Independent DevSecOps · AppSec · Cloud Security

Embedding security directly into fast-shipping software pipelines.

I'm Andy Truman, a DevSecOps engineer of ten-plus years, available for contract and PAYE work. I embed secure-by-default cloud infrastructure, pipeline security and threat modelling directly into fast-moving engineering teams.

CI/CD · SECURITY GATESmain →
COMMIT
SAST
SCA
DAST
IaC SCAN
DEPLOY
BUG BOUNTY
Checkov · TFLint · Snyk · OWASP ZAP · GitLeaks · HackerOnegated ✓
CORE CAPABILITIES10+ yrs
Azure & AWS Cloud DevSecOps Pipelines Serverless Infrastructure as Code Application Security Bug Bounty Programs Security Culture Container & Egress Isolation
Terraform Docker Python Bash GitHub Actions Azure DevOps Snyk OWASP ZAP Checkov TFLint GitLeaks HackerOne Cloudflare
10+ yrs
Security & DevSecOps engineering
£700m
Acquisition (Visa/Currencycloud): security posture & remediation
Shift-left
SAST, DAST & SCA scanning built directly into CI/CD pipelines
HackerOne bug bounty programs launched & run

Services

Where I plug in

Engagements are tailored directly to your engineering team's current stack and delivery goals.

Cloud

Azure & AWS security

Secure-by-default cloud architecture, least-privilege IAM, PaaS/SaaS/IaaS hardening, serverless & container estates.

Pipeline

DevSecOps & CI/CD

SAST, DAST, and SCA scanning integrated into GitHub Actions and Azure DevOps to catch vulnerabilities during pull request reviews.

IaC

Infrastructure as Code

Terraform estates designed for security from the first module, policy-checked with Checkov and TFLint in CI.

AppSec

Application security & bug bounty

HackerOne program setup and triage, Security Champions programs, vulnerability remediation that engineering teams actually buy into.

Isolation

Container & egress security

Hardened container sandboxes, egress network controls, and least-privilege scoping to safely isolate runtime workloads and developer environments.

Compliance

Culture & compliance

ISO 27001 / SOC 2 readiness, risk assessment, penetration test management, and building a blame-free security culture.

Impact Highlights

Case studies & key work

High-stakes security problems solved across enterprise acquisitions, scaling appsec programs, and workload isolation.

CASE STUDY 01 · M&A AUDIT

£700m Visa Acquisition Remediation

  • Context: Currencycloud acquisition technical due diligence.
  • Challenge: Rapidly auditing multi-cloud estates, IaC policy drift, and legacy AppSec debt under strict deadlines.
  • Solution: Automated Checkov & TFLint policy checks into CI/CD, remediated high-risk IAM policies, and standardised container builds.
✓ Cleared technical security due diligence with zero launch delays
CASE STUDY 02 · APPSEC & CULTURE

Security Champions & Bug Bounty

  • Context: Scaling security culture across Cencora engineering squads.
  • Challenge: Dev teams viewed security as a bottleneck; growing vulnerability backlog.
  • Solution: Founded Security Champions network from scratch and launched HackerOne bug bounty program with real engineering buy-in.
✓ Built developer-led triage & significantly reduced vulnerability MTTR
CASE STUDY 03 · WORKLOAD ISOLATION

Secure Container & Egress Sandboxing

  • Context: First Senior DevSecOps hire inside an AI Acceleration team.
  • Challenge: High risk of untrusted code execution and data exfiltration in rapid dev environments.
  • Solution: Designed hardened Docker sandboxes with strict network egress filtering and scoped IAM tokens.
✓ Enabled rapid innovation without exposing internal network assets

Approach

Hands-on DevSecOps engineering built for speed

I've spent ten years bridging the gap between security engineering and shipping software fast. Most recently I was the first Senior DevSecOps hire inside an AI Acceleration team, embedding secure container sandboxes, egress network boundaries, and least-privilege IAM patterns into fast-moving engineering environments.

Before that, at Cencora I chaired the Security Champions program from scratch and stood up a HackerOne bug bounty platform with real engineering buy-in. At Currencycloud I was a key contributor to hardening security posture through a £700m acquisition by Visa.

I stay hands-on through Hack The Box web exploitation labs, practical container & egress security, and deepening multi-cloud coverage across AWS & Azure. Outside of work: fingerstyle guitar, mountain biking, and a slow descent into astrophotography.

Based
Newport, Wales, UK
Availability
Remote-first; hybrid considered locally.
Clearance
SC cleared previously (lapsed), open to re-vetting
Toolbox
Terraform · Docker · Python & Bash · Snyk · OWASP ZAP · Checkov · TFLint · GitLeaks · HackerOne
Elsewhere
linkedin.com/in/andymtruman
Unblocking Security on LinkedIn

Engagement

Contract & Permanent Engagements

Through Unblocking Security I take on interim DevSecOps engineering work, and I'm separately open to permanent (PAYE) roles.

Contract / Interim

Outside IR35 (Ltd Co) & Inside IR35 Accepted
  • Day-rate DevSecOps or AppSec engineering, remote-first
  • Pipeline security build-outs, IaC estates, security audits
  • Flexible start date, scoped engagements or ongoing embed

Permanent (PAYE)

  • Full-time or part-time, remote or hybrid near Newport, Wales
  • Senior / Principal DevSecOps, Cloud Security or AppSec roles
  • Flexible start date