Senior Cloud & Cybersecurity Engineer | DevOps & Infrastructure Automation
IT professional with 15+ years of experience in infrastructure, cybersecurity, and automation. Specialized in designing and implementing secure enterprise architectures, leading cloud migration initiatives (AWS & hybrid environments), and optimizing processes through Infrastructure as Code (Terraform, Ansible, custom tools), CI/CD pipelines, and Lean Six Sigma practices. Proven track record in the banking and telecommunications sectors, ensuring business continuity, regulatory compliance, and secure, high-availability systems. Recognized for quickly mastering new technologies and delivering solutions to complex challenges.
Pentesting, Ethical Hacking, Hardening, Risk Analysis
AWS, Azure, Huawei Cloud, VMware, Proxmox
DevOps, HashiCorp Terraform, Vault, Nomad, Consul, Ansible, Kubernetes, GitHub Actions, Docker
Lean Six Sigma in IT, ISO 27001, PCI DSS, ITIL, NIST 800-53
Highlighted Projects
Led the migration of critical services to Amazon Web Services (AWS) while designing and implementing full infrastructure automation using HashiCorp’s HashiStack. Built automated infrastructure pipelines with Packer and Terraform, integrating AWS services including IAM, KMS, RDS, S3, ALB, VPC, EC2, Auto Scaling, and Security Groups. Secured secrets and access management with Vault, migrated workloads to containers orchestrated with Nomad, and implemented Consul for service discovery, monitoring, and load balancing. Additionally, designed and delivered staff training programs on the new infrastructure, including hands-on workshops for Terraform, Nomad, Consul, and Vault, ensuring smooth adoption and operational readiness. This project resulted in a highly scalable, secure, and production-ready cloud environment, reducing deployment times and improving operational reliability.
Led the design and implementation of a Red Hat–based private cloud within enterprise data centers, leveraging open-source technologies and Red Hat products. Automated server provisioning, OS hardening, monitoring, and patch management using Ansible, Red Hat Satellite, and CloudForms. Strengthened security with SELinux, AIDE, OpenSCAP, OpenVAS, iptables, and Firewalld, ensuring compliance with STIG, DISA FSO, PCI DSS, CIS Benchmarks, and ISO 27001. Delivered a scalable, secure on-premise cloud environment using OpenStack, OpenShift, Ceph, and Gluster Storage, significantly reducing provisioning times and improving compliance reporting.
Designed and implemented end-to-end automation for server provisioning and application deployment in Red Hat Enterprise Linux environments. Automated the installation, configuration, and hardening of servers, ensuring compliance with corporate security standards. Streamlined deployment of enterprise applications, including Oracle Database, IBM WebSphere, WebSphere MQ, and IBM HTTP Server, as well as agent configuration for Changeman, Tivoli, Bladelogic, Control-M, and NetBackup. This initiative significantly reduced manual effort, deployment time, and configuration errors, enabling faster and more reliable production rollouts.
Led a project to proactively analyze production issues using metrics, advanced monitoring, and root cause analysis to identify recurring service-impacting problems. Developed custom tools and scripts to automatically detect and remediate these issues in real time. This solution reduced service incidents, minimized false alerts, and improved overall system availability, allowing engineers to focus on high-value tasks instead of repetitive manual fixes.
Led the end-to-end deployment of an OSSIM AlienVault SIEM solution in enterprise servers, configuring log collection, event parsing, alert thresholds, and automated response actions using Python scripting. Integrated log sources across critical servers and services, ensuring full visibility into security events. Conducted a comprehensive security and compliance audit aligned with ISO 27001 and internal banking policies, and delivered training sessions for security teams on SIEM administration and best practices. This project significantly improved threat detection, reduced incident response times, and strengthened overall compliance posture.
A selection of the most relevant certifications and courses.
AWS
HackTheBox
eLearnSecurity/INE
EC-Council
University of California, Irvine (UCI)
Linux Foundation
SimpleLearn
Management & Strategy Institute
SimpliLearn
Native
Professional (B2-C1)