Hi, my name is

Yehualashet.

I build secure, automated systems.

Full-stack software engineer specializing in production-grade backends, SOAR security automation, and DevSecOps pipelines. I architect systems that are tested, containerized, and designed to scale.

About Me

I am a full-stack software engineer with a relentless focus on building production-grade systems that are secure by default, thoroughly tested, and designed for long-term maintainability. My stack spans Django REST APIs, React frontends, and containerized infrastructure — all held together by engineering discipline.

In my security automation work I build SOAR platforms that replace manual incident triage with fast, deterministic, auditable workflows. Security is not a feature I add — it is an architectural property I enforce from the first commit.

I practice TDD across every layer, ship reproducible Docker environments, and enforce coverage gates in CI. Nothing deploys broken on my watch.

I am expanding into DevSecOps, AI evaluation tooling, and cloud-native architectures — investing in technologies that compound engineering capability over time.

TECH I REACH FOR

  • Python / Django
  • React / Next.js
  • Docker / Compose
  • GitHub Actions
  • PostgreSQL
  • Security Onion

Skills

⚙️

Backend Engineering

  • Python
  • Django
  • Django REST Framework
  • REST API Design
  • PostgreSQL
  • Celery
🖥️

Frontend Engineering

  • React
  • JavaScript (ES6+)
  • TypeScript
  • HTML5 / CSS3
  • Responsive Design
🔒

Security & Automation

  • SOAR Platforms
  • Security Workflow Automation
  • Incident Response Systems
  • Threat Detection Pipelines
🧪

Testing & Quality Engineering

  • Unit Testing
  • Integration Testing
  • End-to-End Testing
  • Test-Driven Development
  • Pytest / Selenium / Playwright
🚀

DevOps & CI/CD

  • Docker
  • Docker Compose
  • GitHub Actions
  • GitLab CI/CD
  • Infrastructure as Code
🔮

Emerging Focus

  • DevSecOps
  • AI Systems & Evaluation Tooling
  • Cloud Computing
  • Distributed Systems
  • Quantum Computing Fundamentals

Projects

01

SOAR Incident Response Platform

PROBLEM

Security teams faced slow, manual incident triage across disparate tools, leading to delayed threat containment and inconsistent response procedures.

ARCHITECTURE

Event-driven microservice architecture with a Django orchestration layer consuming webhook events from SIEM/EDR sources, dispatching playbook actions through a task queue, and persisting audit trails to PostgreSQL.

SECURITY & TESTING

Role-based access control on all endpoints. Full integration test suite covering playbook execution paths. Secrets managed via environment injection — zero hardcoded credentials.

PythonDjangoCeleryPostgreSQLDockerREST API
02

Full-Stack DevSecOps Dashboard

PROBLEM

Engineering leadership lacked a unified view of pipeline health, vulnerability scan results, and deployment status across multiple repositories and environments.

ARCHITECTURE

React SPA backed by a Django REST API. GitHub Actions and GitLab CI/CD webhooks feed pipeline metrics into the backend. Real-time updates delivered via WebSocket channels.

SECURITY & TESTING

OWASP dependency scanning integrated into CI. CSRF and XSS protections enforced server-side. End-to-end tests validate dashboard rendering under various permission levels.

ReactTypeScriptDjango REST FrameworkWebSocketsGitHub ActionsDocker
03

Automated Security Tool Orchestrator

PROBLEM

Security engineers manually executed and correlated output from multiple scanning tools (Nmap, Nikto, OWASP ZAP), wasting hours per assessment cycle.

ARCHITECTURE

CLI-driven Python framework that orchestrates scanning tools in parallel, normalizes output into a unified JSON schema, and generates consolidated PDF reports. Packaged as a Docker image for reproducible execution.

SECURITY & TESTING

Input sanitization on all user-supplied targets. Sandboxed execution within Docker containers. Unit tests cover parser logic for each supported tool's output format.

PythonDockerClick CLIJinja2JSON Schema
04

E2E Test Infrastructure Framework

PROBLEM

QA cycles were bottlenecked by flaky, poorly structured test suites that provided low confidence in release readiness and slowed deployment cadence.

ARCHITECTURE

Layered test framework following the Page Object Model pattern. Shared fixtures and factories ensure reproducible state. Integrated with CI pipelines for automated regression on every pull request.

SECURITY & TESTING

Test data generated via factories — no production data in test environments. CI secrets rotated on schedule. Coverage reports enforced as merge-gate thresholds.

PythonPytestSeleniumPlaywrightGitHub ActionsDocker Compose

Engineering Principles

🛡️

Secure by Design

Security is an architectural property, not a bolt-on feature. Least privilege, secrets management, and defense-in-depth enforced from commit one.

Automation-First

If a process runs more than once, it gets automated. CI/CD pipelines, incident playbooks, and testing suites eliminate toil systematically.

🧪

Test-Driven Development

Tests before implementation. Unit, integration, and E2E layers provide confidence. Coverage gates enforce quality at merge time.

🚀

CI/CD Reliability

Every commit triggers build, test, and deploy. Infrastructure is codified, environments reproducible, deployments deterministic.

🌐

Scalable Architecture

Clean boundaries, separation of concerns, and horizontal scalability — systems ready to grow without rewrites.

🔭

Compound Learning

I invest in technologies that compound: DevSecOps, AI evaluation tooling, cloud-native patterns, and quantum computing fundamentals.

Get In Touch

WHAT'S NEXT?

Let's Build Something Together

Whether you have a project needing a strong engineering foundation, a security automation challenge, or just want to connect — my inbox is always open.

Say Hello