OpeningLet’s talk
A dark operations room with a release pipeline and a graph on the wall screen

Case 01 · Integrity Advocate

Security at every stage.Releases in nine minutes.

How a high-traffic identity verification and proctoring platform got faster releases and wider threat coverage at the same time.

Senior DevSecOps Developer
Dec 2023 – Aug 2026 · Remote

01 · The challenge

A platform people trustwith their identity.

Integrity Advocate runs identity verification and online proctoring for high-traffic workloads on AWS. Any weakness in delivery or detection lands on real people sitting real exams.

Deploys took around 45 minutes, a new environment took a full working day to set up, and SOC 2 and GDPR evidence had to stay audit-ready at all times.

Starting point

45 min

Deploy time

45 min

Time to resolve incidents

8 h

New environment setup

Figures at the start of the engagement.

02 · Rebuilding the path

Gates atevery stage.

GitHub Actions with SonarQube and Snyk built in, automated scanning gates on every change, and Terraform across four environments.

Deploy time

9 min

Down from 45 minutes. SonarQube, Snyk and automated scanning gates run on every change, so the faster path is also the safer one.

Before · 45After · 9

Time to resolve incidents

20 min

Down from 45 minutes, with custom dashboards across the observability stack.

New environment setup

30 min

Down from 8 hours, with Terraform across sandbox, dev, staging and production.

+80%

Threat detection coverage

GuardDuty, Security Hub, Inspector, Config and Macie integrated, with security findings centralised and handled automatically.

03 · Seeing it

Every servicein view.

Custom dashboards across CloudWatch, X-Ray, Grafana, CloudTrail and VPC Flow Logs, so problems show up where people already look.

  1. Collect

    Logs, traces, flow logs and audit trails in one place.

  2. Correlate

    Dashboards organised by service, with alerts that name an owner.

  3. Respond

    Mean time to resolve cut from 45 to 20 minutes.

DashboardsCloudWatch and Grafana
ALERT · OWNER PAGED
TracesAWS X-Ray
SLOW SPAN FOUND

04 · Compliance

Audit-readywithout the scramble.

SOC 2 and GDPR enforced with Drata and Carbide, regular security audits, and documentation kept ready for an auditor at any time.

Talk about your audit

SOC 2 · GDPR · Drata · Carbide

05 · What shipped

One platform.Five layers of safety.

Pipeline
GitHub Actions with security gatesSonarQube, Snyk and automated scanning on every change
Infrastructure
Terraform in four environmentsSandbox, dev, staging and production, each set up in about 30 minutes
Detection
AWS security servicesGuardDuty, Security Hub, Inspector, Config and Macie
Compliance
SOC 2 and GDPRDrata and Carbide, regular audits, audit-ready documentation
Review
Secure code reviewNode.js and TypeScript microservices, fixed before production

On the road

The peoplebehind the platform.

Offsites, long team dinners and one very competitive night of axe throwing. A few photos from work trips with the Integrity Advocate team.

The Integrity Advocate team together for a group photo
The sea framed by a thatched roof at the team retreat
Johnson outside at night, a city skyline behind him
The team after a night of axe throwing
Morning coffee by the sea at sunrise
Johnson with teammates, arm in arm, for a team photo
Johnson on the beach during the team retreat
A team dinner, everyone cheering for the camera
Palm trees and the pool at dusk at the retreat
Johnson in an axe throwing lane, his axe in the target
The team around a dinner table on a work trip
Johnson by a canal in Amsterdam
The team in matching shirts at a company offsite
Waves rolling onto the rocky shore near the retreat
A long team dinner in a wood-panelled room
Coffee in hand, looking out over the palms to the sea

More work

More platforms.Same standards.

Pagefreezer and Neo Financial: pipelines, Kubernetes and security at scale.

Your next release

If it has to be fast,it has to be safe.

Start a conversation