Skip to content
View h3n-x's full-sized avatar
  • Open to Global Remote Roles
  • Colombia (Worldwide Remote)
  • LinkedIn in/h3n-x

Highlights

  • Pro

Block or report h3n-x

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
h3n-x/README.md

Henry Pacheco (h3n-x) - DevOps & Systems Security Engineer

Typing Headline

Portfolio  LinkedIn  GitHub  Spanish Version

Divider

🌌 Engineering Philosophy

"Understanding systems from their kernel primitives to build resilient, hardened, and automated cloud-native pipelines."

I operate at the convergence of Linux systems engineering, runtime container security, and backend automation. My work eliminates operational fragility through predictable automation, strict policy enforcement, and reproducible architectures.

  • Core Focus: DevOps & DevSecOps Engineering, Container Runtime Security (CIS Benchmarks), Linux Kernel Hardening (cgroups, capabilities, seccomp BPF), and Automated CI/CD Quality Gates.
  • Engineering Values: Deterministic execution, zero-CVE dependencies, fail-closed design, and formal security reporting (OASIS SARIF 2.1.0 & CycloneDX SBOM).
  • Current Status: Open to Global Remote Roles · Junior DevOps / DevSecOps Engineer.

Divider

🛡️ Defense-in-Depth Architecture

The engineered systems below interconnect into a cohesive, five-layer zero-trust ecosystem:

5-Layer Defense-in-Depth Architecture

Divider

🛠️ Featured Systems & Core Repositories

DockerWard repo-secret-auditor
secuscan-api archforge
portfolio chat-anonimo

Divider

⚡ Technical Capabilities & Stack

Layer 01 [Systems & Kernel Hardening]:
  OS: Arch Linux, Debian, Ubuntu LTS
  Core Primitives: systemd daemons, cgroups v1/v2, namespaces, capabilities, seccomp BPF
  Automation & Security: Idempotent Bash, nftables firewall, ShellCheck compliance

Layer 02 [Containers & Runtime Security]:
  Engines: Docker Engine API (UNIX socket), Docker Compose
  Standards: CIS Docker Benchmark v1.6.0, Non-Root Hardening, Resource Quotas
  Build Optimization: Multi-stage slim builds, zero-CVE base images, Distroless

Layer 03 [CI/CD & DevSecOps]:
  Pipelines: GitHub Actions Reusable Workflows, Pre-commit automated hooks
  Standards: OASIS SARIF 2.1.0, CycloneDX 1.5 JSON SBOM, FIRST CVSS v3.1
  Auditing: Gitleaks pattern rules, Google OSV API, pip-audit, Shannon entropy

Layer 04 [Backend & Distributed Systems]:
  Languages: Python 3.12+, TypeScript, Bash
  Frameworks: FastAPI, Pydantic v2, SQLAlchemy, Celery async queues, Redis, PostgreSQL 16
  Quality Gates: Pytest (85%+ suite coverage), Mypy strict typing, Ruff linter

Layer 05 [Cryptography & Zero-Trust Comms]:
  Standards: WebCrypto API, AES-256-GCM symmetric encryption, ECDH P-256 key exchange
  Architecture: Zero-RAM message relay, Ephemeral WebSockets, In-memory ratchets

Divider

📡 Verified Quality Standards & Evidence

System / Tool Standards & Specifications Automated Tests CVEs in Deps Output Format
DockerWard CIS Docker Benchmark v1.6.0 71 Tests (100% Rules) 0 CVEs OASIS SARIF 2.1.0
repo-secret-auditor CycloneDX 1.5 SBOM · FIRST CVSS v3.1 74 Tests (91% Cov) 0 CVEs SARIF 2.1.0 + JSON
secuscan-api Anti-SSRF Guard · OWASP Top 10 86 Tests (100% Pass) 0 CVEs REST API / JSON
archforge 28 Modules · Idempotent Bash · SemVer Automated Sanity Suite 0 CVEs Native Linux Config
portfolio Astro 5 · Tailwind v4 · WCAG AA Access E2E Playwright Suite 0 CVEs Static Web (Netlify)
chat-anonimo WebCrypto AES-256-GCM · Zero-RAM Relay 40 Suites (Pytest/Vitest) 0 CVEs Ephemeral WSS

Divider

🚀 Quick Evaluation in Terminal

To test the systems directly from your local terminal:

# 1. Audit your live Docker containers against CIS Benchmark v1.6.0
git clone https://github.com/h3n-x/DockerWard.git
cd DockerWard && pip install -e . && dockerward --help

# 2. Audit Git history for leaked credentials & generate CycloneDX SBOM
git clone https://github.com/h3n-x/repo-secret-auditor.git
cd repo-secret-auditor && pip install -e . && secret-auditor --help

# 3. Inspect 28 modular Arch Linux post-installation hardening scripts
git clone https://github.com/h3n-x/archforge.git
cd archforge && ./archforge.sh --help

Divider

📊 Engineering Health & Ecosystem Insights

Engineering Metrics & Ecosystem Distribution

Divider

Crafted with the Twilight Sky & Warm Lantern palette · Built for resilience, reproducibility, and precision.
© 2026 Henry Pacheco (h3n-x) · h3n-x.dev

Pinned Loading

  1. DockerWard DockerWard Public

    Runtime security audit engine for Docker containers against CIS Benchmark v1.6.0. Inspects cgroups limits, kernel capabilities, seccomp filters, and exports SARIF 2.1.0 for CI/CD gates.

    Python

  2. repo-secret-auditor repo-secret-auditor Public

    CI/CD secret scanner and dependency auditor with Gitleaks TOML rules, Git history analysis, CycloneDX 1.5 SBOM export, CVSS v3.1 scoring, and SARIF 2.1.0 policy gates for GitHub Actions.

    Python

  3. secuscan-api secuscan-api Public

    High-performance async FastAPI backend for External Attack Surface Management (EASM). Deep TLS/SSL inspection, anti-SSRF, DNS hygiene, socket-level anti-rebinding, and OASIS SARIF 2.1.0 export.

    Python

  4. archforge archforge Public

    Modular post-installation and security hardening toolkit for Arch Linux. Features idempotent Bash execution, dry-run mode, automated /etc backups, nftables firewall, and systemd management.

    Shell

  5. portfolio portfolio Public

    Personal software engineering portfolio showcasing systems architecture, container runtime security, Linux automation, and DevSecOps tooling. Built with Astro 5, Tailwind v4 & TypeScript.

    Astro

  6. chat-anonimo chat-anonimo Public

    Zero-Knowledge ephemeral messaging suite with Blind Relay architecture, in-memory RAM cryptography (AES-256-GCM + ECDH), biometric voice obfuscation, duress decoy mode, and anti-forensic defenses.

    3