 - Jul 2022DevOps Engineer
Aug 2021 - Jul 2022Javascript Engineer
Aug 2021 - Jul 2022Java Software Engineer
Jun 2021 - Jul 2022Python Engineer
May 2021 - Jul 2022

Vmo group
Aug 2022 - nowSenior devops engineerVMO Group is an outsourcing company that provides software development and IT services to clients across various industries. As a DevOps engineer at VMO Group, my main role was to create and maintain dev environments for all Delivery Units in the company, using various technologies and best practices.• Set up and maintained a robust and secure on-premise Kubernetes system for deploying and managing containerized applications• Implemented a Ceph storage system to provide scalable and reliable storage for the Kubernetes clusters• Installed and configured Gitlab system to enable version control, continuous integration, and continuous delivery for the development teams• Integrated Gitlab dynamic runner system used IaC tools to manage Gitlab runner system with GitOps, which is a methodology that applies the principles of version control and automation to the entire software delivery pipeline to improve the efficiency, reliability, and security of the software delivery process at VMO Group• Provision and manage the Proxmox system, which is a virtualization platform that allows running multiple operating systems on a single host Show less

Gem - global enterprise mobility
Sept 2022 - Dec 2022Devops engineer- Built a logging and tracing system on AWS to monitor and troubleshoot the performance and health of their applications• Used Fluent Bit to collect and forward logs from various sources to Loki• Used Loki to store and query the logs in a scalable and cost-effective way• Used Grafana to visualize and analyze the logs and metrics from Loki and other sources• Used OpenTelemetry to instrument and collect traces from the applications• Used AWS X-Ray to store and visualize the traces and identify bottlenecks and errors• Used CloudFormation to provision and manage the AWS resources for the logging and tracing system• Used HashiCorp Packer to create and configure custom AMIs for the EC2 instances running the applications Show less

Dentity
Dec 2022 - Sept 2023Senior devsecops engineerDentity is a platform that enables consumers and businesses to more easily and safely share their identity data. It provides secure and scalable authentication and authorization services for web and mobile applications. Dentity System leverages the best practices and tools of DevSecOps to ensure the highest level of security and performance throughout the software development lifecycle.As a sole DevSecOps engineer working on Dentity System, I am responsible for integrating security into the development and operations processes. Some of the tasks that I perform include:• Manage project-evel secrets using Vault Warden• Automate the deployment of your applications to AWS EKS clusters using fully managed by GitOps with Gitlab CI and ArgoCD• Infrastructre as Code (IAC) to improve the scalability, availability, security, and performance of the infrastructure by following best practices such as version control, modularization, testing, and monitoring using Terraform.• Autoscale the EKS clusters with KEDA and Kapenter• Manage your secrets and rotate secrets securely with Hashicorp Vault and enforce policies with OPA GateKeeper• Passwordless and credential-less design pattern to connect to a database or other AWS resources without storing or passing any passwords or credentials.• SAST and DAST scan IAC and Application code for vulnerabilities with Snyk, Sonarqube, Trivy and ZAP operator• Monitor the performance and health of your system with logging (Promtail, loki, grafana), tracing (ElasticSearch, Jaeger), and monitoring (Prometheus)• Automatically deploys and manages AWS WAF rules to protect your web applications from common attacks with Automation WAF (anti DDoS, Web Scan, XSS/SQL injection, Bot and IP restriction, ...)By following the DevSecOps approach, I help Dentity System deliver secure and reliable identity services to its customers while maintaining agility and innovation in AWS. Show less

Bicbank cambodia
Jan 2023 - Feb 2024Senior devsecops engineerLed a comprehensive cloud migration to AWS for BIC Bank Cambodia, transforming their on-premises infrastructure for increased scalability, agility, and cost-efficiency.Technical Approach:Technical approach:- Migrate all on-premises banking platforms to AWS with a re-architect strategy- Design and implement landing zones for organizations with IAM Identity Central Active Directory- Design and implement hub and spoke hybrid network model- Implement Site to Site VPN and Software VPN with SSO Active Directory with Pritunl Enterprise- Implement all underlying infrastructure as EKS, RDS serverless, DynamoDB ...- Implement centralized security and monitoring in shared-service EKS cluster with Hashicorp Vault high availability, Prometheus with Thanos Multi cluster pattern.- Implement secret rotation and injection with Hashicorp Vault Injector high availability, directly pass secrets into the pod without storing them as secrets inside the cluster.- Implement distro-less images with smaller size, faster deployments, and potentially improved security.- Implement Istio gateway and service mesh with strict mTLS between microservices.- Implement Gitlab for 5000 users with hybrid architecture- Integrate GitLab dynamic runner system with GitOps managed declarative config- Implement a centralized pipeline template with many security layers in the pipeline, including SAST and SCA with Sonarqube, Trivy, Snyk, Docker Scout, ...and DAST with OWASP ZAP - Implement policy enforcement with Open Policy Agent GateKeeper with Centralized Policy Management, Admission Control Integration, Enforcing Best Practices and Compliance Enforcement to comply with internal security policies or external regulatory requirements (e.g., PCI-DSS, HIPAA)- Implement Security Automations for AWS WAF rules to protect your web applications from common attacks with Automation WAF (anti DDoS, Web Scan, XSS/SQL injection, Bot and IP restriction, ...) Show less

Bb digtal
Feb 2023 - nowSenior devops engineerAs a sole DevOps engineer at BB Digital Company, you are responsible for ensuring the security and reliability of the company's software development and operations processes. You implement DevSecOps best practices, such as using tools like Vault Warden, Gitlab CI/ArgoCD, Terraform, KEDA/Kapenter, Hashicorp Vault/OPA GateKeeper, and Snyk/Sonarqube/Trivy/ZAP Operator to automate security tasks throughout the software development lifecycle. You also monitor the performance and health of the company's systems with logging (Promtail, Loki, Grafana), tracing (ElasticSearch, Jaeger), and monitoring (Prometheus). Additionally, you use Automation WAF to automatically deploy and manage AWS WAF rules to protect the company's web applications from common attacks. Show less

Onqlave
Jun 2023 - Sept 2023Senior devsecops engineerAs a DevSecOps engineer at OQL Company in Australia, I am responsible for ensuring the security and reliability of the company's Encryption as a Service platform on Google Cloud Platform. I work in a fully secured environment and use a landing zone approach with Google Cloud Foundation Fabric.My responsibilities include:- Implementing and managing DevSecOps best practices throughout the software development lifecycle, from code development to deployment and operations.- Using Google Cloud Platform security tools and services to protect the company's infrastructure, data, and applications.- Configuring and managing Google Cloud Foundation Fabric to create a secure landing zone for the Encryption as a Service platform.- Working with other engineers to automate security tasks and integrate security into the company's development and operations processes.- Monitoring the performance and security of the Encryption as a Service platform and responding to incidents promptly.I am a highly skilled and experienced DevSecOps engineer with a deep understanding of Google Cloud Platform security tools and services. I am also passionate about DevSecOps and am committed to delivering secure and reliable software. Show less

Zuellig pharma
Oct 2023 - nowSenior platform engineerZuellig Pharma, Asia's healthcare leader for over a century, provides top-notch distribution and services to expand healthcare access across 16 markets. They partner with top pharma companies, serving over 200,000 medical facilities.Objective:The objective is to modernize cloud infrastructure by migrating from Azure to GCP with Kubernetes Engine for orchestration. This transition will implement best practices for organization and security (Fabric FAST, GKE best practices, GitOps) and leverage CloudSQL with Workload Identity for secure databases. An IaC pipeline will automate infrastructure management.Responsibilities:• Migrate all the infrastructure from Azure to Google Cloud• Set up and maintain the Kubernetes system• Implement best practice Organization model using Fabric FAST• Implement security best practices to the GKE system• Migrate and implement security with GitOps from AAKS to GKE• Provision CloudSQL and implement SQLproxy with Workload Identity Authentication methods to provide secured connection to the databases.• Setup pipeline for IaC Show less
Licenses & Certifications

Aptis - c level (cerf - ielts 7.5 equivalent)
British councilAug 2020- View certificate

Data analysis for business and finance
UdemyMar 2021 - View certificate

Python for data science and ai
IbmMar 2023 - View certificate

Python for data analysis, data science & ml with pandas
UdemyMar 2021 - View certificate

Devops on aws specialization
CourseraAug 2022 - View certificate

Google cloud fundamentals: core infrastructure
GoogleMar 2022 - View certificate

Continuous integration and continuous delivery (ci/cd)
IbmAug 2022 - View certificate

Power bi - data analytics essentials with power bi
UdemyMar 2021 - View certificate

Sql bootcamp with mysql, php & python : 5 courses in 1
UdemyMar 2021 
Certificate for completion of the internship
Jetro - japan external trade organizationFeb 2021
Honors & Awards
- Awarded to Son DoVMO Silver Star Award 2023 VMO Group Jan 2024 VMO Shining Star Award 2023 is an annual recognition program that celebrates the outstanding achievements and contributions of VMO employees who demonstrate the company's values of collaboration, caring, aspiration, and excellence. VMO group is about 1300 employees by the end of 2023.
- Awarded to Son DoVMO Shining Star Award 2022 VMO Group Jan 2023 VMO Shining Star Award 2022 is an annual recognition program that celebrates the outstanding achievements and contributions of VMO employees who demonstrate the company's values of collaboration, caring, aspiration, and excellence. VMO group is about 1500 employees by the end of 2022.
- Awarded to Son DoEmployee of the year 2021 - Saltlux Saltlux Jan 2022 Saltlux Employee of the Year 2021 is an annual recognition program that celebrates the outstanding achievements and contributions of Saltlux employees who demonstrate the company's values of collaboration, caring, aspiration, and excellence. Saltlux is about 250 employees by the end of 2021.
- Awarded to Son Do経済産業省 国際化促進インターンシップ事業 (METI Government of JAPAN, Japan Internship Program) 経済産業省
Volunteer Experience
Content and Technical Support
Issued by Ecommerce Club FTU on Oct 2017
Associated with Son Do
Languages
- viVietnamese
- enEnglish
Recommendations

Phuc mai vinh
National Security Manager - DHL ExpressHo Chi Minh City Metropolitan Area
Julian hillery, cfa, cpa
Vice President - Davenport Asset ManagementRichmond, Virginia, United States
Manasa yemula
Senior Analyst at CapgeminiHyderabad, Telangana, India
María daniela lituma vásconez
Talent Acquisition Specialist I Technical Recruiter I USA I EUROPE I LATAM I IT I Full Cycle Recruit...Cuenca, Azuay, Ecuador
Kimberly xiong
Production Admin at 4imprintOshkosh, Wisconsin, United States
Elisa díaz martínez
Psychologist | Talent Acquisition | HRGreater Madrid Metropolitan Area
Nicole flemming
Financial Associate at CIBC Wood GundySaint Marys, New Brunswick, Canada
Mohamed faisal
System Support Engineer at Urbansoft Middle East W.L.Lالبحرين
Frederic meuriot
Senior VP, Credit Portfolio Group Manager, Citi Private BankSingapore
Mohamed aboassaker
Plant general Manager في Al kindi pharmaceutical companyBaghdad Governorate, Iraq
...