Dominic Heun

Cloud Architect, IT Security Enthusiast, Software Engineer

Summary

I am passionate about creating software that makes a difference for everybody. My focus is on cloud-native applications featuring Kubernetes and modern SSDLC approaches. In these approaches, the software should not only meet customer criteria but also follow best practices, be secure and compliant according to regulations.

Experience

December 2024 - Present

Head of Operations and Governance

Operation, Governance and Engineering of a SaaS-Platform

  • I established a governance model for the development and deployment of the platform. This increased developer productivity and correctness of the process.
  • I implemented a multi-tenant identity and access management system, implementing OAUTH2.0. In this system, I used NestJS, Typescript, TypeORM, and Redis.
  • Access control governance using Open-Policy-Agent, Rego, and JWTs for a microservice-oriented application.
  • I led a project to ensure ISO27001 compliance of our department and implemented measures to adhere to the ISMS.
  • I operated several internal systems using ArgoCD and Azure Kubernetes Service.
May 2021 - December 2024

Lead Developer and Head of Operations

Creation and Operation of a SaaS-Plattform

  • I planned the development and developed myself on our SaaS platform using NestJS, Typescript, and Docker. During this time, I led a team of developers to create our software.
  • Creation of engineering approaches to increase velocity in the development lifecycle using Open Policy Agent.
  • I governed GitHub Actions to periodically check our source code for vulnerabilities, licenses, and code smells. With SonarQube, the whole code was periodically SAST-checked. These checks were mandatory for all pull requests in our organization.
  • I implemented new requirements for operation of the platform using Pulumi and Kustomize.
  • I governed the operational lifecycle of the platform. This included the review of IaC PRs as well as the selection of cloud-provider resources for the fulfillment of the requirement.
  • I helped customers to implement their own solutions using our SaaS platform.
September 2020 - Present

Freelancer

Creation and maintenance of a planning system

  • Analysis of requirements in the business process.
  • Creation of a webapp using React.
  • Implementation of the system using TypeScript, NestJS, and MySQL.
  • Maintenance and consulting for changing business needs.
September 2020 - May 2021

Freelancer

Working on the creation of a SaaS chatbot platform and its Operations. DevOps engineer and software engineer.

  • Transition of ClickOps to IaC using Pulumi.
  • Planning and implementation of a Kubernetes-native approach with AKS.
  • Maintenance and deployment of a Hashicorp Vault cluster for secure operations.
  • Transition of GitLab CI to GitHub Actions.
  • Maintenance and Governance of AWS, Azure, and GCP Accounts.

Education

Karlsruhe Institute of Technology

October 2024 - Present

Master of Science IT-Security and Telematics

  • IT Security
  • Design and Analyze Decentralized Systems
  • Telematics
  • Web Applications and Service-Oriented Architectures

Karlsruhe Institute of Technology

October 2020 - September 2024

Bachelor of Science Computer Science

  • Software Security Engineering
  • Decentralized Systems

Volunteer

KIT

July 2022 - Present
Ministry for Group Coordination

I am responsible for organizing the structure and processes of my student group. This includes the processing of AStA forms, governance of members, and organization of meetings.

  • Awarded 'Auszeichnung für herausragende Ehrenamtliche Leistung' in 2025.

El Rancho

January 2020 - July 2020
Volunteer

I helped to serve up to 900 persons daily

  • Preparation of meals for our catering.
  • Planning of staff meals.