Sina Ebrahimi

DevOps Engineer
Tehran, Iran

About

Im a DevOps Engineer working on automation, containerized infrastructure, and CI/CD pipelines in Linux environments, with a focus on integrating security into infra and deployment workflows

I have experience in infrastructure setup, Linux systems, monitoring, and applying security practices across systems and pipelines.

Download My Résumé

Education

Bachelor of Computer Science
2018 – 2024
Amirkabir University of Technology (Tehran Polytechnic)

Experience

Arcaptcha
DevOps Engineer
Feb 2026 – Present
  • Improved internal infra by moving core services and tools (like MinIO, n8n, Nexus) into Kubernetes for better management
  • Built an Ansible-based Docker image scanning tool to improve container image security
  • Set up a Prometheus and Grafana monitoring stack for internal services and created additional dashboards with a focus on security
  • Automated GitLab Runner deployment and configuration using Ansible, reducing manual Runner setups
  • Designed HA Postgres, Mongo, and Redis clusters using Docker Compose, automated with Ansible
  • Implemented TLS between one internal service and its database using Kubernetes cert-manager to secure communications
Arcaptcha
DevOps Intern
Nov 2025 – Feb 2026
  • Assisted in Linux server administration and infrastructure setup
  • Deployed and tested applications in a Kubernetes (k3s) environment
  • Assisted in Kubernetes deployments and basic ingress configuration
Central Securities Depository of Iran
Security Operations Center Analyst
Apr 2023 – Oct 2025
  • Joined as one of the first members of a newly formed SOC team and helped build its initial monitoring structure
  • Built 30+ production SPL searches and dashboards used daily by SOC analysts and IR teams
  • Organized monitoring across key sources like Windows systems, Sysmon, Linux, Active Directory, WAF, and endpoint security, improving infrastructure visibility
  • Deployed real-time dashboards on SOC wall monitors for continuous event monitoring
  • Reviewed and tuned ~10 important Splunk ES correlation rules, reducing false positives and improving alert quality
  • Created a structured incident documentation process to improve investigation continuity
  • Worked with SIEM engineers to improve log onboarding and centralized logging
  • Helped onboard and guide new SOC analysts on dashboards and monitoring workflows
Saba System Sadra
Security Analyst Intern
Dec 2022 – Apr 2023
  • Assisted in monitoring security alerts and log analysis
  • Studied SOC processes, incident handling, and SIEM concepts

Skills

Infrastructure
Kubernetes Docker Docker Compose Linux Helm
Automation
Ansible Terraform
CI/CD
Git GitLab CI ArgoCD
Observability
Prometheus Grafana
Networking
DNS Nginx TLS
Scripting
Bash Python Go
View Certificates

My Projects

HA-DB-Docker-Compose

High-availability Postgres, Mongo, and Redis clusters deployed on virtual machines using Docker Compose

repo-orchestrator

Ansible-based framework for discovering, scanning, and orchestrating changes across large Git repositories

gitlab-runner

GitLab Runner deployment and configuration automation using Ansible

prometheus-training

Prometheus monitoring stack deployment with Nginx and nginx_exporter on k3s

n8n

n8n workflow automation platform deployment on Kubernetes cluster

basic-TLS-connectivity-lab

TLS connectivity implementation using Cert-Manager for databases (Mongo, Redis, Postgres)

Dockerfile-check-Tools

Validate Dockerfile and container images using various security and best-practice tools

Basic-Dockerfile-check-sh

Shell script to check if Dockerfile includes USER directive and other security best practices

LPIC2-LAB

LPIC-2 lab machines and practice environments for Linux system administration

Active-Directory-Home-Lab

Setup a basic Active Directory environment on virtual home network for security testing

set-up-basic-Suricata

Set up Suricata as a Network Intrusion Detection System (NIDS) for security monitoring

SOC-Linux-Monitoring-Starter-Pack

Basic metrics and monitoring scripts for SOC environments and Linux security monitoring

View All Projects

Connect