[SYSTEM: ONLINE]
Initializing Secure Connection...
Mervin Jones | Cloud Security & PKI Engineer
Enterprise PKI and certificate lifecycle management. I build the systems that keep certificates — and the authorities that sign them — from becoming the reason everything stops.
01. selected operations
CertPilot
Open-source PKI and certificate lifecycle management for the team that owns the CA hierarchy. Discovery across Certificate Transparency logs, cloud accounts and firewalled hosts; renewals deployed in declared waves with a handshake to prove they took; and issuing CAs watched on the same clock as everything they sign.
MervinX Cloud (MXC)
A private cloud I run at home — personal storage, container hosting, and a WireGuard tunnel for access. Where cloud ideas get tried properly before they meet anything that matters.
Graphi-X
Sketch a maths problem on a canvas and get it solved. Gemini vision reads the drawing, FastAPI serves it. Hosted on MXC.
mxc-ai-bot
A Telegram bot with switchable LLM backends — Gemini, OpenAI, DeepSeek — with image input and per-user model selection.
02. career path
Engineer
- Automated certificate management pipelines integrating Cert Hub with Google Cloud CAS
- Provisioning, renewal and ingress certificate binding for enterprise microservices across GKE, using Terraform and GitOps
- Monitoring and alerting built to stop certificate expiry becoming an outage
System Engineer
- Managed PKI and DevOps processes across multi-tenant enterprise environments
- Certificate management with Cert Hub, Google CAS, Terraform and GKE
- Research into post-quantum cryptography and future-proofing encryption strategy
Student Intern
03. stack
04. certifications
Certified Ethical Hacker (CEH)
Associate Cloud Engineer
Azure Fundamentals (AZ-900)
Security, Compliance & Identity (SC-900)
Databricks Fundamentals
Candidate
Certified Cyber Warrior
Introduction to Cybersecurity
Cybersecurity Essentials
Skill Badge — Cloud Infrastructure
Skill Badge — Cloud-Native App Dev
Skill Badge — Security & Identity
Skill Badge — Networking
Skill Badge — Data & ML
Skill Badge — Workspace Admin
On-The-Spot Award — Sep 2022
05. writing
Your certificate inventory is exact. Your tickets are not.
Code owns expiry, chains and CAA. A decision model reads the ticket. What happened when I measured it against an ordinary LLM.
An expiring certificate breaks one service. An expiring CA breaks all of them.
Everyone automates leaf certificates. Almost nobody has a renewal script for an issuing CA — and the blast radius is not comparable.
What Certificate Transparency tells you about your own estate
CT was built so the world could audit certificate authorities. It is also the cheapest inventory tool you have for your own domains.
Post-quantum: the half you can fix today
Signatures are a planning problem. Key exchange is a shipping problem, and it has already shipped — in your standard library.
Let's talk about the thing nobody is watching.
Certificate estates, CA rotation, or anything self-hosted. I'm always glad to hear how somebody else runs theirs.