INDEPENDENT DEVOPS CONSULTING

Bring code and secrets security into your workflow

Security checks are most useful when developers can understand and act on their results. I help teams bring code scanning, dependency checks and secrets management into the tools and delivery workflows they already use.

Remote collaboration with international software teams.

Discuss code and secrets security

Is this the help your team needs?

For software teams introducing repository security checks, untangling an existing scanning setup, or moving secrets out of manual configuration and into a more manageable workflow.

Put the right checks in the development workflow

Adding a scanner is a starting point. The useful work includes deciding where it runs, making its findings visible, and understanding who responds. A check that nobody can interpret or maintain adds friction without a clear benefit.

Code scanning

Bring static analysis into the repository workflow so findings can be reviewed alongside development. My production work includes GitHub Advanced Security and CodeQL.

Dependency checks

Make dependency findings visible to the team responsible for the application. Consider where checks run, how updates enter the workflow, and which results need attention before a release.

Secrets management

Review where application and pipeline credentials are stored and how they reach the systems that need them. Secret scanning and secret management address different parts of that process.

Plan the rollout around the repositories and people

An existing repository has its own languages, build requirements, permissions and release constraints. Those details determine how a check fits into development and what the team will need to operate it.

We can start by discussing the current setup and the problems you want to address. The relevant implementation work might involve an existing scanning pipeline, a new check, or the way credentials are passed between systems. The scope follows that discussion.

Make findings and ownership clear

A useful handover explains both the configuration and the workflow around it. The team needs to understand where findings appear, how to investigate failures and who owns the next action.

  • Which repositories and workflows are covered by each check.
  • How the checks authenticate and what access they require.
  • Where developers review findings and pipeline failures.
  • Who maintains the configuration and handles follow-up work.

RELEVANT BACKGROUND

Experience behind the work

My work at EPAM Systems includes hands-on security scanning with GitHub Advanced Security, CodeQL and Mend.io, with a GCP focus.

System Engineer · EPAM Systems · 2025–present

About Aleksandre Ghvineria

Tell me about your setup

I work on scoped implementation projects and ongoing engineering support. A description of the problem is a useful starting point.

  • Which repositories, languages and CI/CD tools are involved?
  • Which scanning or secrets-management tools do you use now?
  • What is difficult about the current setup or the findings it produces?
  • Do you need an implementation project or ongoing engineering support?
Email Aleksandre