Interactive Resume Agent
🛡 Protected by Dual-Layer GuardrailsDefense Pipeline
Active1. Ingress Rate Limiting
Sliding window rate-limiter prevents Denial of Wallet (DoW) attacks.
2. Prompt Injection Filter
Heuristic regex engine intercepts jailbreak signatures before inference.
3. Hardened Gemini Core
Inference with sandboxed directives and embedded canary token.
4. Egress DLP & Canary Guard
Blocks token leaks and scrubs internal IPs & API keys from responses.
5. K8s Network Isolation
NetworkPolicy allows egress solely to Google Gemini API (port 443).
Warren David McDonald
AI DevSecOps Engineer | Kubernetes & Cloud Platform Specialist
Professional Profile
AI DevSecOps Engineer specializing in securing generative AI systems, orchestrating resilient Kubernetes infrastructure, and automating cloud-native DevSecOps pipelines. Proven expertise in hardening Google Kubernetes Engine (GKE) and AWS EKS environments, enforcing Zero-Trust workload isolation, implementing defense-in-depth LLM guardrails (OWASP Top 10 for LLMs), and codifying immutable infrastructure with Terraform.
Core Competencies
Cloud & Kubernetes
- Google Cloud Platform (GCP) & GKE
- AWS EKS & OrbStack
- Multi-tenant Cluster Isolation
- Workload Identity Federation
Security & Policy as Code
- Cilium & Calico NetworkPolicies
- Kyverno & OPA Gatekeeper
- Pod Security Standards (Restricted)
- mTLS & Zero-Trust Architecture
AI DevSecOps & Governance
- OWASP Top 10 for LLMs & GenAI
- Prompt Injection Mitigation
- Cryptographic Canary Tokens
- Egress DLP & Presidio Sanitization
CI/CD & Supply Chain
- Terraform & Infrastructure as Code
- GitHub Actions CI/CD
- Cosign / Sigstore Container Signing
- Trivy Container & IaC Vulnerability Scanning
Professional Experience
Interwell Health LLC • Lead DevOps Engineer
Aug 2022 – Jan 2026 (Recent)Led comprehensive DevOps transformation, orchestrating cloud infrastructure, Dockerizing applications, and implementing modern CI/CD pipelines in GitHub Actions. Architected and maintained highly available AWS Kubernetes clusters. Drove AWS to Azure migration with Terraform and led the implementation of Databricks in Azure for healthcare AI/ML workloads.
Workpath • Senior DevOps Engineer
Oct 2021 – Jun 2022Provisioned and managed AWS infrastructure with Terraform, Kubernetes, Fargate, and EC2. Transitioned DNS to Cloudflare, configured Pritunl VPN with VPC peering, and deployed cross-region RDS read-replicas with Prometheus/Grafana monitoring.
Synchrony • AVP, Senior DevOps Engineer
Jul 2018 – Oct 2021Managed enterprise AWS deployments using Chef/OpsWorks and Jenkins. Built hardened AMIs with Packer and Docker, implemented autoscaling policies reducing timeouts by 90% during traffic surges, and managed offshore engineering teams.
New York Media • DevOps Engineer
May 2017 – May 2018Streamlined CI/CD with CircleCI, deployed Node.js/PostgreSQL services with AWS CodeDeploy, optimized high-traffic media properties with Fastly VCL CDN, and maintained centralized ELK logging stacks.
Kenzan Media • DevOps Engineer
Apr 2016 – Apr 2017Maintained AWS environments using Terraform, built AMIs via Bamboo and Ansible, and deployed open-source observability solutions (Graylog, Netflix OSS).
Comcast • DevOps Engineer
Mar 2014 – Mar 2016Deployed Java services in Tomcat/Jetty with Splunk logging, executed Puppet Blue/Green canary deployments, and administered distributed Cassandra databases.
Education & Certifications
New Jersey Institute of Technology (NJIT)
B.S. in Information Technology • Newark, NJ
AWS Certified Developer - Associate
Verification ID: F2B4829BC24E13GF
Featured Architectural Projects
1. Fortified AI Resume Platform (warrenmac.com)
Architected and deployed an interactive portfolio and AI assistant secured against OWASP LLM vulnerabilities on Kubernetes. Implemented dual-layer guardrails featuring cryptographic canary token monitoring for prompt exfiltration prevention and real-time egress data loss prevention (DLP).
2. Zero-Trust Kubernetes AI & MCP Sandbox Platform
Engineered an isolated execution environment for AI agents and Model Context Protocol (MCP) tools using gVisor container sandboxing with Envoy-based credential redaction.
Cluster & AI Threat Telemetry
Live metrics streamed from the running Kubernetes pod