RS
Rupinder Singh
Staff QA & AWS Cloud Operations • AI-Assisted Testing
Get in Touch
ZTCA™ Certified Zero Trust ArchitectAWS Cloud Ops & Automation14+ Years Enterprise QA, Cloud Ops & TestingMohali, Punjab, India (Open to Hybrid / Remote)

Rupinder Singh

Staff Test & QA Engineer • AWS Cloud Operations Specialist|Microservices Quality, AI-Assisted Testing & IAM Security

Core Impact Metrics
14+
Years Test Engineering & Ops Track Record
AI+QA
AI-Assisted Testing & Quality Validation
Zero
Trust Architecture Certified (ZTCA)
AWS Ops
IAM, SQS, CloudWatch & Security Groups
Control-Plane Observability 99.99% Reliability

Executive Summary

Accomplished Staff Test Engineer / QA & AWS Cloud Operations Specialist with 14+ years of specialized experience directing microservices quality, AI-assisted testing workflows, cloud security infrastructure, and control-plane reliability for high-throughput Java microservices across Zscaler Private Access (ZPA). Proven track record leading hybrid lab-to-AWS infrastructure migrations and establishing secure network interconnectivity for enterprise crown jewel tools (GitLab, Bitbucket, Jira, Confluence), hardening AWS test cloud perimeters with AWS CloudFront and internal routing—guaranteeing zero unauthorized public internet exposure—spearheading production infrastructure deployments including high-availability Redis caching clusters for critical authentication services, and architecting Grafana observability suites (monitoring p95 latency, task crash/restart events, and real-time microservice exception alerts). Adept in automated Jenkins CI/CD whitelisting pipelines, AI tools for test authoring and smart triage, distributed JMeter load benchmarking, and scalable cloud staging via Amazon ECS, Docker, Terraform, and CloudWatch.

Technical Skills & Competencies

Categorized matrix spanning cloud architecture, infrastructure as code, zero trust security, and protocols.

AWS Cloud Operations & Infrastructure

AWS CloudFront PerimeterAWS IAM (Roles & Policies)AWS EventBridge & LambdaAWS CloudTrail & SQSRedis Production DeploymentSecurity Groups & VPCDynamic Testbox WhitelistingAWS CloudWatch & AlarmsAmazon ECS & EC2Zero Public Exposure LockdownLab-to-AWS MigrationHybrid Cloud InterconnectEnterprise Tool Interconnect (GitLab, Bitbucket, Jira)

Microservices Testing & AI-Assisted QA

AI-Assisted Test GenerationAI Tools for QA & TriageJava Microservices TestingJMeter Performance TestingIntegration & API ValidationRegression & Functional QAThroughput Benchmarking

CI/CD & Infrastructure as Code

Jenkins CI/CD PipelinesAutomated Whitelisting CI/CDTerraformAnsibleAutomated Test StagesSecurity Group Rule AutomationGit / GitHub

Zero Trust & Security Architecture

ZPA (Zscaler Private Access)IAM Policy GovernanceOAuth 2.0 EnrollmentSAML 2.0 ValidationRADIUS / 2FA / MFACert-Based Auth (CBA)Zscaler Client Connector (ZCC)ZPA App ConnectorPrivate Subnet & VPC HardeningAWS KMS (Multi-Region Keys)Applied Cryptography & HSM

AI Tools, Utilities & Scripting

Grafana Observability (p95, Crashes)ChatOps (Slack API Alerts)Build Drift AuditabilityAI Prompt-Driven Test AuthoringPython Verification ScriptsBash Shell UtilitiesREST APIs & JSON ValidationTask Crash & Restart Alerting

Networking & Deep Protocols

TCP/IP, HTTP/HTTPSNetwork PresenceVRRP & iSCSIFCIP & Storage SANCisco CFS & MDS SwitchesCross-Environment Routing
STAFF QUALITY & CLOUD OPS INITIATIVES

System Architecture & Reliability Highlights

High-impact engineering artifacts designed and delivered across global microservice architectures.

AWS CloudFront Zero Public Exposure Perimeter

Architected and deployed AWS CloudFront edge protection and routing for test cloud ZPA Java microservices. Locked down ingress to ensure zero unauthorized public internet exposure, enforcing strict access solely via authenticated Zscaler secure network channels.

Tech: AWS CloudFront • Zero Public Exposure • VPC Ingress • ZPA Routing

Automated Client & Testbox Whitelisting Engine

Engineered an automated Jenkins CI/CD pipeline dynamically updating AWS Security Groups and ACLs to securely whitelist verified developer laptops, client testboxes, and automated test runners for seamless test cloud microservice validation.

Tech: Jenkins CI/CD • AWS Security Groups • Dynamic Whitelisting • Python

Lab-to-AWS Automation Infrastructure & Crown-Jewel Interconnect

Spearheaded migration of legacy on-prem LAB automation test infrastructure to AWS; engineered secure hybrid network routing and cross-environment peering/connectivity ensuring mission-critical enterprise crown jewel applications—GitLab, Bitbucket, Jira, and Confluence—are seamlessly and securely reachable from the AWS test environment for unhindered automated test execution.

Tech: AWS Hybrid Networking • VPC Peering / Direct Connect / Routing • GitLab / Bitbucket • Jira / Confluence • Infra Migration

Control-Plane Telemetry, Grafana & Redis Deployments

Architected comprehensive Grafana observability dashboards across all critical microservices—tracking service p95 latency, task crash/restart events, health status, and real-time microservice exception telemetry. Spearheaded production infrastructure deployments including high-availability Redis clusters powering session state and caching for core services such as Authentication.

Tech: Grafana • Redis • AWS CloudWatch • Telemetry & Alerts • JMeter

Zero-Trust AWS Perimeter & Zscaler Client Connector Architecture

Eliminated public attack surfaces across AWS test environments by architecting end-to-end private connectivity via Production Zscaler Client Connectors. Collaborated closely with production infrastructure teams to deploy App Connectors across all AWS QA VPCs, ensuring internal testboxes operate strictly within isolated private subnets with zero public ingress. Standardized secure, identity-governed SSH and RDP management sessions through Zscaler Client Connector without exposing public IPs or jump hosts.

Tech: Zscaler Client Connector (ZCC) • ZPA App Connector • Private Subnets & VPC Lockdown • Zero Public Ingress • Secure SSH / RDP

Event-Driven Build Telemetry & Slack Audit Pipeline

Architected an automated, event-driven environment audit pipeline using AWS CloudTrail, EventBridge, SQS, and Lambda to resolve lower-cloud build drift and prevent invalid release sign-offs. Captures multi-service deployment events across QA clouds and streams rich Slack notifications with microservice name, version transition (v1 → vX), timestamp, and deployer identity—guaranteeing 100% build awareness and environment integrity.

Tech: AWS EventBridge • AWS Lambda • AWS CloudTrail • AWS SQS • Slack API • Build Drift Prevention

Professional Experience

14+ years of continuous growth across cloud security leaders, defense-grade authentication, and storage networking.

Stack:RedisGrafana ObservabilityEventBridge & LambdaAWS CloudTrail & SQSChatOps / Slack APIAI-Assisted TestingAWS CloudFrontAutomated Whitelisting CI/CDJava Microservices QAJMeter Load TestingTerraform / ECSLab-to-AWS MigrationAWS KMS (Multi-Region)Envelope Encryption / HSM

Staff QA & AWS Cloud Operations Engineer

Zscaler SoftechCloud Security Leader (ZPA)
Jun 2018 – Present
  • Automated Deployment Telemetry & Build Drift Prevention: Engineered an event-driven QA monitoring and notification pipeline using AWS CloudTrail, EventBridge, SQS, Lambda, and Slack API to eliminate release sign-offs on unverified builds caused by untracked deployment changes in lower clouds. Configured event triggers across microservices broadcasting real-time alerts with version transitions (v1 → vX), timestamps, and deployer identity—guaranteeing test environment integrity and deployment awareness.
  • Cryptographic Database Migration & Multi-Region AWS KMS Validation: Spearheaded the end-to-end testing, validation, and architectural rollout of sensitive database key migrations from single-region AWS KMS keys to AWS Multi-Region Keys (MRKs) using internal CryptService across QA and lower cloud environments. Rigorously tested envelope re-encryption pipelines, simulated cross-region failovers, and verified zero-downtime key rotation policies—guaranteeing data integrity, disaster recovery resilience, and seamless cryptographic performance prior to production promotion.
  • Hybrid Cloud Migration & Enterprise Tool Interconnect: Architected and executed the end-to-end migration of test automation infrastructure from physical on-prem LAB hardware into AWS. Engineered dedicated, secure network interconnectivity allowing AWS test environments to seamlessly communicate with enterprise crown jewel systems (GitLab, Bitbucket, Jira, Confluence), eliminating network bottlenecks and enabling smooth continuous automation execution across test cycles.
  • AWS CloudFront Perimeter & Zero Public Exposure Lockdown: Shielded and fronted all test-cloud ZPA Java microservices behind AWS CloudFront edge distributions and internal network boundaries; locked down ingress points to eliminate unauthorized public internet exposure, ensuring services are strictly accessible only within authenticated Zscaler secure network channels.
  • Production Infrastructure Deployments & Redis Cluster Provisioning: Spearheaded production infrastructure deployments including standalone and clustered Redis provisioning for core high-throughput services like Authentication, substantially boosting caching efficiency, query throughput, and session state reliability.
  • Automated Client & Testbox Whitelisting CI/CD Pipeline: Designed and implemented an automated Jenkins CI/CD whitelisting pipeline that dynamically updates AWS Security Groups and ACLs, enabling authorized developer machines, client testboxes, and testing runners to seamlessly connect to target Java microservices across isolated test cloud environments.
  • Core Java Microservices QA & Integration Testing: Spearheaded comprehensive functional, regression, and cross-service integration validation for mission-critical Zscaler Private Access (ZPA) Java microservices—including Authentication, Authorization, Drill Down, Kafka, Enrollment, Management API, SCIM, and Userdb services.
  • Grafana Observability & Cloud Telemetry: Architected and maintained comprehensive Grafana observability dashboards across all critical ZPA microservices (monitoring p95 latency thresholds, container/task crashes, unexpected restarts, and real-time exception alerting) coupled with CloudWatch operational telemetry and automated alerts.
  • AI-Assisted Testing & Smart QA Workflows: Integrated modern AI tools to accelerate test case generation, synthesize boundary condition scenarios, and assist in rapid log triage; boosted functional test coverage and accelerated regression turnaround across microservice releases.
  • Distributed Load & Performance Testing: Designed and executed distributed JMeter stress and latency test suites on ZPA microservices to benchmark control-plane throughput thresholds and uncover concurrency bottlenecks prior to production rollouts.
  • Test Cloud Staging & Defect Analysis: Provisioned reproducible staging environments utilizing Terraform, Docker, and ECS; conducted root cause analysis (RCA) on deep microservice concurrency, memory, and protocol defects in close collaboration with development engineering.
Stack:Redis (Cluster & Standalone)Grafana Observability (p95, Exceptions)EventBridge & LambdaAWS CloudTrail & SQSChatOps / Slack APIZPA Java Microservices (Auth, SCIM, Kafka, Drill Down)AI-Assisted TestingAWS CloudFrontDynamic Whitelisting CI/CDJMeter Load TestingTerraform / ECSLab-to-AWS MigrationAWS KMS (Multi-Region)CryptServiceEnvelope Encryption / HSM

Senior Software Engineer

Thales (formerly SafeNet / Gemalto) Identity & Data Protection
Jul 2014 – Jun 2018 (4 Years)
  • Cryptographic Database Migration & Multi-Region AWS KMS Validation: Spearheaded the end-to-end testing, validation, and architectural rollout of sensitive database key migrations from single-region AWS KMS keys to AWS Multi-Region Keys (MRKs) using internal CryptService across QA and lower cloud environments. Rigorously tested envelope re-encryption pipelines, simulated cross-region failovers, and verified zero-downtime key rotation policies—guaranteeing data integrity, disaster recovery resilience, and seamless cryptographic performance prior to production promotion.
  • Authentication Integration: Orchestrated end-to-end integration of SafeNet Authentication Products (Cloud and On-Premises) with enterprise third-party applications and critical network appliances.
  • Enterprise Appliance Configuration: Configured and validated integrations across Cisco ASA, Cisco ISE/ACS, McAfee Firewall, Juniper Gateways, Cisco WLAN Controllers, BIG-IP F5 APM, and Zscaler.
  • Multi-Factor Authentication (MFA/2FA): Implemented seamless 2FA/MFA integrations leveraging secure authentication standards including SAML 2.0, RADIUS, and Certificate-Based Authentication (CBA).
  • Partner Ecosystem Enablement: Collaborated with security partners to validate single sign-on (SSO) workflows, verify authentication flows, and author authoritative technical integration guides.
Stack: SafeNet Authentication SAML 2.0 RADIUS Cisco ASA & ISE F5 BIG-IP SSO / MFA AWS KMS (Multi-Region)CryptServiceEnvelope Encryption / HSM

Project Engineer

Wipro Technologies Limited Cisco Practice & Storage Systems
May 2011 – Apr 2014 (3 Years)
  • Cryptographic Database Migration & Multi-Region AWS KMS Validation: Spearheaded the end-to-end testing, validation, and architectural rollout of sensitive database key migrations from single-region AWS KMS keys to AWS Multi-Region Keys (MRKs) using internal CryptService across QA and lower cloud environments. Rigorously tested envelope re-encryption pipelines, simulated cross-region failovers, and verified zero-downtime key rotation policies—guaranteeing data integrity, disaster recovery resilience, and seamless cryptographic performance prior to production promotion.
  • Cisco MDS SAN Switch Testing: Validated advanced networking and storage protocols on Cisco Multilayer Datacenter Switch (MDS) platforms, including VRRP, iSCSI, SAN Extension Tuner (SET), and NetSim.
  • Cisco Fabric Services (CFS): Executed comprehensive functional and regression test suites for CFS components including Callhome, Fctimer, RADIUS, NTP, SysLog, Port Security, and Dynamic Port VSAN Membership (DPVM).
  • Storage Protocol Validation: Engineered test scenarios for Fibre Channel over IP (FCIP), systematically verifying throughput, latency tolerance, and data integrity over long-distance topologies.
Stack: Cisco MDS FCIP SAN Storage VRRP / iSCSI Cisco Fabric Services (CFS) AWS KMS (Multi-Region)CryptServiceEnvelope Encryption / HSM

Industry Certifications

ZTCA – Zero Trust Certified Architect

Zscaler Certified Certification

Specialized in Zero Trust Network Access (ZTNA), Identity-Driven Security, Micro-segmentation Architecture, and Software-Defined Perimeter controls.

Formal Education

Graduated: 2010 4-Year Degree

B.Tech / B.E. in Computer Science & Engineering

Sri Sukhmani Institute of Engineering & Technology (SSIET)

Dera Bassi, Punjab, India

Foundational coursework in Data Structures, Operating Systems (Unix/Linux), Computer Networks, Distributed Computing, and Storage Architectures.

Languages Spoken: English (Fluent), Hindi (Native), Punjabi (Native)