> about
Cloud Security Architect with over 10 years of cybersecurity experience. Specializing in AWS Cloud Security and Kubernetes, I design scalable, secure-by-default multi-tenant architectures and automated DevSecOps pipelines that reduce risk without slowing down delivery.
- Cloud & Container Security. Hardened multi-account AWS architectures and Kubernetes clusters (CKA & CKS certified).
- Security Automation. Scaled secure-by-default deployments using Terraform, AWS CDK, and automated DevSecOps guardrails.
- Leadership. Led cloud security capabilities (IAM, logging, compliance) and drove shift-left security practices.
- Security Operations. Guided incident response, threat mitigation, and continuous vulnerability management.
> experience
Cloud Security Engineer
- Implemented resilient cloud security controls and best practices for production AWS and Kubernetes environments.
- Hardened infrastructure by refactoring Terraform codebases for enhanced security, reliability, and automation.
- Conducted vulnerability assessments and drove targeted cross-functional remediation efforts.
- Streamlined incident response by refining SOC playbooks and coordinating containment plans.
[AWS Security][Kubernetes][Terraform][Incident Response]
Cloud Architect — Cloud Security Team Lead
- Directed Cloud Security strategies across IAM, network security, CI/CD pipelines, and compliance.
- Pioneered shift-left DevSecOps adoption within engineering application workflows.
- Automated security detections to accelerate incident response and operational capabilities.
- Architected scalable logging, monitoring, and firewalling capabilities for AWS environments.
[AWS Security Architecture][DevSecOps][Leadership]
Cloud Security Engineer
- Secured large-scale multi-account AWS organizations while ensuring strict PCI compliance.
- Automated DevSecOps guardrails using AWS CDK, Lambda, Security Hub, GuardDuty, and external tools like Qualys.
- Strengthened IAM governance, centralized SIEM log orchestration, and continuous CloudWatch alerting.
[AWS Security Hub][GuardDuty][AWS CDK][IAM Governance][PCI Compliance]
Senior Security Consultant
- Led AWS security architecture and implementation in Agile delivery environments.
- Performed security assessments and drove vulnerability remediation plans.
- Embedded security controls across the Software Development Life Cycle (SDLC).
Security Engineer
- Performed penetration testing for web and mobile applications.
- Monitored and triaged security events using QRadar.
- Implemented security controls for Azure cloud environments.
- Supported GDPR compliance and data protection initiatives.
Security Analyst
- Delivered vulnerability analysis and technical guidance for the Spanish government CERT.
- Developed expertise in malware analysis, detection, and mitigation tooling.
- Provided security mentoring and consulting for public-sector initiatives.
- Designed and tested Capture The Flag (CTF) exercises for security education.
- Authored whitepapers, technical guides, and security blog content.
- Presented at security events organized by INCIBE.
- Led cyber exercises for public sector organizations and educational institutions.
- Performed penetration testing and ethical hacking assessments.
> certifications
- CKA CKA: Certified Kubernetes Administrator
- CKS CKS: Certified Kubernetes Security Specialist
- AWS-MLS AWS Machine Learning Specialty
- AWS-SAP AWS Solutions Architect Professional
- AWS-SECS AWS Security Specialty