Kỹ sư hạ tầng & vận hànhInfrastructure & operations engineer

Chẩu Đình Doanh

DevOps EngineerDevSecOps Engineer

Tôi dựng hạ tầng, giữ cho nó chạy, và làm nó khó bị phá hơn. Tôi bắt đầu ở ca trực SOC đọc cảnh báo QRadar; giờ tôi làm ở phía bên kia của cảnh báo — cụm OpenShift, pipeline Jenkins, và những cổng quét chặn một bản build hỏng trước khi nó kịp ra production.

I build infrastructure, keep it running, and make it harder to break into. I started on a SOC shift reading QRadar alerts; now I work on the other side of the alert — OpenShift clusters, Jenkins pipelines, and scan gates that stop a bad build before it reaches production.

PDF, 2 trang, tiếng Việt · 312 KB PDF, 2 pages, in Vietnamese · 312 KB

Chẩu Đình Doanh
Ảnh thẻ · trích từ CVID photo · from the CV

Tóm tắtSummary

Kinh nghiệmExperience
5+ nămyears
Vai tròRoles
3
Chứng chỉ chínhLead credential
AWS DevOps Pro
Quản trịGovernance
ISO 27001 IA

Định hướngDirection

Mục tiêu là làm DevSecOps Engineer: đưa bảo mật vào bên trong đường ống thay vì dán thêm ở cuối. Hai hướng tôi đang đi sâu — Security OperationsCloud Security — đều nối tiếp việc đã làm, không phải bắt đầu lại từ đầu.

Điều tôi mang theo từ phòng SOC là một thói quen cụ thể: hỏi “nếu hỏng thì mình biết bằng cách nào” trước khi hỏi “bao giờ xong”. Hạ tầng tự động hoá được mà không quan sát được thì chỉ là hỏng nhanh hơn.

The goal is to work as a DevSecOps Engineer: put security inside the pipeline rather than bolting it on at the end. The two areas I am going deeper on — Security Operations and Cloud Security — continue what I already do rather than starting over.

What I took from the SOC floor is one concrete habit: ask “how would we know if this broke” before asking “when will it ship”. Infrastructure you can automate but cannot observe just fails faster.

Kinh nghiệmExperience

Ba vai trò, xếp từ gần nhất.Three roles, most recent first.

  1. naypresent

    42 thángmonths

    đang làmcurrent

    IT Manager & DevOps

    Công ty Cổ phần Công nghệ VISSOFT

    Vai trò rộng nhất tới giờ: vừa giữ hạ tầng on-prem chạy được — máy chủ, mạng, lưu trữ — vừa dựng phần DevOps cho đội phát triển. Tôi dựng và duy trì bộ công cụ (Jira, Confluence, GitLab, SonarQube) rồi đặt pipeline Jenkins vào giữa chúng, để việc kiểm tra chất lượng và bảo mật xảy ra tự động chứ không phụ thuộc vào ai nhớ chạy.

    Phần bảo mật là chỗ tôi dành nhiều thời gian nhất: Wazuh để phát hiện bất thường ở tầng host, Splunk để gom và phân tích tập trung, quét lỗ hổng định kỳ, và tham gia áp chính sách theo ISO/IEC 27001:2022. Chính phần ISO dạy tôi điều mà công cụ không dạy được — bảo mật là bằng chứng và quy trình, không chỉ là một dashboard màu xanh.

    The broadest role so far: keeping on-premise infrastructure alive — servers, network, storage — while building out the DevOps side for the development team. I set up and maintain the toolchain (Jira, Confluence, GitLab, SonarQube) and put Jenkins pipelines between them, so quality and security checks run automatically instead of depending on someone remembering to run them.

    Security is where most of my time goes: Wazuh for host-level anomaly detection, Splunk for centralised collection and analysis, periodic vulnerability scanning, and contributing to ISO/IEC 27001:2022 policy adoption. The ISO work taught me the thing tools cannot — security is evidence and process, not just a green dashboard.

    • ci/cdJenkins, GitLab CI/CD, SonarQube
    • cloudQuản trị hệ thống AWSAWS system administration
    • secWazuh (IDS) · Splunk (SIEM) · quét lỗ hổng định kỳperiodic vulnerability scanning
    • govISO/IEC 27001:2022
    • infraMáy chủ on-prem, mạng, lưu trữOn-prem servers, network, storage
  2. 5 thángmonths

    SOC Tier 1

    Công ty Cổ phần TVAT Việt Nam

    Quãng ngắn nhất trong hồ sơ, và là quãng đổi cách tôi nhìn hệ thống nhiều nhất. Khi phải phân loại cảnh báo QRadar theo ca trực, người ta thôi coi log là thứ sinh ra sau sự cố và bắt đầu coi nó là thứ phải thiết kế trước. Tôi cũng tham gia viết playbook xử lý sự cố — tài liệu để người trực ca sau không phải đoán lại từ đầu.

    The shortest entry here, and the one that changed how I look at systems the most. Once you are triaging QRadar alerts on shift, you stop treating logs as something produced after an incident and start treating them as something to design before one. I also helped write incident-response playbooks — documents so that whoever takes the next shift does not have to guess.

    • secGiám sát & xử lý sự cố an ninh mạngSecurity monitoring & incident handling
    • secPhân tích log và cảnh báo trên IBM QRadarLog and alert analysis on IBM QRadar
    • netFortinet Security Fabric (NSE4)
    • govPlaybook xử lý sự cố ATTTInformation-security incident playbooks
  3. 14 thángmonths

    Network / System Engineer

    ETC Technology Systems Jsc

    Công việc đầu tiên, và là chỗ tôi học cách một hệ thống doanh nghiệp thực sự được nối với nhau. Tôi triển khai và cấu hình hạ tầng mạng ở mức CCNA, vận hành hệ thống, và lần đầu chạm vào thiết bị bảo mật thật: Fortinet Firewall trong kiến trúc Security Fabric, và IBM QRadar — lúc đó còn ở vai người đọc log, chưa phải người điều tra.

    My first job, and where I learned how an enterprise system is actually wired together. I deployed and configured network infrastructure at CCNA level, ran systems, and first touched real security equipment: Fortinet Firewall inside a Security Fabric architecture, and IBM QRadar — at that point as someone reading the logs, not yet investigating them.

    • netTriển khai & cấu hình hệ thống mạng (CCNA)Network deployment & configuration (CCNA level)
    • netFortinet Firewall · Security Fabric
    • secIBM QRadar (SIEM)
    • infraQuản trị và hỗ trợ vận hành hạ tầngInfrastructure administration & operations support

Dự ánProjects

Mỗi sơ đồ vẽ đúng hình dạng hệ thống đã dựng — không phải hình minh hoạ. Each schematic draws the actual shape of the system built — not an illustration.

  1. PRJ-01

    Hạ tầng ứng dụng trên AWSApplication infrastructure on AWS

    DevOps Engineer

    Dựng hạ tầng chạy ứng dụng trên AWS: VPC phân vùng công khai / riêng tư, EC2 ở vùng riêng, IAM cấp quyền theo nguyên tắc tối thiểu, security group siết theo từng tầng thay vì mở một lần cho tiện. Sau khi hệ thống chạy ổn thì quay lại tối ưu chi phí và hiệu năng — phần việc ít được nhắc tới nhưng quyết định hạ tầng có sống lâu được hay không.

    Built the AWS infrastructure an application runs on: a VPC split into public and private subnets, EC2 in the private tier, IAM granted on least-privilege lines, and security groups tightened per tier rather than opened once for convenience. Once it was stable I went back for cost and performance tuning — the unglamorous part that decides whether infrastructure survives.

    Sơ đồ: VPC chứa subnet công khai và subnet riêng tư với EC2, kèm IAM và security group VPC public subnet EC2 private security group IAM

    AWS EC2 · VPC · IAM · Security Group

  2. PRJ-02

    Cụm OpenShift & dịch vụ dự án ADNOpenShift cluster & ADN project services

    DevOps / Platform Engineer

    Triển khai và cấu hình cụm OpenShift cho môi trường dev/test của BCA và dev/test nội bộ, rồi vận hành nó như một nền tảng container thật chứ không phải một cụm demo: routing, cân bằng tải, chính sách bảo mật, và CI/CD tự động đẩy ứng dụng lên cụm. Các dịch vụ thuộc dự án ADN được đưa lên nền tảng này để tối ưu đường truyền và khả năng sẵn sàng.

    Deployed and configured OpenShift clusters for the BCA dev/test environment and our internal one, then ran it as a real container platform rather than a demo cluster: routing, load balancing, security policy, and CI/CD that deploys onto the cluster automatically. The ADN project services were moved onto this platform to improve traffic handling and availability.

    Sơ đồ: lưu lượng vào qua router và cân bằng tải, phân xuống ba node worker của cụm OpenShift ingress router load balance node node node worker plane

    OpenShift · Kubernetes · CI/CD · Định tuyến & cân bằng tảiRouting & load balancing

  3. PRJ-03

    Pipeline DevSecOps có cổng quét lỗ hổngDevSecOps pipeline with an automated scan gate

    DevSecOps Engineer

    Thiết kế và triển khai pipeline CI/CD có bảo mật nằm bên trong, không phải một bước kiểm tra dán thêm ở cuối. Acunetix và Nessus chạy tự động sau mỗi lần build và deploy; kết quả được phân tích và gắn cảnh báo khi phát hiện lỗ hổng.

    Điểm được nhất của dự án này không phải là công cụ — mà là vị trí của nó. Khi cổng quét nằm giữa build và deploy, lỗ hổng bị bắt trong SDLC, lúc còn rẻ để sửa và chưa ai ở ngoài nhìn thấy.

    Designed and shipped a CI/CD pipeline with security inside it, not as a check bolted on at the end. Acunetix and Nessus run automatically after every build and deploy; results are analysed and alerts raised when a vulnerability appears.

    The best part of this project is not the tooling — it is the placement. With the scan gate sitting between build and deploy, vulnerabilities are caught inside the SDLC, while they are still cheap to fix and before anyone outside has seen them.

    Sơ đồ: commit tới build tới cổng quét lỗ hổng; đạt thì deploy, không đạt thì rẽ nhánh sang cảnh báo commit build scan deploy Acunetix · Nessus alert fail pass

    Jenkins · Acunetix · Nessus · Cảnh báo tự độngAutomated alerting

  4. PRJ-04

    Hạ tầng CNTT doanh nghiệpEnterprise IT infrastructure

    System / Network Engineer

    Triển khai trọn gói mạng, tường lửa và cụm máy chủ cho doanh nghiệp. Fortigate lo NAT, VPN và policy; lớp mạng chia VLAN với định tuyến và chuyển mạch tương ứng; cụm máy chủ dựng theo hướng sẵn sàng cao để một máy hỏng không kéo theo cả dịch vụ. Giám sát và log được tích hợp ngay từ đầu — bổ sung sau thì luôn thiếu đúng khoảng thời gian mình cần nhìn lại.

    Deployed enterprise IT infrastructure end to end: network, firewall and server cluster. Fortigate handles NAT, VPN and policy; the network layer is split into VLANs with matching routing and switching; the server cluster is built for high availability so one failed machine does not take the service with it. Monitoring and logging were integrated from the start — added afterwards, they are always missing exactly the window you need to look back at.

    Sơ đồ: Internet qua tường lửa Fortigate, xuống lớp chuyển mạch VLAN, tới cụm máy chủ sẵn sàng cao internet Fortigate NAT·VPN VLAN server server cluster · HA

    Fortigate · VLAN · Định tuyến & chuyển mạchRouting & switching · Cụm sẵn sàng caoHA cluster

Kỹ năngSkills

Xếp từ dưới lên, đúng thứ tự đã đi: hạ tầng trước, bảo mật sau. Cột bằng chứng đếm số vai trò và dự án ở § 03 và § 04 có chạm tới miền đó — không có thang tự chấm điểm. Ordered bottom-up, in the order actually travelled: infrastructure first, security last. The evidence column counts the roles and projects in § 03 and § 04 that touch each domain — no self-rated scale.

Bảng kỹ năng theo miền, kèm số vai trò và dự án làm bằng chứng Skills by domain, with the number of roles and projects as evidence
MiềnDomain Nội dungContent Bằng chứngEvidence
Hệ thống & Hạ tầngSystems & Infrastructure Windows Server · Linux · VMware / Hyper-V · HCI · SAN/NAS · máy chủ on-premon-prem servers 2 vai trò · 3 dự án2 roles · 3 projects
MạngNetworking CCNA · TCP/IP · VLAN · định tuyến & chuyển mạchrouting & switching · Fortinet Security Fabric 3 vai trò · 3 dự án3 roles · 3 projects
DevOps & Tự động hoáDevOps & Automation Jenkins · GitLab CI/CD · Docker · OpenShift / Kubernetes · Bash · Python · SonarQube 1 vai trò · 3 dự án1 role · 3 projects
Bảo mậtSecurity IBM QRadar · Splunk · Wazuh · Acunetix · Nessus · OWASP Top 10 · DLP · ISO/IEC 27001 3 vai trò · 3 dự án3 roles · 3 projects

Chứng chỉ & Học vấnCredentials & Education

  • AWS Certified DevOps Engineer – Professional
  • Google Cybersecurity
  • Chuyên viên đánh giá nội bộ — ISO 9001 & ISO 27001 Internal auditor — ISO 9001 & ISO 27001

Học vấnEducation

Kỹ sư An toàn thông tinEngineer, Information Security

Học viện Kỹ thuật Mật mãAcademy of Cryptography Techniques

Liên hệContact

Email
doanhkma.work@gmail.com
Điện thoạiPhone
0347 731 898
Facebook
facebook.com/q.doanhkma
Nơi ởBased in
Thanh Trì, Hà NộiThanh Tri, Hanoi, Vietnam

Tải CV (PDF)Download CV (PDF)

Ghi chú kỹ thuậtColophon

Trang này cũng là một mẫu việc. Mọi câu dưới đây đều kiểm chứng được bằng curl -I. This page is also a work sample. Every claim below is verifiable with curl -I.

Xây dựngBuild
HTML/CSS/JS viết tay. Không framework, không bước build, không phụ thuộc lúc chạy.Hand-written HTML/CSS/JS. No framework, no build step, no runtime dependencies.
ChữType
Source Serif 4 · IBM Plex Sans · IBM Plex Mono. Tự chứa, đã cắt về bộ ký tự ASCII + tiếng Việt.Self-hosted, subset to ASCII + Vietnamese.
Chạy trênRuntime
nginx không đặc quyền trong Docker (uid 101), rootfs chỉ đọc, bỏ toàn bộ capability.Unprivileged nginx in Docker (uid 101), read-only rootfs, all capabilities dropped.
Truyền tảiTransport
TLS 1.2/1.3, chứng chỉ Let's Encrypt (ECDSA), HSTS một năm.TLS 1.2/1.3, Let's Encrypt certificate (ECDSA), one-year HSTS.
CSP
default-src 'self'không script ngoài, không style ngoài, không CDN, không unsafe-inline.no third-party scripts, styles or CDNs, and no unsafe-inline.
Theo dõiTracking
Không có. Không analytics, không cookie, không gọi ra ngoài.None. No analytics, no cookies, no outbound calls.