Son Do

Son Do Email and Phone Number

Platform Leader @ Zuellig Pharma
Hanoi, Vietnam
Son Do's Location
Đống Đa district, Hanoi, Vietnam, Viet Nam
About Son Do

With over 5 years of experience in DevSecOps, I bring a proven track record of success in leading cloud migrations, implementing industry-standard DevSecOps practices, and automating security tasks across diverse environments. I possess a deep understanding of security tools and services on major cloud platforms (AWS, Azure, GCP) and a passion for delivering secure, reliable, and scalable software.My expertise extends beyond security to encompass infrastructure and automation. I'm proficient in tools like Terraform, Kubernetes, and Packer, allowing me to design and manage secure and scalable infrastructure. Additionally, I leverage infrastructure as code (IaC) best practices for version control, modularity, testing, and monitoring.I champion GitOps methodologies for streamlined application deployments. From managing project-level secrets with Vault Warden to deploying applications with Gitlab CI and ArgoCD, I ensure efficient and secure delivery pipelines.Security is paramount. I integrate security throughout the software development lifecycle (SDLC) with a comprehensive toolkit. This includes tools like Hashicorp Vault, OPA Gatekeeper, Snyk, and Sonarqube for secret management, policy enforcement, and vulnerability scanning. My commitment extends to monitoring system performance and health with logging, tracing, and monitoring tools.I possess a well-rounded skillset that includes network concepts. My experience includes designing and implementing hybrid cloud environments with Hub and Spoke models, ensuring secure communication between different components.I am confident that my skills and experience can contribute significantly to your organization's success.Just Shawn!https://github.com/shawnsavour

Son Do's Current Company Details
Zuellig Pharma

Zuellig Pharma

View
Platform Leader
Hanoi, Vietnam
Employees:
147
Son Do Work Experience Details
  • Zuellig Pharma
    Platform Leader
    Zuellig Pharma
    Hanoi, Vietnam
  • Zuellig Pharma
    Senior Platform Engineer
    Zuellig Pharma Oct 2023 - Present
    Singapore
    Zuellig Pharma, Asia's healthcare leader for over a century, provides top-notch distribution and services to expand healthcare access across 16 markets. They partner with top pharma companies, serving over 200,000 medical facilities.Objective:The objective is to modernize cloud infrastructure by migrating from Azure to GCP with Kubernetes Engine for orchestration. This transition will implement best practices for organization and security (Fabric FAST, GKE best practices, GitOps) and leverage CloudSQL with Workload Identity for secure databases. An IaC pipeline will automate infrastructure management.Responsibilities:• Migrate all the infrastructure from Azure to Google Cloud• Set up and maintain the Kubernetes system• Implement best practice Organization model using Fabric FAST• Implement security best practices to the GKE system• Migrate and implement security with GitOps from AAKS to GKE• Provision CloudSQL and implement SQLproxy with Workload Identity Authentication methods to provide secured connection to the databases.• Setup pipeline for IaC
  • Vmo Group
    Senior Devops Engineer
    Vmo Group Aug 2022 - Present
    VMO Group is an outsourcing company that provides software development and IT services to clients across various industries. As a DevOps engineer at VMO Group, my main role was to create and maintain dev environments for all Delivery Units in the company, using various technologies and best practices.• Set up and maintained a robust and secure on-premise Kubernetes system for deploying and managing containerized applications• Implemented a Ceph storage system to provide scalable and reliable storage for the Kubernetes clusters• Installed and configured Gitlab system to enable version control, continuous integration, and continuous delivery for the development teams• Integrated Gitlab dynamic runner system used IaC tools to manage Gitlab runner system with GitOps, which is a methodology that applies the principles of version control and automation to the entire software delivery pipeline to improve the efficiency, reliability, and security of the software delivery process at VMO Group• Provision and manage the Proxmox system, which is a virtualization platform that allows running multiple operating systems on a single host
  • Bb Digtal
    Senior Devops Engineer
    Bb Digtal Feb 2023 - May 2024
    Vietnam
    As a sole DevOps engineer at BB Digital Company, you are responsible for ensuring the security and reliability of the company's software development and operations processes. You implement DevSecOps best practices, such as using tools like Vault Warden, Gitlab CI/ArgoCD, Terraform, KEDA/Kapenter, Hashicorp Vault/OPA GateKeeper, and Snyk/Sonarqube/Trivy/ZAP Operator to automate security tasks throughout the software development lifecycle. You also monitor the performance and health of the company's systems with logging (Promtail, Loki, Grafana), tracing (ElasticSearch, Jaeger), and monitoring (Prometheus). Additionally, you use Automation WAF to automatically deploy and manage AWS WAF rules to protect the company's web applications from common attacks.
  • Bicbank Cambodia
    Senior Devsecops Engineer
    Bicbank Cambodia Jan 2023 - Feb 2024
    Cambodia
    Led a comprehensive cloud migration to AWS for BIC Bank Cambodia, transforming their on-premises infrastructure for increased scalability, agility, and cost-efficiency.Technical Approach:Technical approach:- Migrate all on-premises banking platforms to AWS with a re-architect strategy- Design and implement landing zones for organizations with IAM Identity Central Active Directory- Design and implement hub and spoke hybrid network model- Implement Site to Site VPN and Software VPN with SSO Active Directory with Pritunl Enterprise- Implement all underlying infrastructure as EKS, RDS serverless, DynamoDB ...- Implement centralized security and monitoring in shared-service EKS cluster with Hashicorp Vault high availability, Prometheus with Thanos Multi cluster pattern.- Implement secret rotation and injection with Hashicorp Vault Injector high availability, directly pass secrets into the pod without storing them as secrets inside the cluster.- Implement distro-less images with smaller size, faster deployments, and potentially improved security.- Implement Istio gateway and service mesh with strict mTLS between microservices.- Implement Gitlab for 5000 users with hybrid architecture- Integrate GitLab dynamic runner system with GitOps managed declarative config- Implement a centralized pipeline template with many security layers in the pipeline, including SAST and SCA with Sonarqube, Trivy, Snyk, Docker Scout, ...and DAST with OWASP ZAP - Implement policy enforcement with Open Policy Agent GateKeeper with Centralized Policy Management, Admission Control Integration, Enforcing Best Practices and Compliance Enforcement to comply with internal security policies or external regulatory requirements (e.g., PCI-DSS, HIPAA)- Implement Security Automations for AWS WAF rules to protect your web applications from common attacks with Automation WAF (anti DDoS, Web Scan, XSS/SQL injection, Bot and IP restriction, ...)
  • Onqlave
    Senior Devsecops Engineer
    Onqlave Jun 2023 - Sep 2023
    Australia
    As a DevSecOps engineer at OQL Company in Australia, I am responsible for ensuring the security and reliability of the company's Encryption as a Service platform on Google Cloud Platform. I work in a fully secured environment and use a landing zone approach with Google Cloud Foundation Fabric.My responsibilities include:- Implementing and managing DevSecOps best practices throughout the software development lifecycle, from code development to deployment and operations.- Using Google Cloud Platform security tools and services to protect the company's infrastructure, data, and applications.- Configuring and managing Google Cloud Foundation Fabric to create a secure landing zone for the Encryption as a Service platform.- Working with other engineers to automate security tasks and integrate security into the company's development and operations processes.- Monitoring the performance and security of the Encryption as a Service platform and responding to incidents promptly.I am a highly skilled and experienced DevSecOps engineer with a deep understanding of Google Cloud Platform security tools and services. I am also passionate about DevSecOps and am committed to delivering secure and reliable software.
  • Dentity
    Senior Devsecops Engineer
    Dentity Dec 2022 - Sep 2023
    Los Angeles, California, United States
    Dentity is a platform that enables consumers and businesses to more easily and safely share their identity data. It provides secure and scalable authentication and authorization services for web and mobile applications. Dentity System leverages the best practices and tools of DevSecOps to ensure the highest level of security and performance throughout the software development lifecycle.As a sole DevSecOps engineer working on Dentity System, I am responsible for integrating security into the development and operations processes. Some of the tasks that I perform include:• Manage project-evel secrets using Vault Warden• Automate the deployment of your applications to AWS EKS clusters using fully managed by GitOps with Gitlab CI and ArgoCD• Infrastructre as Code (IAC) to improve the scalability, availability, security, and performance of the infrastructure by following best practices such as version control, modularization, testing, and monitoring using Terraform.• Autoscale the EKS clusters with KEDA and Kapenter• Manage your secrets and rotate secrets securely with Hashicorp Vault and enforce policies with OPA GateKeeper• Passwordless and credential-less design pattern to connect to a database or other AWS resources without storing or passing any passwords or credentials.• SAST and DAST scan IAC and Application code for vulnerabilities with Snyk, Sonarqube, Trivy and ZAP operator• Monitor the performance and health of your system with logging (Promtail, loki, grafana), tracing (ElasticSearch, Jaeger), and monitoring (Prometheus)• Automatically deploys and manages AWS WAF rules to protect your web applications from common attacks with Automation WAF (anti DDoS, Web Scan, XSS/SQL injection, Bot and IP restriction, ...)By following the DevSecOps approach, I help Dentity System deliver secure and reliable identity services to its customers while maintaining agility and innovation in AWS.
  • Gem - Global Enterprise Mobility
    Devops Engineer
    Gem - Global Enterprise Mobility Sep 2022 - Dec 2022
    - Built a logging and tracing system on AWS to monitor and troubleshoot the performance and health of their applications• Used Fluent Bit to collect and forward logs from various sources to Loki• Used Loki to store and query the logs in a scalable and cost-effective way• Used Grafana to visualize and analyze the logs and metrics from Loki and other sources• Used OpenTelemetry to instrument and collect traces from the applications• Used AWS X-Ray to store and visualize the traces and identify bottlenecks and errors• Used CloudFormation to provision and manage the AWS resources for the logging and tracing system• Used HashiCorp Packer to create and configure custom AMIs for the EC2 instances running the applications
  • Saltlux (솔트룩스)
    C# Software Engineer
    Saltlux (솔트룩스) Oct 2021 - Jul 2022
    - Personal Agent Desktop: Part of the Personal Agent project, personalized data mining, using resources from the user's own computer. Personal Agent desktop is in the presentation layer to manage the collected data, statistics and all source to collect of user. (hybrid app with Personal Agent web with more personal functions)- Personal Agent windows services: Part of the Personal Agent project, personalized data mining, using resources from the user's own computer. The windows service will be responsible for checking the collection schedule and conducting highly personalized data collection.
  • Saltlux (솔트룩스)
    Devops Engineer
    Saltlux (솔트룩스) Aug 2021 - Jul 2022
    Vietnam
    • Used Google Kubernetes Engine (GKE) to deploy and manage a crawler system with 800 nodes on Google Cloud Platform (GCP)• Used Kafka to stream and process large amounts of data from the crawler system• Used Redis to store and access data in memory for fast performance• Used MongoDB to store and query structured and unstructured data• Used Loki, Promtail, and Grafana to monitor and visualize the logs and metrics of the crawler system and other components• Used best practices and tools to automate, secure, and optimize the DevOps workflow on GCP
  • Saltlux (솔트룩스)
    Javascript Engineer
    Saltlux (솔트룩스) Aug 2021 - Jul 2022
    - Account control extension: Chromium-core extension for obtaining account-based cookies for the collection of data that requires login authentication such as social networks. Collect facebook full access token of account.- Personal Agent web-frontend: Part of the Personal Agent project, personalized data mining, using resources from the user's own computer. Personal Agent web-frontend is in the application layer to manage the collected data, statistics and all source to collect of user. + Tool: Vue, Bootstrap- Blocking paywall extension: Chromium-core extension for blocking the payment required in some Newspaper (for data collection module)
  • Saltlux (솔트룩스)
    Java Software Engineer
    Saltlux (솔트룩스) Jun 2021 - Jul 2022
    Backend modules: - All about Data Extraction module (Worker, manager, queue, document parser, ...): Collecting all kinds of data on social networks on demand. Manage the workers to collect. Data stored at MongoDB and managed data at Postgree. Workers, using http, selenium depend on Rule template sepecified, are given the option to use proxies to avoid problems with blocking requests. + Full responsibility (develop, manage source code, deploy) + Tools: MongoDB, Postgree, Kafka, Selenium. - Realtime metasearch: Quickly search results related to keywords on search systems. Handles blocking requests (Redis cache, autohealing), automatically scaling according to requests received and resources used. + Full responsibility (develop, manage source code, GKE deploy) + Tools: Kafka, Redis, K8s, Jetty - Personal Agent web-backend: Part of the Personal Agent project, personalized data mining, using resources from the user's own computer. Personal Agent web is in the application layer to manage the collected data, statistics and all source to collect of user. + Full responsibility (develop, manage source code, deploy): + Tool: Spring boot, Kafka
  • Saltlux (솔트룩스)
    Python Engineer
    Saltlux (솔트룩스) May 2021 - Jul 2022
    Internal Software: -Accounts Helper Application (windows application): + Auto check and update status of cookie/token. + Get cookies and api tokens on a large number of accounts automatically. + Auto create accounts and get account info to crawl data (social network). + Automate all work if possible in the business.
  • グローバル戦略室 - グラビティ株式会社 - Global Strategy Office - Gravity Corporation
    Intern Of Global Strategy Office
    グローバル戦略室 - グラビティ株式会社 - Global Strategy Office - Gravity Corporation Dec 2020 - Feb 2021
    Tokyo, Japan
    This internship was approved by the METI Japan Internship program, organized by METI Government of Japan-Acquired knowledge about Blockchain, Web 3.0, Smart contract through internal training conferences-Learned deeply about Scrum and Agile software development methods. -Worked under the supervision of CTO-Contributed to the company's first product in the education sector
  • Wesports
    Php Web Developer
    Wesports Apr 2019 - Jun 2020
    Vietnam
    • Worked with Wordpress to create and maintain dynamic websites and web applications• Deployed Wordpress on Apache servers and used jQuery for front-end interactivity• Developed software solutions using PHP frameworks, SQL databases, and object-oriented programming• Managed multi-tenant web applications with security and scalability in mind• Used Git for version control and collaboration• Applied HTML5, CSS, JavaScript and other web technologies to design and implement user interfaces and front-end features
  • Wesports
    Sales Marketing Support
    Wesports Mar 2019 - Dec 2019
    Vietnam
    - Support customers for more information and promote Sales - Raise ideas, give detailed planning for sales campaigns- Create events for customers
  • Vnpt-Media
    General Administrative Assistant
    Vnpt-Media Aug 2019 - Dec 2019
    Vietnam
    - Process invoice documents and finance report- Help company get tax information- Manage content posted on media channels
  • Fpt Software
    Machine Learning Support
    Fpt Software Sep 2018 - Feb 2019
    Vietnam
    Trained Artificial Intelligence with personalized data, enabling AI to identify identity cards, automatically retrieve information and enter data into archives.

Son Do Education Details

Frequently Asked Questions about Son Do

What company does Son Do work for?

Son Do works for Zuellig Pharma

What is Son Do's role at the current company?

Son Do's current role is Platform Leader.

What schools did Son Do attend?

Son Do attended Foreign Trade University.

Not the Son Do you were looking for?

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.