About
Cloud Infrastructure & Security Manager at 7-Eleven Vietnam, where I design and operate the platform that powers hundreds of convenience stores across the country. I lead a team responsible for a Kubernetes fleet of 200+ worker nodes, 50+ microservices, and 30+ database servers — maintaining 99.9% uptime in a mission-critical environment.
My work spans multi-cloud architecture (AWS, GCP, VNG Cloud, FPT Cloud), DevSecOps pipelines, platform security, and cost optimization. I drive GitOps, IaC (Terraform/Ansible), and full-stack observability (PLG, ELK, New Relic) so engineering teams ship reliably and safely. I also maintain an Engineering Knowledge Base documenting production patterns, runbooks, and SRE practices.
Skills
Certifications
Projects
Kubernetes Platform at Scale
Designed and operated a K8s cluster with 200+ worker nodes, 50+ microservices, and 600+ pods for 7-Eleven Vietnam. Achieved 99.9% uptime with auto-scaling, rolling deployments, and multi-zone redundancy.
DevSecOps Pipeline
Built end-to-end CI/CD with integrated SAST, DAST, and container image scanning. Implemented WAF, IDS/IPS, and automated compliance checks — cutting deployment time 60% while hardening security posture.
Multi-Cloud Landing Zone
Architected hybrid landing zones across AWS, GCP, VNG Cloud, and FPT Cloud using Terraform and Ansible — enabling consistent, repeatable provisioning and unified governance.
Observability & Monitoring
Deployed full-stack observability — PLG (Prometheus + Loki + Grafana), ELK, and New Relic. Built alerting pipelines and on-call runbooks covering 30+ database servers and 120+ tenant databases.
Cloud Cost Optimization
Led cloud cost governance — right-sizing workloads, Reserved Instance planning, and Spot instance strategies. Reduced monthly spend while maintaining full SLA compliance.
Engineering Knowledge Base
Personal documentation covering Cloud, Security, SRE, Observability, Database, and Platform Engineering — built from production experience with runbooks, ADRs, and cheatsheets.
Contact
Open to discussions on cloud infrastructure, platform security, DevSecOps practices, or SRE challenges. Drop a message or connect via any channel below.