Skip to content

Sacm89-Code/Sacm89-Code

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

19 Commits
 
 

Repository files navigation

Hi 👋, I'm Simón Cervantes

Principal DevSecOps & Cloud Architect · Cybersecurity Specialist · Applied AI Engineer

📍 Almería, Spain · 12+ years building secure, scalable and intelligent systems
Azure · AWS · GCP · DevSecOps · Cybersecurity · AI Agents


🧭 Professional Profile

Technology professional with 12+ years of experience in IT, evolving from software development into cloud architecture, DevSecOps, cybersecurity and applied artificial intelligence.

I have designed and operated enterprise-scale systems across Azure, AWS and GCP, leading initiatives in infrastructure automation, CI/CD, cloud governance and security-by-design.

In recent years, I consolidated my profile as a DevSecOps and Cybersecurity specialist, and during the last year I have focused on AI-driven solutions and autonomous agents that solve real operational and business problems.

My approach is architectural, pragmatic and security-first, always aligned with enterprise, regulatory and business requirements.


🧱 Career Evolution

  • Software Engineer → Backend, APIs, distributed systems
  • Cloud Architect → Azure, AWS, GCP, enterprise services
  • DevOps / DevSecOps Engineer → automation, CI/CD, GitOps
  • Cybersecurity Specialist → Red Team & Blue Team, governance, SOC, SGSI
  • Applied AI Engineer → LLMs, AI agents, intelligent automation

💼 Professional Experience

DevSecOps & AI Engineer · Navantia (Public Sector)

Cartagena, Spain · 07/2025 – Present

  • Architecture and automation of secure cloud environments on Azure for AI, data and RPA platforms
  • Design and implementation of AI agent-based systems using Azure AI Foundry and Azure OpenAI
  • Development of intelligent agents with Semantic Kernel, LangChain and custom orchestration
  • Integration of AI workloads with Microsoft Fabric (data engineering, analytics and pipelines)
  • Deployment of NLP and LLM-based solutions using OpenAI API and Hugging Face
  • Secure integration with enterprise platforms (SAP, UiPath)
  • Risk analysis, threat modeling and ENS compliance for AI-driven applications
  • Identity, secrets and privileged access management with CyberArk, IAM and Key Vault

DevSecOps Engineer / Cloud Architect · NTT DATA

Murcia, Spain · 09/2023 – 04/2025

  • Cloud architecture and DevSecOps leadership for public and private sector projects
    (Telefónica, ICO, Madrid Digital, judicial and government platforms)
  • Design of secure microservices architectures with cloud-first security principles
  • Infrastructure as Code using Terraform, Ansible and cloud-native templates
  • CI/CD and GitOps pipelines with GitLab CI, Jenkins, ArgoCD, Tekton
  • Kubernetes platforms: AKS, EKS, GKE, OpenShift
  • API management and security with WSO2
  • Progressive adoption of AI-assisted development and internal tooling
  • Python-based development for productivity and automation
    (FastAPI, Flask, Django, Pydantic, Celery, SQLAlchemy)
  • Technical governance, documentation and DevSecOps best practices

DevOps & Automation Specialist · Viewnext

Almería, Spain · 07/2021 – 09/2023

  • CI/CD pipelines with Jenkins, SonarQube, Nexus and Docker
  • Infrastructure automation using Terraform, Bash and Kubernetes
  • Banking and critical systems (Banco de España – CIRBE)
  • Performance optimization (SQL, batch processes, critical workloads)
  • Monitoring, observability and operational audits

🛡️ Cybersecurity

🔵 Blue Team / Defense (Primary Focus)

  • Security monitoring, detection and response
  • SIEM & SOC operations
  • Cloud-native security and posture management
  • Incident response and forensic analysis

Tools & Platforms

  • SIEM: Wazuh, Splunk, ELK Stack
  • Detection: Microsoft Defender, Suricata, Snort
  • Cloud Security: Defender for Cloud, CSPM
  • Forensics: Autopsy, log and disk analysis

🔴 Red Team / Pentesting (Supporting Defense)

  • Web & API Pentesting (OWASP Top 10)
  • Infrastructure and Active Directory testing
  • Vulnerability discovery and exploitation (controlled environments)

Tools

  • Nmap, Nessus
  • Burp Suite, OWASP ZAP
  • Metasploit Framework
  • SQLmap, Gobuster, Hydra
  • Kali Linux, BlackArch

🟣 Purple Team

  • Attack simulation to improve detection and response
  • Continuous feedback between offensive and defensive teams
  • Detection engineering and tuning

📜 Governance, Risk & Compliance

  • ENS (Spain)
  • ISO/IEC 27001 & 27002
  • NIST Cybersecurity Framework
  • Secure SDLC
  • CIS Benchmarks, STIGs
  • SGSI design and implementation

☁️ Cloud Architecture & DevSecOps

Cloud Platforms

  • Azure (core): App Service, AKS, Functions, Key Vault, Monitor, Defender for Cloud
  • AWS: EC2, EKS, IAM, VPC, CloudWatch
  • GCP: GKE, IAM, networking services

Infrastructure as Code & Automation

  • Terraform
  • Ansible
  • Helm
  • ARM / CloudFormation

CI/CD, GitOps & Platforms

  • Jenkins
  • GitLab CI
  • GitHub Actions
  • ArgoCD
  • Tekton
  • FluxCD
  • Docker, Kubernetes, OpenShift

🤖 Artificial Intelligence & Intelligent Automation

Foundations

  • Machine Learning fundamentals
  • NLP concepts
  • Transformers, embeddings, semantic search

Applied AI & LLMs

  • OpenAI / GPT
  • Azure OpenAI
  • Hugging Face
  • Prompt engineering
  • RAG (Retrieval-Augmented Generation)

AI Agents & Orchestration

  • Semantic Kernel
  • LangChain
  • Multi-agent systems
  • Tool-augmented agents
  • Autonomous workflows

Emerging Areas

  • Agentic architectures
  • Reasoning models
  • AI governance and safety
  • Enterprise-grade AI adoption

💻 Development Stack

  • Languages: Python, Java, JavaScript, Bash, PowerShell
  • Frameworks: FastAPI, Flask, Django, Spring Boot, Node.js
  • Databases: PostgreSQL, MySQL, MongoDB
  • Architecture: REST APIs, microservices, distributed systems

🎯 Current Focus

  • Secure cloud architectures with embedded AI
  • Enterprise-grade AI agents and automation
  • DevSecOps and cloud governance at scale
  • Blue Team cybersecurity and compliance
  • High-impact systems aligned with business value

Connect with me:

About

Intro

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published