Robin Chan
Systems Administrator
Linux · AWS · Virtualization · Security & Monitoring
Toronto, ON · rt.chan99@gmail.com · linkedin.com/in/robin-t-chan · github.com/r-t-chan · robinchan.pages.dev
SUMMARY
Systems Administrator with six years in a HIPAA-regulated telehealth SaaS environment, progressing from QA security testing to building and running production infrastructure. Core strengths in Linux systems administration, virtualization, security operations, and monitoring across on-prem and AWS environments.
TECHNICAL SKILLS
Systems & Infrastructure Administration: Linux, Proxmox VE, OVHCloud, DigitalOcean, AWS (EC2, ECS, Lambda, S3, IAM, SSM, CloudWatch, EventBridge, VPC), Keycloak (SSO / IAM), DNS/DHCP, VLAN segmentation, firewall management
Security & Monitoring: OpenSearch / ELK, Zabbix, Grafana, Loki, Prometheus, Sigma rules, Fluentbit, Nessus, JMeter
Automation & Scripting: Terraform, Ansible (patch management, config remediation), GitHub Actions, Docker, Python, Bash, Lua, JavaScript
Frameworks & Compliance: FedRAMP, HIPAA, PHIPA, PIPEDA, NIST, ISO 27001, SOC 2
Operations & Support: Jira Service Management, automated backup administration
Additional (coursework): Windows Server / Active Directory
EXPERIENCE
DevOps Engineer
2023 – PresentKeel Digital, HIPAA-regulated telehealth SaaS
- Led a 14-server migration from DigitalOcean droplets to OVHcloud bare-metal (Proxmox VE, Debian): vendor analysis, full disk image transfer over SSH, and Ansible-based post-migration remediation; designed a NAT gateway topology removing public interfaces from dev VMs, saving ~$18,000 CAD annually.
- Own core network administration across production and development environments: DNS, DHCP, VLAN segmentation, and firewall rule management.
- Administer a self-hosted OAuth/SSO platform serving thousands of users across US/CA production: client/scope management, authentication flows, delegated admin groups, and Zabbix alerting on auth failures and service errors; manage least-privilege IAM policies across 16 environments.
- Manage OS patch cycles across production and development servers using Ansible playbooks, maintaining a consistent security update cadence.
- Implemented and maintain automated backup processes for production infrastructure and databases.
- Built an OpenSearch SIEM from the ground up: Fluentbit-based log ingestion with PII/PHI filtering, Lambda-based automated alerting, and custom Sigma rules targeting authentication and authorization threats.
- Core responder on the Rapid Response Team, covering 10+ production incidents over 6–12 months; traced one degradation to database connection-pool exhaustion via Elastic log analysis and coordinated remediation.
- Serve as an escalation point for infrastructure and access-related tickets in Jira Service Management, triaging and resolving requests across engineering teams.
- Maintain and extend Terraform IaC across multiple AWS accounts (26 modules) and GitHub Actions CI/CD pipelines deploying 40+ containerized services across US/CA production on a biweekly cadence, with out-of-band releases for vulnerability fixes.
- Contributed to the FedRAMP authorization effort, implementing technical controls across infrastructure and CI/CD pipelines.
QA Analyst
Co-op 2020–2022, Full-time 2022–2023Keel Digital
- Added a Nessus container to the application's Docker Compose stack to run monthly internal-network vulnerability scans for compliance, reporting findings to security, compliance, and operations teams.
- Solely responsible for artifact builds and production deployments for client onboarding and demos, supporting multiple releases per week at peak.
- Developed JMeter test suites for API rate limiting, RBAC enforcement, and authorization boundary testing.
- Discovered and reported a critical vulnerability in the registration API before it reached production.
EDUCATION & CERTIFICATIONS
Advanced Diploma, Cybersecurity, Fanshawe College, London, ON
Certified Ethical Hacker (CEH) v13, EC-Council