Sitemap
Petru Lucian Giurca
Petru Lucian Giurca
he/him

πŸ‘·β€β™‚οΈ Senior Security Professional with 15+ years of experience transitioning from Tier-1 DevSecOps to Smart Contract Security Auditing. Fluent in English, Spanish and Italian.

ο»Ώ

πŸ› οΈ Core Technical Stack (Consolidated Matrix):

βœ… Web3 / Smart Contract Security: Solidity, EVM, smart-contract auditing, Slither, Foundry, fuzzing harnesses, MEV, flash loans, oracle manipulation.

βœ… DevSecOps & CI/CD: GitHub, GitHub Actions, GitLab CI, Jenkins, Azure DevOps, ArgoCD, Atlassian Bamboo, GitOps, ALM, SDLC security, code review.

βœ… Container Platforms & Orchestration: Red Hat OpenShift (S2I, CoreOS, oc, Operators), Kubernetes, Helm, Istio (service mesh), Kafka (Strimzi), Docker, Red Hat OpenStack.

βœ… Application Security: SAST, DAST (OWASP ZAP), SCA (OWASP Dependency-Check, Trivy, Dependabot), OWASP SAMM, NIST SSDF, SBOM (Syft), supply-chain security (Sigstore/cosign), Falco, HashiCorp Vault, SonarQube.

βœ… Cloud & IaC: Azure, AWS (EKS, Lambda, CloudFormation), GCP (GKE), Terraform, Ansible, Puppet, Kyverno / OPA Gatekeeper.

βœ… Observability & SIEM: Prometheus, Grafana, Alertmanager, Splunk Enterprise Security, Microsoft Sentinel, Microsoft Defender.

βœ… Databases: MS SQL Server, MySQL, Postgres, MongoDB.

βœ… Standards & Compliance: ISO/IEC 27001, ISO/IEC 22301, ISO/IEC 31000, PCI-DSS 4.0, NIST, CIS, GDPR, NIS 2.

ο»Ώ

✨ Profesional Experience ✨

πŸš€ Web3 Security Researcher, HCLTech (Financial Intermediaries) β€” Bucharest, May 2023 – Present

β€’ Conduct adversarial security research on Ethereum / EVM smart-contract systems (Solidity), identifying criticalvulnerability classes across pre-deployment and production codebases.

β€’ Apply static and dynamic analysis (Slither, Foundry, custom fuzzing harnesses) and produce reproducible proof-of-concept exploits with severity classification and remediation guidance.

β€’ Analyze code and communicate review findings to protocol engineering teams, embedding secure developmentpatterns throughout the SDLC.

β€’ Build internal security tooling and automation to scale vulnerability discovery and standardize research methodology.

ο»Ώ

πŸš€ DevSecOps Expert (Deutsche Bank UK), HCLTech β€” Bucharest, Oct 2022 – Apr 2023

β€’ Operated enterprise Kubernetes clusters for deployment and scaling of containerized banking applications, ensuringhigh availability and zero-downtime rolling updates across Production and DR environments.

β€’ Designed and maintained complete CI/CD pipelines using GitHub Actions (multi-stage, reusable workflows, matrixbuilds) for Java Spring Boot (Maven) and Rust (Cargo + musl) microservices, integrating security gates automatically.

β€’ Integrated SAST across Java and Rust codebases and DAST using OWASP ZAP (baseline, active scan, API scripting)directly in pipelines, with fail-fast enforcement and automated reporting to the security team.

β€’ Configured SCA for Maven and Cargo dependencies (OWASP Dependency-Check, Trivy, Dependabot) with automaticblocking of vulnerable artifacts (CVSS β‰₯ 7.0).

β€’ Developed modular Infrastructure-as-Code with Terraform (remote state in S3 + DynamoDB) for Kubernetes clusters,VPC networking, ingress-nginx, cert-manager, and policy enforcement (Kyverno / OPA Gatekeeper).

β€’ Implemented container and Kubernetes hardening: image scanning (Trivy / Grype), Pod Security Admission, NetworkPolicies, RBAC, External Secrets Operator + HashiCorp Vault, and runtime protection with Falco.

β€’ Advanced DevSecOps maturity to an β€œAdvanced” level per OWASP SAMM and NIST SSDF, including policy-as-code,supply-chain security (Sigstore/cosign), and SBOM generation (Syft).

β€’ Ensured compliance with banking standards (PCI-DSS 4.0, ISO 27001, GDPR, National Bank requirements) through automated reporting, evidence collection, and full audit trails.

ο»Ώ

πŸš€ DevSecOps Engineer (UniCredit S.p.A., Italy), Axsys Romania β€” Bucharest, Mar 2022 – Sep 2022

β€’ Built and administered private-cloud infrastructure on Red Hat OpenStack and deployed containerized workloads via Red Hat OpenShift, creating and managing pods and clusters across the platform.

β€’ Packaged and deployed applications to OpenShift using Helm charts, standardizing templated, versioned releases across environments.

β€’ Deployed and configured Istio service mesh for secure service-to-service communication (mTLS), traffic management, and observability across microservices.

β€’ Managed OpenShift / OpenStack node lifecycle on Red Hat Enterprise Linux (RHEL) and CoreOS, including OS patching, user access controls (PAM / sudoers), and kernel-parameter tuning for high-performance private-cloud networking.

β€’ Secured the container ecosystem at the Linux-kernel level β€” configuring cgroups and namespaces for strict process isolation and auditing file permissions to prevent privilege escalation on host nodes.

β€’ Led DevSecOps activities across vulnerability scanning, certificate management, password-policy management, and remediation/patching coordination.

β€’ Analyzed code and communicated code-review findings to development teams; enforced shift-left compliance for the Spring Boot stack via Maven-integrated SCA in Jenkins pipelines, blocking vulnerable transitive dependencies before packaging.

ο»Ώ

πŸš€ Senior DevOps Engineer (LEGO Group, Denmark), Arnia Software β€” Bucharest, Sep 2021 – Feb 2022

β€’ Managed the lifecycle of OpenShift clusters, ensuring seamless upgrades and patching of the underlying CoreOS nodes.

β€’ Optimized the developer experience with OpenShift Source-to-Image (S2I) workflows, letting teams push code directly from Git while OpenShift built secure, versioned container images β€” streamlining code-commit to deployment without complex Dockerfile management.

β€’ Managed application deployments with Helm charts, enabling repeatable, parameterized releases across OpenShift environments.

β€’ Provisioned Azure infrastructure with Terraform and Ansible, writing reusable, well-tested infrastructure code.

β€’ Designed and maintained SIEM use cases within Splunk ES, focusing on high-fidelity alerting and compliance reporting.

β€’ Worked with AWS services (EKS, CloudFormation, CloudWatch, Lambda, API Gateway, Aurora) and monitoring stacks (Prometheus, Grafana).

ο»Ώ

πŸš€ DevSecOps Specialist (Nordic RSC, Denmark), GE Digital β€” Bucharest, Jul 2019 – Aug 2021

β€’ Developed and maintained backend services in Go (net/http, gRPC/REST APIs), handling high concurrency, request routing, and robust error handling.

β€’ Maintained critical backend components for Longhorn and the Kubernetes CSI storage provider in Go, focusing on high availability volume attach/detach/recovery workflows and CSI compliance.

β€’ Built observability into all services with Prometheus (client_golang), distributed tracing, and structured logging.

β€’ Operated Kafka (via Strimzi) on Kubernetes to support event-driven microservice architectures, and integrated SonarQube quality gates into Maven pipelines for Quarkus / JBoss services.

β€’ Managed ingestion, normalization, and correlation of security data into Microsoft Sentinel; conducted threat hunting and tuned automated investigation and response via Microsoft Defender.

β€’ Embedded shift-left security into Spring Boot microservices via Maven build profiles triggering SAST and SCA during compilation, before artifacts reached the Nexus Repository.

β€’ Architected multi-stage Azure DevOps YAML pipelines with mandatory security gates (SAST, secret scanning, dependency checks) deploying to Azure Kubernetes Service (AKS).

β€’ Performed security risk assessments and application/network vulnerability scanning; mentored team members and drove security awareness across the organization.

ο»Ώ

πŸš€ IT System Engineer / Cloud Engineer, BullGuard β€” Bucharest, Apr 2018 – Jun 2019

β€’ Served as Cloud Engineer for a global B2C cybersecurity vendor, migrating critical backend infrastructure to Microsoft Azure and adopting modern DevOps practices.

β€’ Provided architectural recommendations to improve efficiency, reliability, and performance while reducing cost.

β€’ Deployed Prometheus and Grafana for advanced monitoring, enabling proactive resolution of performance bottlenecks.

β€’ Contributed to Agile ceremonies and collaborated with architects to define secure, scalable enterprise cloud products.

ο»Ώ

πŸš€ Linux System Administrator, StarTechTeam β€” Bucharest, Apr 2014 – Mar 2018

β€’ Administered a complex RHEL6 environment, performing kernel upgrades, security patching, and driver integration to ensure 99.9% availability.

β€’ Managed VMware ESXi virtualization (VM lifecycle, snapshots, resource allocation) and improved the virtualization stack.

β€’ Used Puppet for configuration management to enforce desired state and compliance across systems.

β€’ Executed backup/restore procedures and monitored system health to ensure business continuity.

ο»Ώ

πŸš€ Help Desk Support Specialist (Italian), Genpact β€” Bucharest, Jan 2009 – Mar 2014

β€’ Managed the end-to-end incident lifecycle for complex telecom faults (VoIP, MPLS, Fiber), bridging enterprise clients and T3 network engineers.

β€’ Resolved T1/T2 technical and product support inquiries via ticketing, live chat, and phone; escalated and tracked faults through resolution.

ο»Ώ

✨ Education ✨

Master's Degree, Law Spiru Haret University, Bucharest | 2008 – 2010

Bachelor's Degree, Law Spiru Haret University, Bucharest | 2004 – 2008

ο»Ώ

✨ Certifications ✨

Web3 & Blockchain

Cloud & DevSecOps

AI & Data

ο»Ώ

ο»Ώ

Medium member since August 2026
Petru Lucian Giurca

Petru Lucian Giurcahe/him

Senior Security Professional with 15+ years of experience transitioning from Tier-1 DevSecOps to Smart Contract Security Auditing.