Sean Michael Stoves Sr.
SecOps & Platform Engineer
Remote
Summary
SecOps and Platform Engineer with over 23 years of experience in systems administration, DevOps, and software engineering. Five years specializing in cloud technologies, with the rest on-premises. Primary expertise includes AWS security hardening, SOC 2 compliance, security standards, and CI/CD pipelines and infrastructure-as-code using tools like Terraform, OpenTofu, Pulumi, GitHub Actions, and AWS CodePipeline. Also skilled in incident response, security automation, and full-stack development. Over 15 years working remotely or in hybrid positions.
Technical skills
- Cloud & Infrastructure
- AWS · Proxmox · VMware · VirtualBox · Docker · Kubernetes
- Security & Compliance
- SOC 2 audit readiness · Vulnerability management (Wiz, Snyk) · IAM & secrets rotation · Cloudflare Zero Trust (Access, Tunnel) · IPTables · Bastille · Snort · OSSEC · Nmap · Rapid7 · BitDefender · Wiz
- CI/CD & DevOps
- GitHub Actions · AWS CodePipelines · Azure DevOps · TeamCity · GitLab · SaltStack · Bacula · Terraform / OpenTofu · Pulumi · Ansible · Chef
- Languages
- TypeScript · Python · Bash · PowerShell · PHP · C#/.NET · C/C++ · Java · Batch · VBScript
- Application Frameworks
- Ruby on Rails · FastAPI · Next.Js / React · React Native · CodeIgniter · Symfony · Laravel
- Databases
- MySQL · PostgreSQL · MSSQL · MongoDB · Elasticsearch · MS Access
- Monitoring & Observability
- Datadog · SolarWinds · Zabbix · Nagios · ZenOSS
- Networking
- Cloudflare (DNS, CDN, WAF) · Cisco · Juniper · Dell · SonicWall · DHCP · WINS · TCP/IP · SMTP
- Operating Systems
- Linux · Unix · Windows · macOS
- Servers & Services
- Apache · Nginx · Postfix · Qmail · Bind · PowerDNS · LDAP · Active Directory
- AI Tooling
- Claude (plugin authoring, prompt engineering) · LLM-assisted development workflows
Experience
Wizards of the Coast (D&D Beyond)
2022 – PresentRemote (Renton, WA)
SecOps-Focused Platform Engineer
2025 – Present- Track and triage CVEs impacting D&D Beyond services, routing remediation work to the owning teams
- Keep platforms aligned with security best practices and internal compliance standards
- Harden AWS IAM, secrets rotation, and least-privilege access across accounts
- Expand logging, monitoring, and alerting coverage for security-relevant events
- Authored an internal Claude plugin that codifies and enforces company policies, naming conventions, and security guardrails, and accelerates RCA and incident-response workflows for D&D Beyond engineers
Software Engineer, Discord
2023 – 2025- Developed new features in Python for Avrae, the open-source Discord bot powering D&D play
- Served as primary pull-request reviewer and maintainer for the open-source codebase
- Maintained Avrae's automation database for 1PP and 3PP content
- Owned the release process and ongoing modernization of the platform
Platform Engineer
2022 – 2023- Built and ran CI/CD on GitHub Actions and AWS CodePipelines
- Wrote Terraform IaC for production AWS infrastructure
- Owned monitoring and weighed in on AWS architecture decisions across teams
Cardtapp
2024 – PresentRemote (Seattle, WA)
Lead Platform & Software Engineer (Contract)
2025 – Present- Sole engineer on a greenfield rebuild replacing the legacy Rails platform — a FastAPI modular monolith (21 modules, 243 endpoints, 60 tables across 14 Postgres schemas) and three Next.js 15 surfaces, at ~60k LOC source and ~33k LOC test
- Built the entitlements core — three-layer resolve across plan baseline, add-on grants, and per-org overrides — enforced fail-closed server-side, alongside Stripe billing with bidirectional plan sync and drift detection
- Own all cloud infrastructure: 26 OpenTofu modules and 400 resources across three AWS accounts on ECS Fargate, RDS, DocumentDB, Valkey, Lambda, CloudFront, and WAF
- Built hub-and-spoke OIDC CI across 40 workflows with no long-lived AWS keys, SHA-pinned actions, and permissions boundaries on every Lambda role
- Ran a security and Well-Architected gap audit across three AWS accounts and nine repos: 203 findings, 7 critical, including a cross-tenant IDOR and a severity-9 GuardDuty alert unrouted for seven weeks. Scoped 8 epics and 55 remediation tickets, shipping ~54
- Authored two Claude plugins (31 skills, 13 commands, Python and Bash enforcement hooks) encoding legacy and rebuild system knowledge, published to the org marketplace
- Part-time maintainer of a 14-year-old Rails 6 / Mongoid multi-vertical SaaS monolith — 295k LOC, 120 models, three Ember frontends, and a Capacitor mobile app
- Added brute-force mitigation to a legacy Devise multi-step login, scoped CanCanCan abilities to least privilege via a zero-downtime data migration, and added snapshot-plus-audit to a policy that was destroying customer data irrecoverably
Platform & Software Engineer (Contract)
2024 – 2025- Part-time maintainer of a 14-year-old Rails 6 / Mongoid multi-vertical SaaS monolith — 295k LOC, 120 models, three Ember frontends, and a Capacitor mobile app
- Added brute-force mitigation to a legacy Devise multi-step login, scoped CanCanCan abilities to least privilege via a zero-downtime data migration, and added snapshot-plus-audit to a policy that was destroying customer data irrecoverably
- Shipped NFC chip lock-to-readonly: forked the upstream Capacitor plugin and implemented iOS locking through raw MiFare commands, keeping the fork tracking upstream
- Automated remediation for A2P 10DLC registrations stuck mid-workflow, replacing a manual runbook; fixed a Stripe webhook that was downgrading paying customers to free
Fandom (D&D Beyond)
2021 – 2022Remote (San Francisco, CA)
TechOps Engineer
- Built and ran CI/CD on GitHub Actions and AWS CodePipelines
- Wrote Terraform IaC for AWS infrastructure
- Owned production monitoring and AWS architecture recommendations
Momentum Telecom, Inc.
2016 – 2021Remote (Philadelphia, PA)
Software Engineer
2019 – 2021- Built billing-implementation processes for telecom customer onboarding
- Built Elasticsearch integrations for fraud detection and CDR delivery
- Ran Azure DevOps CI/CD for the Billing Engineering team
- Operated and monitored the .NET production application stack
Sr. SysOps Engineer
2016 – 2019- Kept production servers healthy across multiple ESX clusters via vCenter
- Built SaltStack automation for config management at scale
- Wrote internal tools and processes for engineering and ops
- Ran GitLab and Active Directory for the org
- Ran continuous stress testing against production-bound systems
Web Agent Solutions
2012 – 2016Hybrid Remote (Chalfont, PA)
Sr. Server Administrator, Project Manager & Product Developer
- Designed and shipped web-based tools and products end-to-end
- Managed an outsourced dev team and reviewed code on delivery
- Owned server health, MySQL maintenance, and stress testing
- Handled customer technical support by phone and email as needed
Go 2 Strategies
2011 – 2026Remote
Sr. SysOps Engineer (Freelance)
- System administration and operations across Linux, BSD, and Windows servers
- Ongoing server maintenance, performance tuning, and uptime monitoring
- Custom WordPress development and ad-hoc PHP work as needed
Earlier experience
Server Administrator & Developer. VoIP network operations across Linux, BSD, and Windows environments
Network Operations & Server Administrator. WiMAX 4G operations, SolarWinds monitoring, and Bacula backups
Desktop Support & Network Administrator. Windows 2003 domain administration, CloneZilla imaging, and MSSQL support
Web Developer & Server Administrator. Custom PHP/MySQL hosting applications and server administration
Linux/Unix Systems Administrator. Qmail, Apache, and MySQL administration for managed hosting
Technical Support Specialist. Web hosting support, scripting, and internal tooling
Education
Chubb Institute
Diploma, Network Security and Server Administration (4.0 GPA)
Carbon County Vocational Technical School
Integrated Information Systems Program