Outcomes, measured
Figures carried over from the record, with the mechanism that produced each one. Nothing here is an estimate.
- 243
core applications migrated from legacy KOPS to AWS EKS 1.33
zero customer-facing downtime via Route53 weighted routing, Argo Rollouts and Istio traffic shifting
- 35%
EC2 spend reduction
Karpenter consolidation, ARM64 Graviton node pools and automated spot execution
- 40%
LATAM cloud operating cost reduction
FinOps rightsizing, automated resource lifecycle management and decommissioning
- 75%
deployment lead-time reduction
quarterly release batches replaced by continuous production delivery
What I actually run
48 tools, rated for depth rather than exposure. Amber marks the ones this career is built around.
Depth 1–5 · 5 = designs, owns and debugs it unaided in production
Languages
10- Bash
- C#
- Go
- Groovy
- Java
- PowerShell
- Python
- Rust
- SQL
- Ruby
Cloud
3- AWS
- Azure
- GCP
Orchestration
9- Argo Rollouts
- ArgoCD
- Docker
- EKS
- Helm
- Istio
- Karpenter
- Kubernetes
- KOPS
Infrastructure as Code
4- OpenTofu
- Terraform
- Terragrunt
- Pulumi
Observability
9- Alloy
- Grafana
- Jaeger
- Kiali
- Prometheus
- CloudWatch
- Datadog
- Loki
- OpenTelemetry
Data
8- Redshift
- Step Functions
- Apache Airflow
- Athena
- AWS Glue
- PostgreSQL
- Lake Formation
- Liquibase
Security
5- Snyk
- SonarQube
- SOPS
- Consul
- HashiCorp Vault
Where the work happened
Retail banking, telecom, quick-service restaurant e-commerce, EdTech, agribusiness and B2B SaaS — the constant is production systems other people depend on.
Oct 2024 — Present/1 yr 10 mos
Viafoura
B2B customer-community and social-engagement SaaS
Senior SRE Cloud Engineer
- Led the KOPS 1.18.20 to AWS EKS 1.33 migration of the core application estate using Route53 weighted routing, Argo Rollouts and Istio traffic shifting, completing cutover without customer-facing downtime.
- Containerized legacy workloads and authored Helm charts guarded by values.schema.json, rejecting invalid GitOps values before they reach a cluster.
- Provisioned data-lake and analytics infrastructure with Terraform and OpenTofu across Athena, Glue Data Catalog, Redshift, Step Functions and Airflow, applying Lake Formation column- and table-level governance for least-privilege analyst access.
- Codified observability as infrastructure in Terraform across Grafana Cloud dashboards, Loki log pipelines, Prometheus alert rules, Datadog dashboards and label-based Slack routing with OpenTelemetry.
- Standardized multi-account governance with AWS Account Factory for Terraform, Well-Architected guardrails and IAM Identity Center, and migrated legacy Jenkins jobs to declarative GitHub Actions reusable workflows with ArgoCD-centralized GitOps enabling canary and blue-green releases.
Oct 2023 — Oct 2024/1 yr
Stanza Systems
Senior SRE Cloud Engineer
- Tuned Karpenter-based autoscaling and cluster ingress to absorb variable demand without over-provisioning.
- Gated production deployment with Semgrep and Snyk scanning, SonarQube quality gates, SOPS-encrypted Helm secrets and ArgoCD sync policies.
- Moved application delivery onto declarative GitOps, with ArgoCD reconciling Helm releases against Git so live EKS state could not drift from the committed source.
- Imported existing AWS resources into Terraform state, bringing hand-provisioned infrastructure under version control and plan review.
- Provisioned secure Amazon SageMaker and Bedrock endpoints with Terraform using scoped IAM execution roles, VPC network isolation and per-workload budget guardrails.
- Maintained multi-environment GitLab CI/CD pipelines enforcing a strict validate, plan and gated apply workflow with Jira ticket-first traceability.
Apr 2022 — Sep 2023/1 yr 5 mos
Nutrien Agriculture Solutions
agribusiness
SRE Cloud Engineering Manager
- Led the LATAM Cloud Engineering cross-squad team supporting downstream software and data engineering squads, building a high-density automation framework rather than growing headcount.
- Architected multi-account hub-and-spoke infrastructure across AWS, Azure and GCP using Transit Gateway, VPC, VPN and centralized identity, consolidating shared data platform services including data lakes, Glue, Lambda, RDS and Redshift.
- Established platform self-service patterns and GitHub Actions reusable workflows that replaced batch releases with continuous production delivery.
- Drove FinOps rightsizing, automated resource lifecycle management and decommissioning, reporting spend directly to the director.
- Mentored senior and junior engineers into end-to-end incident ownership.
Nov 2021 — Apr 2022/5 mos
Passei Direto
high-traffic EdTech SaaS
Senior SRE Cloud Engineer
- Refactored core infrastructure and tuned application performance across AWS VPC, EC2, ECS and Lambda to defend availability under sudden enrolment-driven traffic surges.
- Implemented infrastructure as code with Terraform, Terragrunt and Pulumi, and maintained CI/CD across Jenkins and GitHub Actions.
- Hardened platform tooling including HashiCorp Vault secret delivery, Backstage service catalog and shared Jenkins libraries, instrumenting Sentry error tracking and SonarQube analysis.
Nov 2018 — Nov 2021/3 yrs/2 roles
RDI Software - Capgemini Americas Subsidiary
quick-service restaurant e-commerce
DevOps Engineering Lead
Mar 2020 — Nov 2021/1 yr 8 mos
- Led a distributed engineering group across the US, Hungary, India and Brazil, establishing delivery KPIs and unifying incident ownership for high-stakes e-commerce order and payment operations.
- Migrated the traffic layer from standard ingress controllers to Istio service mesh and from MuleSoft to AWS API Gateway using progressive traffic shifting, completing both cutovers without customer transaction impact.
- Operated service discovery and secret management with HashiCorp Consul and Vault, removing static credentials from microservice deployment paths.
Senior Software Developer
Nov 2018 — Mar 2020/1 yr 4 mos
- Engineered the decomposition of a monolithic e-commerce platform into decoupled microservices handling order and payment loops, using Terraform, Helm and reusable Kubernetes deployment modules to isolate failure domains.
- Automated infrastructure provisioning and operational tooling with Terraform, Helm, Bash, Python, Ruby, Go and PowerShell across AWS EC2, S3 and Lambda.
- Delivered C# fixes in the product layer and drove live upgrades on production KOPS clusters.
Jul 2017 — Nov 2018/1 yr 4 mos
RDI Software - McDonalds Subsidiary
quick-service restaurant e-commerce
Software Developer
- Developed features and defect fixes for a global quick-service restaurant e-commerce platform using C# and .NET.
- Automated infrastructure provisioning with Terraform and Chef across multiple Linux distributions.
May 2016 — Jul 2017/1 yr 2 mos
WF - Brains For Your Business
high-volume banking
DevOps
- Built automated CI/CD pipelines from scratch with Jenkins and GitLab SCM for high-volume banking systems at a top-tier Brazilian bank.
- Managed IT infrastructure including servers, networks and Zabbix monitoring, and developed IoT-connected web and support systems.
Earlier · 3 roles
- Nov 2014 — May 2016Questor SistemasSoftware Developer
- Apr 2008 — Aug 2014BradescoJunior Software Developer
- Jun 2007 — Apr 2008Worktime Assessorial LtdaInformation Technology Infrastructure Analyst
Published, and checkable
Infrastructure tooling on crates.io and the Terraform Registry, authored and maintained across two accounts. Every row below links to a public package page.
registry downloads across 9 published packages
- rust-yamlnative YAML parsing crate published to crates.ioRust cratecrates.io26,498
- strcase Terraform providerofficial Terraform Registry provider that supplies string case conversion functions to Terraform configurationsTerraform providerregistry.terraform.io3,897
- kind Terraform providerofficial Terraform Registry provider that provisions ephemeral Kubernetes-in-Docker clusters for CI and local test harnessesTerraform providerregistry.terraform.io898
- Docker Terraform providerofficial Terraform Registry provider that manages container lifecycle and image resources declarativelyTerraform providerregistry.terraform.io684
- dnsmasq Terraform providerofficial Terraform Registry provider that brings local DNS record management under declarative infrastructure as codeTerraform providerregistry.terraform.io453
- SOPS Terraform providerofficial Terraform Registry provider that lets practitioners decrypt SOPS-managed secrets natively inside Terraform plansTerraform providerregistry.terraform.io235
- glaucusSafe YAML for Rust — zero unsafe by defaultRust cratecrates.io129
- complyREUSE Specification compliance tool and library: lint, annotate, and fix SPDX license headersRust cratecrates.io67
- ignorefilenative YAML parsing crate published to crates.ioRust cratecrates.io36
Formal record
Education
BENG · Data Processing
São Paulo Faculty Of Technology
2005
Specialization · Software Engineering
PUC-SP
In progress
Certifications · 11
Anthropic
- Claude Code 101
- Claude 101
- Introduction to Agent Skills
Pluralsight
- AWS Engineer
4Linux
- Advanced Penetration Testing & Corporate Network Intrusion Testing
Nic.br
- IPv6 Systems
Alura
- Programming Logic I: Start Your Career with JavaScript
- Programming Logic II: Functions, Drawings, and a Game
- PostgreSQL I: First Steps with Your Queries
- UML: An Introduction to Modeling
- C# I: Language Fundamentals