avatar

Sapan Ganguly
DevSecOps / SRE / Platform Engineering

About

Senior Security Platform Architect and DevSecOps leader with 15+ years designing and operating large‑scale cloud, security, and automation platforms across AWS and Azure. Specialises in platform modernisation, Kubernetes operations at scale, cost optimisation, observability, configuration management, and DevSecOps transformation. Combines deep hands‑on engineering with proven leadership of distributed teams, delivering resilient, automated, secure infrastructure for global enterprises.

Work Experience

August 2022 – Present
Global Cyber Security Platform Engineering
Assumed responsibility for the entire operations team. Reduced the AWS bill from approximately $1M USD per month to about $600K while introducing the team to Azure and Sentinel in preparation for the new platform. Currently implementing deployment automation from scratch using Terraform, Packer, and GitLab CI/CD in Azure, with the goal of fully automating the setup of Sentinel (including resource groups, networks, playbooks, alerting rules, etc.) inside customer subscriptions via Lighthouse. I later relinquished people management and became a certified DevOps Lead.
Highlights
  • Introduced Packer for faster, repeatable Azure VM image builds and maintenance.
  • Assumed responsibility for the existing Terraform codebase.
  • Implemented CI/CD pipelines in GitLab and later in GitHub Actions.
  • Mapped concepts from AWS to Azure to ease the team's transition, e.g., Session Manager vs. Bastion.
  • Developed solutions using Logic Apps, Function Apps, and KQL.
  • Honed skills in JavaScript, JSONata, Python, and Bash scripting.
April 2018 – August 2022
European Technical Operations Manager
Assumed responsibility for the European arm of the technical operations team. In addition to creating collaboration opportunities between geographically dispersed teams, I acted as an escalation point for major issues and continued to handle hiring, development, best practices, and budgeting. I remained technical and hands-on, with Kubernetes and GitOps as main focuses. Other responsibilities included addressing issues flagged in AWS Trusted Advisor and setting up GuardDuty for the CISO team. I mentored junior team members on Git, CI/CD, and other technical tools and concepts. There is much more to this role than I could possibly write here, please ask me about it.
Highlights
  • Operated seven Kubernetes clusters across seven AWS regions, each running several hundred dissimilar pods across hundreds of namespaces. We ran a namespace per customer, with a selection of pods per namespace depending on the service options the customer purchased. The clusters were not EKS; they were self-built, requiring a deeper understanding of Kubernetes. Clusters were scaled using a regular AWS scaling group driven from a launch template built from an AMI I created using Packer, kept up to date with a GitOps pipeline. Controlling cluster size and cost was a continuous process utilizing Prometheus to inform resource request settings, which eventually led to the integration of HPA and KEDA for horizontal pod scaling. We paid special attention to anti-affinity rules to ensure pods with similar functions did not accumulate on the same node. The Kubernetes masters were also built, patched, and maintained by us.
  • Implemented CI/CD pipelines for platform components and mentored junior team members on GitOps and related technologies.
  • Encouraged the use of AWS Session Manager, eliminating the need for VPNs for sysadmin work and further reducing costs.
June 2015 – April 2018
Systems Operations and Platform Engineer
Maintained operational stability for our legacy platform while our future platform was being developed. I was responsible for hiring and running the MSS systems operations team. We were embedded within the development team and assisted with software packaging and automating deployments/releases (DevOps).
Highlights
  • Built an instance of our platform in a 'List X' environment for government departments.
  • Security cleared for work on government infrastructure.
March 2011 – June 2015
Infrastructure Architect
NTT Security is an IT security services company. I was responsible for the design, reliability, and capacity planning of the managed services infrastructure, as well as working with the software development teams. We were practicing DevOps before the term was widely adopted. I was responsible for packaging software as RPMs, which led to building a pipeline for build, test, and deploy. We used Jenkins for builds and some deployments, which later evolved into GitLab CI and Puppet.
Highlights
  • Proposed and implemented our configuration management strategy, codifying configuration for consistency, accountability, repeatability, and auditability.
  • Designed and tested system resilience strategies.
  • Productized our managed services system so it could be deployed as an 'MSS in a Box' for 'List X' clients.
July 2001 – July 2004
UNIX System Architect
Designed and maintained a UNIX system to support long-running jobs such as simulations for technology research teams.
July 1998 – July 2001
Software Consultant
Provided software consultancy and bespoke software solutions to Synstar's clients.

Awards

  • NTT Security (formerly Integralis)

    Exceptional Contribution, Integralis (NTT)

Volunteer

Birmingham Royal Institute for the Blind
July 1993 – July 1995
Technology Implementation
Implemented and maintained IT systems and specialized devices for the blind and visually impaired.

Contact

Reading, Berkshire UK

Education

  • 1995 1998

    University of Reading

    Bachelor

    Chemistry with Computer Science

Certificates

Skillsoft Percipio
2025-09-01
Integralis
2012-06-01
Integralis Leadership Academy
Skillsoft
2024-11-06
Generative AI with Azure OpenAI

Skills

Design
Resilience Reliability Continuity
Strategic Planning
Research Modernisation
Cloud Technologies
AWS Azure Sentinel Compute, Serverless, networking, automation
OS Troubleshooting, Management and Tuning
Linux Windows VMWare MacOS
Configuration Management and Orchestration Tools
Puppet Kubernetes Docker Terraform Packer DevOps DevSecOps CI/CD pipelines Git Gitlab Github Actions GitOps
Network Technology
Load balancing Peering Express Route
Monitoring, Metric Gathering and Alerting
Grafana Graphite Prometheus Kibana Telegraf Rsyslog Elasticsearch Netdata
Compliance
SOC2 SAS ISO

Interests

Technology
Exhibitions Lectures AI and self-hosted opensource LLMs Large language models Ollama

References

[on request]