MUSTAFA F. SUNKA

Senior DevSecOps Engineer

8+ Years · AWS · Azure · GCP

Infrastructure that holds up —
under load, and under audit.

I design and operate highly available cloud infrastructure for organizations that can't afford downtime or a failed audit. The work is mostly unglamorous: Terraform modules, runbooks, and alerting that catches a problem before a customer does. I've also been trusted to mentor the engineers who'll do it after me.

99.9%
availability sustained across 20+ critical services
75%
cut in provisioning time via reusable Terraform modules
75%
reduction in downtime from unified observability
40%
faster incident detection via Splunk & LogicMonitor
65%
faster recovery — automated DR runbooks, 2-hr RTO
100%
compliance sustained across 3 straight audit cycles
500+
endpoints under continuous monitoring
40+
security controls embedded into IaC pipelines

Experience

Thirteen years, one company, five roles
Feb 2013 —
Present

Senior DevSecOps Engineer · Global Payments, Dallas, TX

  • Defined and enforced SLOs/SLIs for 20+ critical services across AWS, Azure, and GCP, holding 99.9% availability.
  • Led incident detection and root-cause analysis for a high-throughput production platform, cutting mean time to detect by 40%.
  • Engineered reusable, policy-as-code Terraform modules that cut deployment cycle time by 75%.
  • Built disaster recovery playbooks with a 2-hour RTO, cutting mean time to recover by 65%.
  • Embedded security scanning and secrets management into CI/CD, eliminating hardcoded credentials across every environment.
  • Mentored four junior engineers — one internal promotion, 30% faster onboarding for new hires.

Five roles at Global Payments: Technical Support Representative → Account Manager → Data Analyst → DevOps Engineer → Senior DevSecOps Engineer.

2005 —
2013

Operations Manager · Best Buy, Hammond, LA

  • Ran a 20-person team at a $10M+ revenue location, lifting customer satisfaction 18% while cutting attrition.

Selected Work

From the portfolio repository

DevSecOps Security Pipeline

A four-gate GitHub Actions pipeline — secrets scanning, SAST, dependency checks, and policy enforcement — that stops insecure code before it reaches production.

PCI DSS Compliance-as-Code

Automated PCI DSS v4.0 scanning with Checkov and OPA, wired into CI/CD so audit evidence is generated on every push instead of scrambled together once a year.

Observability Stack — Prometheus + Grafana

A fully instrumented Flask service with Prometheus metrics and Grafana alerting tied to SLO thresholds — the same pattern I run in production.

Skills

Tools and platforms, by category
Cloud
AWS·Azure·Google Cloud
SRE & Reliability
SLO/SLI·Incident Management·Root Cause Analysis·Disaster Recovery·Chaos Engineering·Runbook Authoring
IaC & Automation
Terraform·ARM Templates·Ansible·PowerShell·Python·Bash
Containers & CI/CD
Kubernetes (GKE)·Docker·Jenkins·Azure DevOps·Git / GitHub
Observability
Splunk·LogicMonitor·ThousandEyes·Application Insights·CloudWatch·Prometheus / Grafana
Security & Compliance
Snyk·Wiz·HashiCorp Vault·PCI DSS·Azure Key Vault·GCP Secret Manager

Certifications

  • Microsoft Certified: Azure Administrator Associate
  • Microsoft Azure Fundamentals
  • Google Cloud Foundational
  • SAS Institute Graduate CertificateBusiness Intelligence & Data Mining

Education

  • M.S., Information Technology ManagementUniversity of Texas at Dallas — 2018
  • B.A., Mass CommunicationLouisiana State University — 2010