Hi, my name is

Burak.

I also known as Capitan

A passionate developer based on cyber security and cloud environments. I tend to make use of modern technologies to build “Secure Feature”.

About Me

I am a software engineer specialized in cloud systems, especially kubernetes, developing security tools for offensive security. I am fascinated by distributed software architectures and cybersecurity.

The applications I develop are mainly clod native and can run in a distributed structure. Apart from that, I participate in CTFs on various platforms, especially hackthebox.

Here are a few technologies I've been working with recently:
  • Python - FastAPI
  • NodeJS - Sequilize
  • Go - Fiber & Gorm
  • ElasticSearch
  • MongoDB
  • PostgreSQL
  • RabbitMQ
  • Kubernetes
  • Docker
  • OpenShift
  • Jenkins
  • Azure DevOps

Experience

Software Engineer - Parlak Jewelry
Jan 2022 - present

I have been working at Parlak Jewelry for more than 6 mounths. I’m mostly working on distrubuted storages by combining technologies like S3, SFTP, NFS …

  • Developed small-scale web services utilizing FastAPI within an e-commerce infrastructure.
  • Conducted deployments on Docker-Swarm and managed the Docker Swarm infrastructure.
  • Automated CI/CD pipelines using Gitea and Jenkins for seamless integration and deployment processes.
  • Designed and implemented applications in accordance with microservice architecture, ensuring scalability and modularity.
  • Integrated and utilized technologies like Redis, PostgreSQL, RabbitMQ, and ElasticSearch to enhance application functionalities and performance.
DevSecOps Engineer - DDTECH
Apr 2023 - Sep 2023
  • Integrating security controls tools like sonarqube & openvas into Continuous Integration (CI) and Continuous Delivery (CD) processes.
  • Participated in information security meetings, sharing insights from my hardening and penetration efforts with team members, contributing to the analysis and reinforcement of robust security strategies.
  • I collaborated with the software teams to mitigate the vulnerabilities discovered in the applications.
  • Enhanced system security by implementing security measures to address vulnerabilities on Linux servers and pipelines.
  • Conducted comprehensive automatic security tests on web applications, operating systems, and cloud infrastructures.
DevOps Engineer - DDTECH
Mar 2022 - Mar 2023
  • Initially, I participated in projects related to identity verification and digital signature processes with Turkey Republic identity cards. In these projects, I took on the management of both large and small-scale environments in cloud infrastructures. I ensured effective management of Development and Stable environments and provided support for the smooth release of versions in the production environment.
  • I played a vital role in the containerization and deployment of applications in the Kubernetes framework, OpenShift and BareMetals.
  • I systematically conducted and enhanced stress, load, and performance assessments for the products, guaranteeing optimal system performance, resilience, and dependability. Detecting bottlenecks and performance issues mostly by Jmeter.
  • I introduced and fine-tuned CI/CD methodologies throughout projects, expediting the software development cycle and elevating overall quality via Jenkins & AzureDevOps.
  • I established and oversaw Kubernetes based environments like OpenShift, Azure, HuaweiCloud, KubesPhere and K8s, implementing automation to streamline deployment and management workflows.
Cyber Security Intern - SiberTime
Aug 2021 - Feb 2022

During my first year at university, I established connections on the HackTheBox platform, which provided me with the unique opportunity to participate in both on-site and remote penetration tests. This hands-on experience allowed me to witness firsthand how companies navigate and implement cybersecurity processes. Specifically, my focus was on areas such as Web Application Security, Network Security, and WAFs.

This exposure marked my initial foray into the cybersecurity landscape within the professional world. These experiences not only honed my technical skills but also ignited a passion for continuous learning. The challenges I encountered during this period have shaped my commitment to contributing meaningfully to the field. Moving forward, I am eager to build upon this foundation, tackle new cybersecurity challenges, and make a significant impact in this dynamic and ever-evolving field.

Cyber Security Intern - ConsSec
Aug 2021 - Feb 2022

During this internship program, I actively participated in security analysis meetings focused on assessing the entire e-commerce infrastructure. My responsibilities included conducting research on attack vectors, with a specific focus on Amazon Web Services. This experience served as my introduction to cloud programming and informatics, providing valuable insights into the intricacies of securing an online retail platform.

Simultaneously, I engaged in another internship where I had the opportunity to delve into the world of DevOps and DevSecOps. While I may not have fully grasped it at the time, the earlier exposure to cloud programming and cybersecurity significantly contributed to my proficiency in these fields. This intersection of experiences has played a pivotal role in shaping my skills for effective system development and maintenance, emphasizing both security and operational efficiency.

Education

2020 - 2024
Bachelor of Science in Software Engineering
University of Istanbul Beykent, Istanbul
GPA: 2.74 out of 4.0
2015 - 2019
High School
Cengizhan Anatolian Highschool, Istanbul
GPA: 80 out of 100

Projects

PortPilot
PortPilot

High performance, distributed port scanner for mostly bugbounty. Fast by FastAPI. Its unique distributed architecture allows scalable agents to be deployed globally, providing unparalleled scanning capabilities.

Python-FastAPI React RabbitMQ ElasticSearch Redis PostgreSQL
System Beacon
System Beacon

System Beacon, or sysbeacon in short, is a platform operating in a distributed structure, aiming to monitor servers and computers subject to strict regulations, where vital information is processed, without any log loss.

Go Rust NodeJS Coucbase RabbitMQ ElasticSearch InfluxDB Grafana Redis PostgreSQL
DevOps Security Issues
DevOps Security Issues

I tried to explain the most common security issues I encounter in the field of devops.

Security Container Linux Capabilities PrivEsc