Robin Chan

DevOps Engineer

AWS · Terraform · CI/CD · Security & Compliance

Toronto, ON · rt.chan99@gmail.com · linkedin.com/in/robin-t-chan · github.com/r-t-chan · robinchan.pages.dev

SUMMARY

DevOps Engineer with six years in a HIPAA-regulated telehealth SaaS environment, progressing from QA security testing to building and running production infrastructure. Core strengths in CI/CD pipeline engineering, Terraform IaC, and security-focused operations across AWS.

TECHNICAL SKILLS

Cloud & Infrastructure: AWS (EC2, ECS, Lambda, S3, IAM, SSM, CloudWatch, EventBridge, VPC), Proxmox VE, OVHcloud, DigitalOcean, Linux

IaC, CI/CD & Containers: Terraform, Ansible (patch management, config remediation), GitHub Actions, Docker

Monitoring & Security: OpenSearch / ELK, Sigma rules, Zabbix; Grafana, Loki, Prometheus (exploratory POC); Keycloak (SSO / IAM), Fluentbit, Nessus, JMeter, Trivy

Networking: DNS/DHCP, VLAN segmentation, firewall management, NAT topology design

Frameworks & Compliance: FedRAMP, HIPAA, PHIPA, PIPEDA, NIST, ISO 27001, SOC 2

Scripting: Python, Bash, Lua, JavaScript

EXPERIENCE

DevOps Engineer

2023 – Present

Keel Digital, HIPAA-regulated telehealth SaaS

  • Maintain and extend GitHub Actions CI/CD pipelines across multiple repos: Trivy vulnerability scanning as a build gate, parallel multi-service builds, and multi-brand matrix builds producing per-brand Docker images; pipelines deploy to ECS via automated task definition updates and to dev environments via SSH through a bastion host.
  • Maintain and extend Terraform IaC across multiple AWS accounts and 26 modules (ECS, S3, IAM, KMS, RDS, VPC, SageMaker); built a new AWS Comprehend module from scratch integrating S3, KMS, and IAM.
  • Led a 14-server migration from DigitalOcean droplets to OVHcloud bare-metal (Proxmox VE, Debian): vendor analysis, full disk image transfer over SSH, and Ansible-based post-migration remediation; designed a NAT gateway topology removing public interfaces from all dev VMs, saving roughly $18,000 CAD annually.
  • Own core network administration across production and development environments: DNS, DHCP, VLAN segmentation, and firewall rule management.
  • Built an OpenSearch SIEM from the ground up: Fluentbit-based log ingestion with PII/PHI filtering, Lambda-based automated alerting, and custom Sigma rules targeting authentication and authorization threats.
  • Administer a self-hosted OAuth/SSO platform serving thousands of users across US/CA production: client/scope management, authentication flows, delegated admin groups, and Zabbix alerting on auth failures and service errors; manage least-privilege IAM policies across 16 environments.
  • Manage OS patch cycles across production and development servers using Ansible playbooks, maintaining a consistent security update cadence.
  • Core responder on the Rapid Response Team, covering 10+ production incidents over 6–12 months; traced one degradation to database connection-pool exhaustion via Elastic log analysis and coordinated remediation.
  • Contributed to the FedRAMP authorization effort, implementing technical controls across infrastructure and CI/CD pipelines.

QA Analyst

Co-op 2020–2022, Full-time 2022–2023

Keel Digital

  • Solely responsible for artifact builds and production deployments for client onboarding and demos, supporting multiple releases per week at peak.
  • Developed JMeter test suites for API rate limiting, RBAC enforcement, and authorization boundary testing.
  • Discovered and reported a critical vulnerability in the registration API before it reached production.
  • Added a Nessus container to the application’s Docker Compose stack to run monthly internal-network vulnerability scans for compliance, reporting findings to security, compliance, and operations teams.

EDUCATION & CERTIFICATIONS

Advanced Diploma, Cybersecurity, Fanshawe College, London, ON

Certified Ethical Hacker (CEH) v13, EC-Council