End-to-End DevSecOps Pipeline with Policy Enforcement
Designed and implemented a fully automated DevSecOps CI/CD pipeline integrating SAST, DAST, dependency scanning, and container image scanning into Jenkins pipelines. Integrated tools such as SonarQube, OWASP ZAP, and container vulnerability scanning to detect security issues early in the SDLC. Enforced security gates that blocked deployments on high/critical vulnerabilities, reducing production security risks by over 40%. Implemented Infrastructure-as-Code (Terraform) with security validation checks and misconfiguration scanning prior to deployment. Deployed runtime security monitoring for Kubernetes workloads, enabling real-time threat detection and policy enforcement.





