[SYSTEM: ONLINE]

Initializing Secure Connection...

Mervin Jones | Cloud Security & PKI Engineer

Enterprise PKI and certificate lifecycle management. I build the systems that keep certificates — and the authorities that sign them — from becoming the reason everything stops.

0xF4A2
SSH://
AES-256
RSA
TLS 1.3
SHA-512

01. selected operations

~/projects/certpilot
Early development

CertPilot

Open-source PKI and certificate lifecycle management for the team that owns the CA hierarchy. Discovery across Certificate Transparency logs, cloud accounts and firewalled hosts; renewals deployed in declared waves with a handshake to prove they took; and issuing CAs watched on the same clock as everything they sign.

Go Vue PostgreSQL gRPC ACME
~/projects/mervinx-cloud
Running

MervinX Cloud (MXC)

A private cloud I run at home — personal storage, container hosting, and a WireGuard tunnel for access. Where cloud ideas get tried properly before they meet anything that matters.

Docker WireGuard Linux
~/projects/graphi-x
Live

Graphi-X

Sketch a maths problem on a canvas and get it solved. Gemini vision reads the drawing, FastAPI serves it. Hosted on MXC.

Python FastAPI Gemini
~/projects/mxc-ai-bot
Live

mxc-ai-bot

A Telegram bot with switchable LLM backends — Gemini, OpenAI, DeepSeek — with image input and per-user model selection.

Python Telegram SQLite

02. career path

2026.06 → PRESENT

Engineer

Tata Consultancy Services · Frankfurt am Main
  • Automated certificate management pipelines integrating Cert Hub with Google Cloud CAS
  • Provisioning, renewal and ingress certificate binding for enterprise microservices across GKE, using Terraform and GitOps
  • Monitoring and alerting built to stop certificate expiry becoming an outage
2021.10 → 2026.05

System Engineer

Tata Consultancy Services · Chennai
  • Managed PKI and DevOps processes across multi-tenant enterprise environments
  • Certificate management with Cert Hub, Google CAS, Terraform and GKE
  • Research into post-quantum cryptography and future-proofing encryption strategy
2019.06 → 2020.10

Student Intern

Spatez Technology · Trichur, Kerala

03. stack

PKI & Crypto
X.509ACME / RFC 8555Certificate Transparency Mutual TLSGoogle Cloud CASHashiCorp Vault OCSP / CRLPost-quantumConfidential computing
Cloud & Platform
Google CloudGKEIAMKubernetes DockerTerraformGitOpsCI/CDLinux
AI & Data
AI PromptingGeminiSplunkMCP
Build
GoPythonVuePostgreSQL gRPCBash

04. certifications

EC-Council

Certified Ethical Hacker (CEH)

Google

Associate Cloud Engineer

Microsoft

Azure Fundamentals (AZ-900)

Microsoft

Security, Compliance & Identity (SC-900)

Databricks

Databricks Fundamentals

(ISC)²

Candidate

HackingFlix

Certified Cyber Warrior

Cisco

Introduction to Cybersecurity

Cisco

Cybersecurity Essentials

Google Cloud

Skill Badge — Cloud Infrastructure

Google Cloud

Skill Badge — Cloud-Native App Dev

Google Cloud

Skill Badge — Security & Identity

Google Cloud

Skill Badge — Networking

Google Cloud

Skill Badge — Data & ML

Google Cloud

Skill Badge — Workspace Admin

TCS

On-The-Spot Award — Sep 2022

Let's talk about the thing nobody is watching.

Certificate estates, CA rotation, or anything self-hosted. I'm always glad to hear how somebody else runs theirs.