Jonathan Veneri

Senior Cloud & Cybersecurity Engineer | DevOps & Infrastructure Automation

Professional Summary

IT professional with 15+ years of experience in infrastructure, cybersecurity, and automation. Specialized in designing and implementing secure enterprise architectures, leading cloud migration initiatives (AWS & hybrid environments), and optimizing processes through Infrastructure as Code (Terraform, Ansible, custom tools), CI/CD pipelines, and Lean Six Sigma practices. Proven track record in the banking and telecommunications sectors, ensuring business continuity, regulatory compliance, and secure, high-availability systems. Recognized for quickly mastering new technologies and delivering solutions to complex challenges.

Experience

Senior Cloud & Cybersecurity Consultant

2022 - Present
Freelance,
  • Cloud Migration & Architecture: Led the migration of on-premise data center infrastructure to Amazon AWS, implementing scalable and secure architectures.
  • Automation & DevOps: Automated infrastructure provisioning and service management using Terraform, Vault, Consul, Nomad, and Docker, reducing deployment times and operational overhead.
  • Cybersecurity Services: Conducted penetration tests, vulnerability assessments, and infrastructure hardening, ensuring compliance with security best practices.
  • Cloud Security & Data Protection: Implemented cloud security controls, IAM policies, and encryption strategies to safeguard sensitive data.
  • Monitoring & Observability: Configured monitoring and alerting systems with Prometheus, Grafana, and CloudWatch to improve visibility and system reliability.
  • Training & Knowledge Transfer: Delivered hands-on training for client teams on emerging cloud, DevOps, and security technologies.
  • Technology Summary: AWS, HashiCorp (Terraform, Vault, Consul, Nomad), Docker, Prometheus, Grafana, CloudWatch, Python, Kali Linux, Metasploit, Nessus, Burp Suite, OWASP ZAP, Tenable, SonarQube.

Cybersecurity / IT Security Engineer

Aug 2021 - May 2022
Data warden,
  • Security testing (Pentest) and vulnerability management.
  • Automation for vulnerability and risk analysis using Python and Nucleus.
  • Implementation of SIEM and security event monitoring solutions.
  • Technology Summary: IBM QRadar, Kali Linux, Burp Suite, Fortify, Tenable, Checkpoint VPN, Python, Nessus.

Cybersecurity / IT Security Engineer

Jan 2019 - Dec 2019
BBVA Bank,
  • Compliance with security policies, updates, regulations, and permissions.
  • Implementation and management of BBVA's internal IT security products.
  • Hardening of servers and services to enhance security.
  • Vulnerability and risk analysis of infrastructure.
  • Deployment and release automation with HashiCorp Terraform and DC/OS.
  • Technology Summary: Burp Suite, Nessus, Metasploit, HashiCorp Vault, PFSense, Proxmox, Ansible, Python, Docker.

DevOps Engineer

Mar 2018 - Dec 2018
Huawei, Claro Video, Telefonica,
  • DevOps support for development teams across LATAM.
  • Design and implementation of CI/CD pipelines and environment creation with Terraform and Ansible.
  • CI/CD for applications with Java, Spring Boot, TypeScript, Angular, Django, Go lang.
  • Integration of monitoring and log analysis with ELK Stack and Grafana.
  • Technology Summary: Huawei Cloud, HashiCorp Terraform, Packer, Jenkins, Ansible, Docker, Grafana, ELK Stack.

System Engineer

Mar 2016 - Nov 2017
Seguros Monterrey,
  • Digital Transformation. Implementation of the Red Hat cloud platform in Seguros Monterrey's data center.
  • Security and hardening implementation in Linux infrastructure. Migration of Windows services to Linux.
  • Compliance with PCI DSS, CIS, and DISA STIG standards.
  • Technology Summary: Red Hat Linux, SELinux, OpenSCAP, Puppet, OpenStack, Ansible, Satellite, OpenShift.

System Engineer & Technical Lead

Mar 2014 - Mar 2016
Produban, Santander Bank,
  • Led IT infrastructure and operations for Santander Bank, supporting 7,000+ servers and 1,000+ internal projects. Progressed from System Engineer to Technical Lead, taking full ownership of team management, automation, and infrastructure delivery.
  • Leadership & Operations: Managed a team of 8 engineers; oversee resource planning, infrastructure operations, and IT provisioning to ensure scalability, security, and compliance.
  • Process Optimization: Implemented ITIL best practices and Lean Six Sigma methodologies, cutting incident resolution time by 50% and reducing infrastructure delivery time by 60%.
  • Infrastructure Automation: Designed Infrastructure-as-Code (IaC) using Terraform, Packer, and Vagrant. Automated provisioning via Ansible and Python, reducing environment build time by 50%.
  • System Administration: Managed Red Hat Linux (v6/v7) and Windows servers; performed OS hardening and security configuration per banking regulations.
  • Enterprise Tools: Administered Veritas Cluster, IBM WebSphere/MQ, BladeLogic, Control-M, NetBackup, and Tivoli.
  • DevOps Enablement: Promoted DevOps culture across teams, standardizing build/configuration processes to improve speed, security, and consistency.
  • Tools & Technologies: ITIL, Lean Six Sigma, DevOps, VMware ESX, Ansible, Terraform, Packer, Vagrant, Python, Shell Scripting, Git, Linux (RHEL), Windows Server, WebSphere, MQ, BladeLogic, Control-M, Tivoli, NetBackup.

Cybersecurity & System Engineer

2004 - 2013
Telefonica, Grant Thornton, Proweb, Bandes Bank (Consolidated professional experience),
  • Delivered end-to-end infrastructure and cybersecurity services across multiple organizations, systems in telecom, finance, and consulting firms.
  • Infrastructure Management: Administered Windows, Linux, and UNIX (SunOS/Solaris, HP-UX) production and pre-production environments. Conducted performance tuning, capacity planning, and continuous improvement initiatives.
  • Automation & Orchestration: Streamlined operations with Ansible, CFEngine, Python, and Bash (pdsh, pssh), reducing manual work and enabling automated service remediation.
  • Security Hardening & Risk Management: Implemented server and application security baselines, developed custom audit/reporting tools, and maintained compliance with internal controls.
  • Compliance & Governance: Led ISO 27001 and PCI DSS implementation efforts — policies, evidence gathering, and remediation.
  • Threat Detection & Response: Deployed and operated SIEM/IDS tools (AlienVault OSSIM, Snort, OpenVAS, Suricata, Nagios), correlating security events and leading incident response.
  • Cloud & Virtualization: Managed provider infrastructure including OpenVZ, Unix Jail, web applications, and virtualization platforms, ensuring high availability and performance.
Technical Skills

Infrastructure and Application Security:

Pentesting, Ethical Hacking, Hardening, Risk Analysis

Cloud & Architecture:

AWS, Azure, Huawei Cloud, VMware, Proxmox

Automation & CI/CD:

DevOps, HashiCorp Terraform, Vault, Nomad, Consul, Ansible, Kubernetes, GitHub Actions, Docker

Standards and Regulatory Compliance:

Lean Six Sigma in IT, ISO 27001, PCI DSS, ITIL, NIST 800-53

Projects

Highlighted Projects

Automation with HashiStack & Migration to AWS Cloud

Led the migration of critical services to Amazon Web Services (AWS) while designing and implementing full infrastructure automation using HashiCorp’s HashiStack. Built automated infrastructure pipelines with Packer and Terraform, integrating AWS services including IAM, KMS, RDS, S3, ALB, VPC, EC2, Auto Scaling, and Security Groups. Secured secrets and access management with Vault, migrated workloads to containers orchestrated with Nomad, and implemented Consul for service discovery, monitoring, and load balancing. Additionally, designed and delivered staff training programs on the new infrastructure, including hands-on workshops for Terraform, Nomad, Consul, and Vault, ensuring smooth adoption and operational readiness. This project resulted in a highly scalable, secure, and production-ready cloud environment, reducing deployment times and improving operational reliability.

Red Hat Cloud Infrastructure – On-Premise Deployment

Led the design and implementation of a Red Hat–based private cloud within enterprise data centers, leveraging open-source technologies and Red Hat products. Automated server provisioning, OS hardening, monitoring, and patch management using Ansible, Red Hat Satellite, and CloudForms. Strengthened security with SELinux, AIDE, OpenSCAP, OpenVAS, iptables, and Firewalld, ensuring compliance with STIG, DISA FSO, PCI DSS, CIS Benchmarks, and ISO 27001. Delivered a scalable, secure on-premise cloud environment using OpenStack, OpenShift, Ceph, and Gluster Storage, significantly reducing provisioning times and improving compliance reporting.

IT provisioning Automation

Designed and implemented end-to-end automation for server provisioning and application deployment in Red Hat Enterprise Linux environments. Automated the installation, configuration, and hardening of servers, ensuring compliance with corporate security standards. Streamlined deployment of enterprise applications, including Oracle Database, IBM WebSphere, WebSphere MQ, and IBM HTTP Server, as well as agent configuration for Changeman, Tivoli, Bladelogic, Control-M, and NetBackup. This initiative significantly reduced manual effort, deployment time, and configuration errors, enabling faster and more reliable production rollouts.

Automated Remediation of Production Incidents

Led a project to proactively analyze production issues using metrics, advanced monitoring, and root cause analysis to identify recurring service-impacting problems. Developed custom tools and scripts to automatically detect and remediate these issues in real time. This solution reduced service incidents, minimized false alerts, and improved overall system availability, allowing engineers to focus on high-value tasks instead of repetitive manual fixes.

OSSIM AlienVault SIEM Implementation

Led the end-to-end deployment of an OSSIM AlienVault SIEM solution in enterprise servers, configuring log collection, event parsing, alert thresholds, and automated response actions using Python scripting. Integrated log sources across critical servers and services, ensuring full visibility into security events. Conducted a comprehensive security and compliance audit aligned with ISO 27001 and internal banking policies, and delivered training sessions for security teams on SIEM administration and best practices. This project significantly improved threat detection, reduced incident response times, and strengthened overall compliance posture.

Certifications & Training

A selection of the most relevant certifications and courses.

AWS Cloud Practitioner Essentials

2025

AWS

Penetration Tester & Red Team Operator

2021, 2024

HackTheBox

Certified Professional Penetration Tester (eCPPT)

2020

eLearnSecurity/INE

Certified Ethical Hacker (CEH)

2019

EC-Council

Programming with Google Go Specialization

2019

University of California, Irvine (UCI)

DevOps: Transforming and Improving Operations

2018

Linux Foundation

Red Hat System Administrator & Engineer

2017

SimpleLearn

Lean Six Sigma in IT

2016

Management & Strategy Institute

ITIL Foundation & CISA

2015, 2018

SimpliLearn

Languages

Spanish

Native

English

Professional (B2-C1)