DevSecOps Engineer

Marcus Chen

CKA, Terraform Associate

Marcus Chen

11 years in DevOps and security automation. Builds secure CI/CD pipelines for startups and enterprise organizations. Deep expertise in Kubernetes, Terraform, and container security hardening.

DevSecOps Kubernetes CI/CD Security Container Security

Marcus Chen is a DevSecOps and Platform Security Instructor at GICCT, specialising in embedding security into the software-delivery lifecycle. He has spent his career at the intersection of development, operations, and security, helping engineering teams ship faster without sacrificing safety — and he brings that practical, build-focused perspective into the classroom.

Background and career

Marcus came up through software development and operations before security became his focus, a path that gives him genuine credibility with the engineers he now teaches and works alongside. He understands the pressures of shipping software because he has lived them, and that understanding shapes his entire approach: security that ignores how engineering teams actually work is security that will be resented and circumvented.

He has built secure delivery pipelines for high-growth technology companies, introducing the automation and practices that let teams move quickly while staying safe. He has deep, hands-on knowledge of the toolchains teams actually deploy — from GitHub Actions and Terraform to Docker and Kubernetes — and he is as comfortable debugging a failing pipeline as he is responding to a production incident.

Areas of expertise

Marcus’s expertise spans CI/CD security, container and Kubernetes hardening, infrastructure as code, and the automated security testing that catches problems before they reach production. He has particular depth in designing security into the delivery pipeline itself, so that insecure code and configurations are caught automatically rather than depending on manual review.

He is also a strong advocate for the cultural dimension of DevSecOps, which he considers more decisive than any tool. Getting security to stick in an engineering organisation is fundamentally a problem of people and incentives, and Marcus specialises in the practices that make secure choices the easy, natural choices for developers.

Teaching philosophy

Marcus teaches security as an automatic property of good engineering rather than a gate at the end of the process. His courses are intensely practical, built around real pipelines and clusters that students harden themselves. He believes that DevSecOps concepts only become real when students have automated a security check, watched it catch a genuine problem, and understood how it fits into a delivery workflow.

He champions the “shift-left” philosophy of catching issues early, when they are cheap to fix, and he teaches students to build the feedback loops that make this possible. His graduates leave able not just to use DevSecOps tools but to advocate for and implement these practices in real organisations.

A practitioner’s perspective

Marcus brings a working engineer’s realism to his teaching. He knows that security initiatives most often fail not on technical grounds but because they ignore how teams actually operate, and his courses address this directly — teaching students not only how to implement controls but how to introduce them in ways that teams will accept and maintain.

He stays current with a fast-moving field, following developments in supply-chain security, policy-as-code, and the platform-engineering movement. He shares these as practical considerations his students will encounter, helping them anticipate where the discipline is heading rather than just where it is today.

His students consistently value that he has actually done the work he teaches — that the pipelines and clusters in his labs reflect the real systems he has built and secured, not simplified classroom abstractions. This authenticity gives his teaching a credibility that resonates with the working engineers who make up much of his audience.

At GICCT

At the institute, Marcus leads the DevSecOps Engineering and Kubernetes Security programs. He is a passionate advocate for the idea that security and speed are not opposites — that done well, security automation actually accelerates delivery. For developers and operations professionals moving into security, or security professionals needing to understand modern delivery, his courses offer a bridge grounded in genuine engineering experience.

Προγράμματα που διδάσκει

DevSecOps Engineering

Kubernetes Security