Senior Backend Engineer · Go · DevSecOps / Security Platform · 13+ years
I design and build distributed backend systems and security platform tooling — from API design and data pipelines to CI/CD security gates and production operations. Deep in Go for the last 5 years, with a strong Java / Spring Boot foundation.
At CloudBees, I built 20+ security scanner plugins in Go and Java on the CloudBees Compliance platform, enforcing automated security gates across 40–60 enterprise CI/CD pipelines — 100K+ repositories scanned, 5M+ security findings processed:
- Code — Checkmarx SAST, Coverity & Polaris, Black Duck SCA, Mend SCA, Snyk IaC, Gitleaks, GoSec, FindSecBugs, njsscan
- Binary/Container — Trivy, Grype, Aqua Security, Anchore, Harbor, JFrog Xray, Snyk Container & SBOM
- Infrastructure — AWS & Kubernetes scanners, Falco, Nessus, Cloud Custodian
- Pipeline & DAST — OWASP ZAP, Veracode DAST, StackHawk
Plus: Go RBAC middleware over Keycloak/Okta · FIPS-compliant AWS migrations · gRPC microservices
Merged
- terraform-provider-aws — #48892
ena_queue_countfor launch-template NICs · docs #49017, #49003 - CloudWeGo Eino (Go LLM-agent framework) — #1149: fixed a scheduler race between
time.After(0)and task completion - postgres_exporter — #1349
In review — 30+ open PRs across security & infra tooling
- gitleaks — six secret-detection correctness fixes, e.g. #2200 (allowlist bypass), #2229
- Prometheus — relabel-drop proposal #90 · MSK discovery panic fix #19194
- also: Trivy · Grype · cloudflared · Temporal
- AWS Certified Solutions Architect – Professional (SAP-C02)
- AWS Certified Solutions Architect – Associate (SAA-C03)
- AWS Certified Cloud Practitioner (CLF-C02)
Go Java Spring Boot AWS Kubernetes Docker Terraform Prometheus Kafka gRPC PostgreSQL MongoDB Neo4j
- LinkedIn: linkedin.com/in/rajeshrajendiran
- X/Twitter: @RajChithathur
Interested in security platform engineering, software supply-chain security, cloud-native infrastructure, and observability.
