Cloud Security · DevSecOps · Zero Trust

Emanuel G.
Michea

Cloud Security Engineer

I design AWS-first, Zero Trust infrastructure that is secure by default — not patched after the fact. Terraform IaC, GitOps CI/CD pipelines, and container security on ECS Fargate and EKS.

Stack
AWS ECS Fargate Terraform GitHub Actions IAM · Zero Trust Kubernetes · EKS CloudWatch Secrets Manager Docker · ECR Sigstore · SBOM

Primary Focus

AWS Cloud Security

AWS · Core Platform

Production-grade AWS architecture — security and automation first

Capabilities

Core Skills

Identity & Access

AWS IAM · Zero Trust

Least-privilege role design per service, no long-lived access keys, OIDC federation for CI/CD. Every request authenticated and authorized at the control plane.

Infrastructure as Code

Terraform · Modular IaC

Modular Terraform with separate networking, compute, and security layers. Remote state with S3 + DynamoDB locking. Workspaces per environment.

CI/CD Security

DevSecOps Pipelines

GitHub Actions pipelines with security gates: build → scan (Trivy/Checkov) → push ECR → deploy ECS with zero-downtime rolling updates and automatic rollback.

Container Security

ECS Fargate · EKS

Non-root containers, read-only root filesystem, RBAC on Kubernetes, network policies, container image hardening with multi-stage builds.

Observability

CloudWatch · SLI/SLO

Structured JSON logging, custom application metrics, dashboard-driven SLI tracking, proactive SNS alerting before incidents impact users.

Supply Chain

Sigstore · SBOM · OpenSSF

Artifact signing with Sigstore, SBOM generation for full dependency visibility, OpenSSF Scorecard compliance for repository security posture.

Portfolio

Projects

Credentials

Certifications

LFD121 · Developing Secure Software
LFS183 · Introduction to Zero Trust
LFS169 · Introduction to GitOps
LFS158 · Introduction to Kubernetes
LFS182 · Securing Supply Chain with Sigstore
OpenSSF Scorecard & SBOM Security
Cisco · Cybersecurity Defense Analyst
Cisco · Ethical Hacker
Cisco · Cyber Threat Management

Get in Touch

Contact

Open to Cloud Security, DevSecOps, and AWS architecture roles — remote or Santiago, Chile. Let's talk about building infrastructure that is secure by design, not by accident.