Cloud Security · DevSecOps · Zero Trust
Cloud Security Engineer
I design AWS-first, Zero Trust infrastructure that is secure by default — not patched after the fact. Terraform IaC, GitOps CI/CD pipelines, and container security on ECS Fargate and EKS.
Primary Focus
Capabilities
Identity & Access
Least-privilege role design per service, no long-lived access keys, OIDC federation for CI/CD. Every request authenticated and authorized at the control plane.
Infrastructure as Code
Modular Terraform with separate networking, compute, and security layers. Remote state with S3 + DynamoDB locking. Workspaces per environment.
CI/CD Security
GitHub Actions pipelines with security gates: build → scan (Trivy/Checkov) → push ECR → deploy ECS with zero-downtime rolling updates and automatic rollback.
Container Security
Non-root containers, read-only root filesystem, RBAC on Kubernetes, network policies, container image hardening with multi-stage builds.
Observability
Structured JSON logging, custom application metrics, dashboard-driven SLI tracking, proactive SNS alerting before incidents impact users.
Supply Chain
Artifact signing with Sigstore, SBOM generation for full dependency visibility, OpenSSF Scorecard compliance for repository security posture.
Portfolio
Production-oriented, multi-AZ AWS platform built with Infrastructure as Code, a Zero Trust security model, containerized microservices on ECS Fargate, and full observability via CloudWatch. Designed following real-world cloud engineering principles: security-first, immutable deployments, and separation of infrastructure from application responsibilities.
Infrastructure Stack
| Layer | Service | Purpose |
|---|---|---|
| Compute | AWS ECS Fargate | Serverless containers — no EC2 management |
| Networking | AWS VPC + ALB | Multi-AZ, Security Group segmentation, Layer 7 routing |
| Security | IAM + Secrets Manager | Least-privilege roles, KMS-encrypted secrets, zero hardcoded credentials |
| Observability | CloudWatch | Structured logs, custom metrics, SLI/SLO dashboards |
| IaC | Terraform | Modular, declarative infrastructure — 100% IaC, zero manual changes |
| CI/CD | GitHub Actions | GitOps pipeline with encrypted secrets, OIDC on roadmap |
CI/CD Pipeline
Observability
CPU threshold
> 80%
Alert + scale trigger
HTTP 5xx rate
> 5/min
Critical alert via SNS
Latency
> 2s
Performance warning
Security Controls
Implemented
Roadmap
Credentials
Get in Touch
Open to Cloud Security, DevSecOps, and AWS architecture roles — remote or Santiago, Chile. Let's talk about building infrastructure that is secure by design, not by accident.