Skip to content
View Sacm89-Code's full-sized avatar
:octocat:
Working from home
:octocat:
Working from home

Block or report Sacm89-Code

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Sacm89-Code/README.md

Hi 👋, I'm Simón Cervantes

Principal DevSecOps & Cloud Architect · Cybersecurity Specialist · Applied AI Engineer

📍 Almería, Spain · 12+ years building secure, scalable and intelligent systems
Azure · AWS · GCP · DevSecOps · Cybersecurity · AI Agents


🧭 Professional Profile

Technology professional with 12+ years of experience in IT, evolving from software development into cloud architecture, DevSecOps, cybersecurity and applied artificial intelligence.

I have designed and operated enterprise-scale systems across Azure, AWS and GCP, leading initiatives in infrastructure automation, CI/CD, cloud governance and security-by-design.

In recent years, I consolidated my profile as a DevSecOps and Cybersecurity specialist, and during the last year I have focused on AI-driven solutions and autonomous agents that solve real operational and business problems.

My approach is architectural, pragmatic and security-first, always aligned with enterprise, regulatory and business requirements.


🧱 Career Evolution

  • Software Engineer → Backend, APIs, distributed systems
  • Cloud Architect → Azure, AWS, GCP, enterprise services
  • DevOps / DevSecOps Engineer → automation, CI/CD, GitOps
  • Cybersecurity Specialist → Red Team & Blue Team, governance, SOC, SGSI
  • Applied AI Engineer → LLMs, AI agents, intelligent automation

💼 Professional Experience

DevSecOps & AI Engineer · Navantia (Public Sector)

Cartagena, Spain · 07/2025 – Present

  • Architecture and automation of secure cloud environments on Azure for AI, data and RPA platforms
  • Design and implementation of AI agent-based systems using Azure AI Foundry and Azure OpenAI
  • Development of intelligent agents with Semantic Kernel, LangChain and custom orchestration
  • Integration of AI workloads with Microsoft Fabric (data engineering, analytics and pipelines)
  • Deployment of NLP and LLM-based solutions using OpenAI API and Hugging Face
  • Secure integration with enterprise platforms (SAP, UiPath)
  • Risk analysis, threat modeling and ENS compliance for AI-driven applications
  • Identity, secrets and privileged access management with CyberArk, IAM and Key Vault

DevSecOps Engineer / Cloud Architect · NTT DATA

Murcia, Spain · 09/2023 – 04/2025

  • Cloud architecture and DevSecOps leadership for public and private sector projects
    (Telefónica, ICO, Madrid Digital, judicial and government platforms)
  • Design of secure microservices architectures with cloud-first security principles
  • Infrastructure as Code using Terraform, Ansible and cloud-native templates
  • CI/CD and GitOps pipelines with GitLab CI, Jenkins, ArgoCD, Tekton
  • Kubernetes platforms: AKS, EKS, GKE, OpenShift
  • API management and security with WSO2
  • Progressive adoption of AI-assisted development and internal tooling
  • Python-based development for productivity and automation
    (FastAPI, Flask, Django, Pydantic, Celery, SQLAlchemy)
  • Technical governance, documentation and DevSecOps best practices

DevOps & Automation Specialist · Viewnext

Almería, Spain · 07/2021 – 09/2023

  • CI/CD pipelines with Jenkins, SonarQube, Nexus and Docker
  • Infrastructure automation using Terraform, Bash and Kubernetes
  • Banking and critical systems (Banco de España – CIRBE)
  • Performance optimization (SQL, batch processes, critical workloads)
  • Monitoring, observability and operational audits

🛡️ Cybersecurity

🔵 Blue Team / Defense (Primary Focus)

  • Security monitoring, detection and response
  • SIEM & SOC operations
  • Cloud-native security and posture management
  • Incident response and forensic analysis

Tools & Platforms

  • SIEM: Wazuh, Splunk, ELK Stack
  • Detection: Microsoft Defender, Suricata, Snort
  • Cloud Security: Defender for Cloud, CSPM
  • Forensics: Autopsy, log and disk analysis

🔴 Red Team / Pentesting (Supporting Defense)

  • Web & API Pentesting (OWASP Top 10)
  • Infrastructure and Active Directory testing
  • Vulnerability discovery and exploitation (controlled environments)

Tools

  • Nmap, Nessus
  • Burp Suite, OWASP ZAP
  • Metasploit Framework
  • SQLmap, Gobuster, Hydra
  • Kali Linux, BlackArch

🟣 Purple Team

  • Attack simulation to improve detection and response
  • Continuous feedback between offensive and defensive teams
  • Detection engineering and tuning

📜 Governance, Risk & Compliance

  • ENS (Spain)
  • ISO/IEC 27001 & 27002
  • NIST Cybersecurity Framework
  • Secure SDLC
  • CIS Benchmarks, STIGs
  • SGSI design and implementation

☁️ Cloud Architecture & DevSecOps

Cloud Platforms

  • Azure (core): App Service, AKS, Functions, Key Vault, Monitor, Defender for Cloud
  • AWS: EC2, EKS, IAM, VPC, CloudWatch
  • GCP: GKE, IAM, networking services

Infrastructure as Code & Automation

  • Terraform
  • Ansible
  • Helm
  • ARM / CloudFormation

CI/CD, GitOps & Platforms

  • Jenkins
  • GitLab CI
  • GitHub Actions
  • ArgoCD
  • Tekton
  • FluxCD
  • Docker, Kubernetes, OpenShift

🤖 Artificial Intelligence & Intelligent Automation

Foundations

  • Machine Learning fundamentals
  • NLP concepts
  • Transformers, embeddings, semantic search

Applied AI & LLMs

  • OpenAI / GPT
  • Azure OpenAI
  • Hugging Face
  • Prompt engineering
  • RAG (Retrieval-Augmented Generation)

AI Agents & Orchestration

  • Semantic Kernel
  • LangChain
  • Multi-agent systems
  • Tool-augmented agents
  • Autonomous workflows

Emerging Areas

  • Agentic architectures
  • Reasoning models
  • AI governance and safety
  • Enterprise-grade AI adoption

💻 Development Stack

  • Languages: Python, Java, JavaScript, Bash, PowerShell
  • Frameworks: FastAPI, Flask, Django, Spring Boot, Node.js
  • Databases: PostgreSQL, MySQL, MongoDB
  • Architecture: REST APIs, microservices, distributed systems

🎯 Current Focus

  • Secure cloud architectures with embedded AI
  • Enterprise-grade AI agents and automation
  • DevSecOps and cloud governance at scale
  • Blue Team cybersecurity and compliance
  • High-impact systems aligned with business value

Connect with me:

Popular repositories Loading

  1. next.roadmap.sh next.roadmap.sh Public

    Forked from iamgini/roadmap.sh

    Next version of roadmap.sh

    Astro 1

  2. ProyectoFinaldeCiberseguridad_4Geeks ProyectoFinaldeCiberseguridad_4Geeks Public

    1

  3. hello-compose-wordpress hello-compose-wordpress Public

    Uso de docker-compose para crear un stack de Wordpress

  4. hello-gradle hello-gradle Public

    Forked from devops-summer21/hello-gradle

    Java project using gradle

    Dockerfile

  5. git-katas git-katas Public

    Forked from eficode-academy/git-katas

    A set of exercises for deliberate Git Practice

    Shell

  6. hello-springboot hello-springboot Public

    Groovy