Kỹ sư hạ tầng & vận hànhInfrastructure & operations engineer
Chẩu Đình Doanh
DevOps EngineerDevSecOps Engineer
Tôi dựng hạ tầng, giữ cho nó chạy, và làm nó khó bị phá hơn. Tôi bắt đầu ở ca trực SOC đọc cảnh báo QRadar; giờ tôi làm ở phía bên kia của cảnh báo — cụm OpenShift, pipeline Jenkins, và những cổng quét chặn một bản build hỏng trước khi nó kịp ra production.
I build infrastructure, keep it running, and make it harder to break into. I started on a SOC shift reading QRadar alerts; now I work on the other side of the alert — OpenShift clusters, Jenkins pipelines, and scan gates that stop a bad build before it reaches production.
PDF, 2 trang, tiếng Việt · 312 KB PDF, 2 pages, in Vietnamese · 312 KB
Tóm tắtSummary
- Kinh nghiệmExperience
- 5+ nămyears
- Vai tròRoles
- 3
- Chứng chỉ chínhLead credential
- AWS DevOps Pro
- Quản trịGovernance
- ISO 27001 IA
Định hướngDirection
Mục tiêu là làm DevSecOps Engineer: đưa bảo mật vào bên trong đường ống thay vì dán thêm ở cuối. Hai hướng tôi đang đi sâu — Security Operations và Cloud Security — đều nối tiếp việc đã làm, không phải bắt đầu lại từ đầu.
Điều tôi mang theo từ phòng SOC là một thói quen cụ thể: hỏi “nếu hỏng thì mình biết bằng cách nào” trước khi hỏi “bao giờ xong”. Hạ tầng tự động hoá được mà không quan sát được thì chỉ là hỏng nhanh hơn.
The goal is to work as a DevSecOps Engineer: put security inside the pipeline rather than bolting it on at the end. The two areas I am going deeper on — Security Operations and Cloud Security — continue what I already do rather than starting over.
What I took from the SOC floor is one concrete habit: ask “how would we know if this broke” before asking “when will it ship”. Infrastructure you can automate but cannot observe just fails faster.
Kinh nghiệmExperience
Ba vai trò, xếp từ gần nhất.Three roles, most recent first.
-
IT Manager & DevOps
Công ty Cổ phần Công nghệ VISSOFT
Vai trò rộng nhất tới giờ: vừa giữ hạ tầng on-prem chạy được — máy chủ, mạng, lưu trữ — vừa dựng phần DevOps cho đội phát triển. Tôi dựng và duy trì bộ công cụ (Jira, Confluence, GitLab, SonarQube) rồi đặt pipeline Jenkins vào giữa chúng, để việc kiểm tra chất lượng và bảo mật xảy ra tự động chứ không phụ thuộc vào ai nhớ chạy.
Phần bảo mật là chỗ tôi dành nhiều thời gian nhất: Wazuh để phát hiện bất thường ở tầng host, Splunk để gom và phân tích tập trung, quét lỗ hổng định kỳ, và tham gia áp chính sách theo ISO/IEC 27001:2022. Chính phần ISO dạy tôi điều mà công cụ không dạy được — bảo mật là bằng chứng và quy trình, không chỉ là một dashboard màu xanh.
The broadest role so far: keeping on-premise infrastructure alive — servers, network, storage — while building out the DevOps side for the development team. I set up and maintain the toolchain (Jira, Confluence, GitLab, SonarQube) and put Jenkins pipelines between them, so quality and security checks run automatically instead of depending on someone remembering to run them.
Security is where most of my time goes: Wazuh for host-level anomaly detection, Splunk for centralised collection and analysis, periodic vulnerability scanning, and contributing to ISO/IEC 27001:2022 policy adoption. The ISO work taught me the thing tools cannot — security is evidence and process, not just a green dashboard.
- ci/cdJenkins, GitLab CI/CD, SonarQube
- cloudQuản trị hệ thống AWSAWS system administration
- secWazuh (IDS) · Splunk (SIEM) · quét lỗ hổng định kỳperiodic vulnerability scanning
- govISO/IEC 27001:2022
- infraMáy chủ on-prem, mạng, lưu trữOn-prem servers, network, storage
-
SOC Tier 1
Công ty Cổ phần TVAT Việt Nam
Quãng ngắn nhất trong hồ sơ, và là quãng đổi cách tôi nhìn hệ thống nhiều nhất. Khi phải phân loại cảnh báo QRadar theo ca trực, người ta thôi coi log là thứ sinh ra sau sự cố và bắt đầu coi nó là thứ phải thiết kế trước. Tôi cũng tham gia viết playbook xử lý sự cố — tài liệu để người trực ca sau không phải đoán lại từ đầu.
The shortest entry here, and the one that changed how I look at systems the most. Once you are triaging QRadar alerts on shift, you stop treating logs as something produced after an incident and start treating them as something to design before one. I also helped write incident-response playbooks — documents so that whoever takes the next shift does not have to guess.
- secGiám sát & xử lý sự cố an ninh mạngSecurity monitoring & incident handling
- secPhân tích log và cảnh báo trên IBM QRadarLog and alert analysis on IBM QRadar
- netFortinet Security Fabric (NSE4)
- govPlaybook xử lý sự cố ATTTInformation-security incident playbooks
-
Network / System Engineer
ETC Technology Systems Jsc
Công việc đầu tiên, và là chỗ tôi học cách một hệ thống doanh nghiệp thực sự được nối với nhau. Tôi triển khai và cấu hình hạ tầng mạng ở mức CCNA, vận hành hệ thống, và lần đầu chạm vào thiết bị bảo mật thật: Fortinet Firewall trong kiến trúc Security Fabric, và IBM QRadar — lúc đó còn ở vai người đọc log, chưa phải người điều tra.
My first job, and where I learned how an enterprise system is actually wired together. I deployed and configured network infrastructure at CCNA level, ran systems, and first touched real security equipment: Fortinet Firewall inside a Security Fabric architecture, and IBM QRadar — at that point as someone reading the logs, not yet investigating them.
- netTriển khai & cấu hình hệ thống mạng (CCNA)Network deployment & configuration (CCNA level)
- netFortinet Firewall · Security Fabric
- secIBM QRadar (SIEM)
- infraQuản trị và hỗ trợ vận hành hạ tầngInfrastructure administration & operations support
Dự ánProjects
Mỗi sơ đồ vẽ đúng hình dạng hệ thống đã dựng — không phải hình minh hoạ. Each schematic draws the actual shape of the system built — not an illustration.
-
PRJ-01
Hạ tầng ứng dụng trên AWSApplication infrastructure on AWS
DevOps Engineer
Dựng hạ tầng chạy ứng dụng trên AWS: VPC phân vùng công khai / riêng tư, EC2 ở vùng riêng, IAM cấp quyền theo nguyên tắc tối thiểu, security group siết theo từng tầng thay vì mở một lần cho tiện. Sau khi hệ thống chạy ổn thì quay lại tối ưu chi phí và hiệu năng — phần việc ít được nhắc tới nhưng quyết định hạ tầng có sống lâu được hay không.
Built the AWS infrastructure an application runs on: a VPC split into public and private subnets, EC2 in the private tier, IAM granted on least-privilege lines, and security groups tightened per tier rather than opened once for convenience. Once it was stable I went back for cost and performance tuning — the unglamorous part that decides whether infrastructure survives.
AWS EC2 · VPC · IAM · Security Group
-
PRJ-02
Cụm OpenShift & dịch vụ dự án ADNOpenShift cluster & ADN project services
DevOps / Platform Engineer
Triển khai và cấu hình cụm OpenShift cho môi trường dev/test của BCA và dev/test nội bộ, rồi vận hành nó như một nền tảng container thật chứ không phải một cụm demo: routing, cân bằng tải, chính sách bảo mật, và CI/CD tự động đẩy ứng dụng lên cụm. Các dịch vụ thuộc dự án ADN được đưa lên nền tảng này để tối ưu đường truyền và khả năng sẵn sàng.
Deployed and configured OpenShift clusters for the BCA dev/test environment and our internal one, then ran it as a real container platform rather than a demo cluster: routing, load balancing, security policy, and CI/CD that deploys onto the cluster automatically. The ADN project services were moved onto this platform to improve traffic handling and availability.
OpenShift · Kubernetes · CI/CD · Định tuyến & cân bằng tảiRouting & load balancing
-
PRJ-03
Pipeline DevSecOps có cổng quét lỗ hổngDevSecOps pipeline with an automated scan gate
DevSecOps Engineer
Thiết kế và triển khai pipeline CI/CD có bảo mật nằm bên trong, không phải một bước kiểm tra dán thêm ở cuối. Acunetix và Nessus chạy tự động sau mỗi lần build và deploy; kết quả được phân tích và gắn cảnh báo khi phát hiện lỗ hổng.
Điểm được nhất của dự án này không phải là công cụ — mà là vị trí của nó. Khi cổng quét nằm giữa build và deploy, lỗ hổng bị bắt trong SDLC, lúc còn rẻ để sửa và chưa ai ở ngoài nhìn thấy.
Designed and shipped a CI/CD pipeline with security inside it, not as a check bolted on at the end. Acunetix and Nessus run automatically after every build and deploy; results are analysed and alerts raised when a vulnerability appears.
The best part of this project is not the tooling — it is the placement. With the scan gate sitting between build and deploy, vulnerabilities are caught inside the SDLC, while they are still cheap to fix and before anyone outside has seen them.
Jenkins · Acunetix · Nessus · Cảnh báo tự độngAutomated alerting
-
PRJ-04
Hạ tầng CNTT doanh nghiệpEnterprise IT infrastructure
System / Network Engineer
Triển khai trọn gói mạng, tường lửa và cụm máy chủ cho doanh nghiệp. Fortigate lo NAT, VPN và policy; lớp mạng chia VLAN với định tuyến và chuyển mạch tương ứng; cụm máy chủ dựng theo hướng sẵn sàng cao để một máy hỏng không kéo theo cả dịch vụ. Giám sát và log được tích hợp ngay từ đầu — bổ sung sau thì luôn thiếu đúng khoảng thời gian mình cần nhìn lại.
Deployed enterprise IT infrastructure end to end: network, firewall and server cluster. Fortigate handles NAT, VPN and policy; the network layer is split into VLANs with matching routing and switching; the server cluster is built for high availability so one failed machine does not take the service with it. Monitoring and logging were integrated from the start — added afterwards, they are always missing exactly the window you need to look back at.
Fortigate · VLAN · Định tuyến & chuyển mạchRouting & switching · Cụm sẵn sàng caoHA cluster
Kỹ năngSkills
Xếp từ dưới lên, đúng thứ tự đã đi: hạ tầng trước, bảo mật sau. Cột bằng chứng đếm số vai trò và dự án ở § 03 và § 04 có chạm tới miền đó — không có thang tự chấm điểm. Ordered bottom-up, in the order actually travelled: infrastructure first, security last. The evidence column counts the roles and projects in § 03 and § 04 that touch each domain — no self-rated scale.
| MiềnDomain | Nội dungContent | Bằng chứngEvidence |
|---|---|---|
| Hệ thống & Hạ tầngSystems & Infrastructure | Windows Server · Linux · VMware / Hyper-V · HCI · SAN/NAS · máy chủ on-premon-prem servers | 2 vai trò · 3 dự án2 roles · 3 projects |
| MạngNetworking | CCNA · TCP/IP · VLAN · định tuyến & chuyển mạchrouting & switching · Fortinet Security Fabric | 3 vai trò · 3 dự án3 roles · 3 projects |
| DevOps & Tự động hoáDevOps & Automation | Jenkins · GitLab CI/CD · Docker · OpenShift / Kubernetes · Bash · Python · SonarQube | 1 vai trò · 3 dự án1 role · 3 projects |
| Bảo mậtSecurity | IBM QRadar · Splunk · Wazuh · Acunetix · Nessus · OWASP Top 10 · DLP · ISO/IEC 27001 | 3 vai trò · 3 dự án3 roles · 3 projects |
Chứng chỉ & Học vấnCredentials & Education
- AWS Certified DevOps Engineer – Professional
- Google Cybersecurity
- Chuyên viên đánh giá nội bộ — ISO 9001 & ISO 27001 Internal auditor — ISO 9001 & ISO 27001
Học vấnEducation
Kỹ sư An toàn thông tinEngineer, Information Security
Học viện Kỹ thuật Mật mãAcademy of Cryptography Techniques
—
Liên hệContact
- doanhkma.work@gmail.com
- Điện thoạiPhone
- 0347 731 898
- facebook.com/q.doanhkma
- Nơi ởBased in
- Thanh Trì, Hà NộiThanh Tri, Hanoi, Vietnam
Ghi chú kỹ thuậtColophon
Trang này cũng là một mẫu việc. Mọi câu dưới đây đều kiểm chứng được bằng curl -I.
This page is also a work sample. Every claim below is verifiable with curl -I.
- Xây dựngBuild
- HTML/CSS/JS viết tay. Không framework, không bước build, không phụ thuộc lúc chạy.Hand-written HTML/CSS/JS. No framework, no build step, no runtime dependencies.
- ChữType
- Source Serif 4 · IBM Plex Sans · IBM Plex Mono. Tự chứa, đã cắt về bộ ký tự ASCII + tiếng Việt.Self-hosted, subset to ASCII + Vietnamese.
- Chạy trênRuntime
- nginx không đặc quyền trong Docker (uid 101), rootfs chỉ đọc, bỏ toàn bộ capability.Unprivileged nginx in Docker (uid 101), read-only rootfs, all capabilities dropped.
- Truyền tảiTransport
- TLS 1.2/1.3, chứng chỉ Let's Encrypt (ECDSA), HSTS một năm.TLS 1.2/1.3, Let's Encrypt certificate (ECDSA), one-year HSTS.
- CSP
default-src 'self'— không script ngoài, không style ngoài, không CDN, khôngunsafe-inline.no third-party scripts, styles or CDNs, and nounsafe-inline.- Theo dõiTracking
- Không có. Không analytics, không cookie, không gọi ra ngoài.None. No analytics, no cookies, no outbound calls.