Robin Chan
DevOps Engineer
AWS · Terraform · CI/CD · Security & Compliance
Toronto, ON · rt.chan99@gmail.com · linkedin.com/in/robin-t-chan · github.com/r-t-chan · robinchan.pages.dev
SUMMARY
DevOps Engineer with six years in a HIPAA-regulated telehealth SaaS environment, progressing from QA security testing to building and running production infrastructure. Core strengths in CI/CD pipeline engineering, Terraform IaC, and security-focused operations across AWS.
TECHNICAL SKILLS
Cloud & Infrastructure: AWS (EC2, ECS, Lambda, S3, IAM, SSM, CloudWatch, EventBridge, VPC), Proxmox VE, OVHcloud, DigitalOcean, Linux
IaC, CI/CD & Containers: Terraform, Ansible (patch management, config remediation), GitHub Actions, Docker
Monitoring & Security: OpenSearch / ELK, Sigma rules, Zabbix; Grafana, Loki, Prometheus (exploratory POC); Keycloak (SSO / IAM), Fluentbit, Nessus, JMeter, Trivy
Networking: DNS/DHCP, VLAN segmentation, firewall management, NAT topology design
Frameworks & Compliance: FedRAMP, HIPAA, PHIPA, PIPEDA, NIST, ISO 27001, SOC 2
Scripting: Python, Bash, Lua, JavaScript
EXPERIENCE
DevOps Engineer
2023 – PresentKeel Digital, HIPAA-regulated telehealth SaaS
- Maintain and extend GitHub Actions CI/CD pipelines across multiple repos: Trivy vulnerability scanning as a build gate, parallel multi-service builds, and multi-brand matrix builds producing per-brand Docker images; pipelines deploy to ECS via automated task definition updates and to dev environments via SSH through a bastion host.
- Maintain and extend Terraform IaC across multiple AWS accounts and 26 modules (ECS, S3, IAM, KMS, RDS, VPC, SageMaker); built a new AWS Comprehend module from scratch integrating S3, KMS, and IAM.
- Led a 14-server migration from DigitalOcean droplets to OVHcloud bare-metal (Proxmox VE, Debian): vendor analysis, full disk image transfer over SSH, and Ansible-based post-migration remediation; designed a NAT gateway topology removing public interfaces from all dev VMs, saving roughly $18,000 CAD annually.
- Own core network administration across production and development environments: DNS, DHCP, VLAN segmentation, and firewall rule management.
- Built an OpenSearch SIEM from the ground up: Fluentbit-based log ingestion with PII/PHI filtering, Lambda-based automated alerting, and custom Sigma rules targeting authentication and authorization threats.
- Administer a self-hosted OAuth/SSO platform serving thousands of users across US/CA production: client/scope management, authentication flows, delegated admin groups, and Zabbix alerting on auth failures and service errors; manage least-privilege IAM policies across 16 environments.
- Manage OS patch cycles across production and development servers using Ansible playbooks, maintaining a consistent security update cadence.
- Core responder on the Rapid Response Team, covering 10+ production incidents over 6–12 months; traced one degradation to database connection-pool exhaustion via Elastic log analysis and coordinated remediation.
- Contributed to the FedRAMP authorization effort, implementing technical controls across infrastructure and CI/CD pipelines.
QA Analyst
Co-op 2020–2022, Full-time 2022–2023Keel Digital
- Solely responsible for artifact builds and production deployments for client onboarding and demos, supporting multiple releases per week at peak.
- Developed JMeter test suites for API rate limiting, RBAC enforcement, and authorization boundary testing.
- Discovered and reported a critical vulnerability in the registration API before it reached production.
- Added a Nessus container to the application’s Docker Compose stack to run monthly internal-network vulnerability scans for compliance, reporting findings to security, compliance, and operations teams.
EDUCATION & CERTIFICATIONS
Advanced Diploma, Cybersecurity, Fanshawe College, London, ON
Certified Ethical Hacker (CEH) v13, EC-Council