Robin Chan

Vulnerability Management & Compliance

Vulnerability Management · Compliance & Risk (FedRAMP/HIPAA) · Security Operations

Toronto, ON · rt.chan99@gmail.com · linkedin.com/in/robin-t-chan · github.com/r-t-chan · robinchan.pages.dev

SUMMARY

DevOps Engineer with six years in a HIPAA-regulated telehealth SaaS environment, backed by a cybersecurity diploma and CEH v13. Hands-on across the vulnerability management lifecycle: Nessus and Trivy scanning, Ansible-managed patch remediation, findings reported to security, compliance, and operations, and implemented technical controls for a FedRAMP Moderate authorization. Compliance grounded in the infrastructure it governs: the systems I help secure are the ones I run day to day.

TECHNICAL SKILLS

Vulnerability Management: Nessus (monthly internal-network scanning), Trivy (CI/CD build-gate scanning), Ansible-managed patch remediation, JMeter (authorization/RBAC boundary testing)

Compliance Frameworks: FedRAMP Moderate, HIPAA, PHIPA, PIPEDA, NIST SP 800-53, ISO 27001, SOC 2

Identity & Access Governance: Keycloak (self-hosted OAuth / SSO), AWS IAM, least-privilege policy design, delegated admin groups

Security Monitoring & Detection: OpenSearch / ELK, Sigma rules, Fluentbit, Lambda-based alerting, Zabbix; Grafana, Loki, Prometheus (exploratory POC)

Cloud & Network Security: AWS (IAM, KMS, S3, VPC, SSM, CloudWatch, EventBridge, Lambda, ECS, EC2), VLAN segmentation, firewall management, DNS/DHCP, NAT topology design, Proxmox VE, Linux

Automation & IaC: Terraform, Ansible, GitHub Actions, Docker, Python, Bash, Lua, JavaScript

EXPERIENCE

DevOps Engineer

2023 – Present

Keel Digital, HIPAA-regulated telehealth SaaS

  • Contributed to the FedRAMP Moderate authorization effort, implementing technical controls across infrastructure and CI/CD pipelines, including S3 encryption at rest, audit logging, network segmentation, access controls, and CI/CD pipeline hardening, based on NIST SP 800-53.
  • Added Trivy vulnerability scanning as a build gate across multiple GitHub Actions pipelines, with out-of-band releases for vulnerability fixes outside the biweekly cadence.
  • Manage OS patch cycles across production and development servers using Ansible playbooks, maintaining a consistent security update cadence.
  • Administer a self-hosted Keycloak OAuth/SSO platform serving thousands of users across US/CA production: client/scope management, authentication flows, delegated admin groups, and Zabbix alerting on authentication failures and service errors; manage least-privilege IAM policies across 16 environments.
  • Own core network administration across production and development environments: DNS, DHCP, VLAN segmentation, and firewall rule management.
  • Designed a NAT gateway topology during a 14-server cloud-to-bare-metal migration, removing public interfaces from all dev VMs to reduce attack surface; selected Debian for a minimal OS footprint. Saved roughly $18,000 CAD annually.
  • Built an OpenSearch SIEM from the ground up: Fluentbit-based log ingestion with PII/PHI filtering, Lambda-based automated alerting, and custom Sigma rules targeting authentication and authorization threats.
  • Core responder on the Rapid Response Team, covering 10+ production incidents over 6–12 months; traced one degradation to database connection-pool exhaustion via Elastic log analysis and coordinated remediation.
  • Maintain and extend Terraform IaC across multiple AWS accounts and 26 modules (ECS, S3, IAM, KMS, RDS, VPC, SageMaker); built a new AWS Comprehend module from scratch integrating S3, KMS, and IAM.

QA Analyst

Co-op 2020–2022, Full-time 2022–2023

Keel Digital

  • Added a Nessus container to the application’s Docker Compose stack to run monthly internal-network vulnerability scans for compliance, reporting findings to security, compliance, and operations teams.
  • Discovered and reported a critical vulnerability in the registration API before it reached production, through security-focused API testing.
  • Developed JMeter test suites for API rate limiting, RBAC enforcement, and authorization boundary testing.
  • Solely responsible for artifact builds and production deployments for client onboarding and demos, supporting multiple releases per week at peak.

EDUCATION & CERTIFICATIONS

Advanced Diploma, Cybersecurity, Fanshawe College, London, ON

Certified Ethical Hacker (CEH) v13, EC-Council