MG.dev

Available full-time or on contract · Remote

Marcos Gómez.

DevSecOps & Cloud Security Engineer

I bring security into the pipeline and the server without slowing delivery, and I back it with numbers: 99.9% uptime, zero breaches and −25% technical exposure. I show results, I don't promise them.

  • Pipeline security: OWASP, SAST and secret scanning before every deploy.
  • Linux and cloud hardened to CIS level, with evidence you can verify by command.
  • SOC run and measured: detection, triage and remediation with SLAs.
Cloud SecurityDevSecOpsAppSecLinux HardeningVulnerability ManagementSOC & Threat HuntingCI/CD SecurityAWS / OCIISO 27001 / NIST

Brasil · Remoto

01Results in production

Measurable wins from real projects: every number came out of a production system, not a slide.

99.9%

Sustained uptime

Global e-commerce (Brazil, US, EU and Australia) on Linux and Nginx, with zero security breaches.

+30%

SIEM detection

Alert fidelity in the SIEM/SOAR over six months, tuning custom detection rules.

−25%

Technical exposure

Vulnerability management with Nessus and Nmap and remediation prioritised by ISO 27001 risk.

−40%

Page load time

Web optimisation without trading security; services isolated with Docker and Podman.

02What I can do for your team

Four fronts that come back in every project, from the pipeline down to the host.

Pipeline security

Secret scanning, SAST, dependency and image scanning running on every pull request: what fails is the build, not production. Explicit severity policy and SARIF as evidence.

Linux and cloud hardening

Key-only SSH on a non-standard port, default-deny firewall, fail2ban, auditd, kernel parameters and an idempotent deployment you can verify with one command.

Observability and SOC

SIEM with agents across the fleet, Grafana dashboards, custom rules and automated triage. Alerts you can explain and metrics you can decide with.

Vulnerability to remediation

Inventory, authenticated scanning, prioritisation by real risk and a patch cycle with SLAs. Fewer open findings, more closable ones.

03Experience

From financial operations to the SOC and the pipeline: 20+ years building, and lately defending what was built.

  1. Soulta Beauty

    Jan 2021 — present

    DevSecOps & IT Infrastructure Engineer · Brusque, SC · Remote

    • Global e-commerce infrastructure (Brazil, US, EU and Australia) on Linux and Nginx, with 99.9% sustained uptime.
    • Cloudflare DNS and WAF policies that mitigate Layer 7 attacks and block OWASP Top 10 patterns.
    • CI/CD security controls — secrets, dependencies and code — before every deployment.
    • 40% reduction in page load time without trading away security; services isolated with Docker and Podman.
    LinuxNginxCloudflare WAFDocker/PodmanCI/CDOWASPWooCommerce
  2. NexuTrek

    Sep 2018 — present

    Founder & Cloud Infrastructure Consultant · Brazil · Remote

    • Architecture and administration of dedicated VPS environments (OVH) with HestiaCP, Nginx and PHP-FPM.
    • Multi-domain and email migrations using MySQL and imapsync, with no service downtime.
    • n8n automations integrating WhatsApp Cloud API, Bling ERP and Melhor Envio.
    • Custom PHP/WordPress development and AI-assisted coding tools (Ollama, Cursor, Roo Code) to speed up delivery with security review.
    HestiaCPNginxPHP-FPMMySQLn8nVPS/OVHimapsync
  3. ATHSec

    May 2023 — Jan 2025

    Cyber Security Analyst · Remote

    • Continuous vulnerability assessment and asset discovery with Nessus, Nmap and in-house Bash and Python tooling.
    • SIEM/SOAR rule tuning: +30% detection fidelity in six months, with zero breaches.
    • Remediation prioritised against ISO 27001 risk matrices.
    • Reconnaissance and Markdown reporting assistants for bug bounty programmes.
    NessusNmapSIEM/SOARISO 27001PythonBash
  4. Agencia IDEALIDAD

    Jul 2014 — Feb 2023

    IT Security & Systems Engineer · Bogotá, CO · Remote

    • Security audits, source-code review and malware remediation across 100+ web applications.
    • Designed, maintained and secured Linux VPS environments (cPanel, MySQL) for clients across several industries.
    AuditoríaHardeningcPanelMySQLAnálisis de malware
  5. IDECEB Consultores SAS

    Jul 2014 — May 2016

    General Manager & Marketing Strategist · Medellín, CO

    • Ran operations, processes and digital presence for a consulting firm.
    GestiónProcesosMarketing digital
  6. Banca y aduanas

    Feb 2001 — Jun 2014

    Financial and customs operations · Colombia

    • Thirteen years in banking and customs brokerage: control, traceability and regulatory compliance.
    Banco BNGHelm BankAgencia de Aduanas

04Projects

Verifiable work: public repositories and a lab running in production.

SOC lab on Oracle Cloud

A Linux fleet instrumented with Wazuh over a WireGuard overlay network, plus a triage engine of my own that runs every five minutes.

  • Wazuh manager with its own indexer, dashboard and an agent on every machine.
  • Python triage engine and fleet watchdog shipped as systemd units with audit logging.
  • HMAC-signed webhook receiver, event queue and rule proposals a human approves before install.
  • Grafana dashboards on the lab indices.
WazuhGrafanaWireGuardOracle CloudPythonsystemdBash

DevSecOps pipeline template

Five security gates inside GitHub Actions: secrets, SAST, dependencies, infrastructure configuration and container image.

  • Gitleaks fails the build on any detected secret; Semgrep (p/ci) fails on ERROR severity.
  • Trivy blocks CRITICAL and HIGH across dependencies, IaC and image.
  • SARIF results surfaced directly in the repository security dashboard.
  • Local runner and pre-commit hooks to reproduce the same gates without waiting for CI.
GitHub ActionsGitleaksSemgrepTrivySARIFDocker
View on GitHub

Linux VPS hardening script

Idempotent hardening for Debian/Ubuntu/RHEL servers with a verification mode: it applies the controls and proves they are in place.

  • Key-only SSH on a non-standard port, default-deny firewall, fail2ban and auditd.
  • Kernel parameters and restrictions on access to sensitive system information.
  • Idempotent and fail-closed: if a step cannot be applied it does not pretend to succeed.
  • --check returns PASS/FAIL per control, ready for a pipeline or an inventory.
BashUFW/nftablesfail2banauditdsystemdcloud-initAnsible
View on GitHub

Automated attack-surface reconnaissance

Passive asset sweep from Certificate Transparency logs, with liveness checks and service fingerprinting.

  • Discovers subdomains through Certificate Transparency (crt.sh and certspotter) without touching the target.
  • Checks what is alive, fingerprints services and headers, and ranks findings by interest.
  • Produces a Markdown report ready to attach to a ticket.
  • Active mode requires an authorisation file: the tool does not fire without explicit permission.
BashPythonNmapcrt.shOSINT
View on GitHub

This site

Static portfolio generated with Python (standard library only), no framework, no cookies, no trackers and no third-party assets.

  • Strict Content Security Policy, security headers and an email address that is never plain text in the HTML.
  • Three languages with hreflang, sitemap, robots and structured data.
  • Real text in the HTML (no images): readable by search engines and by applicant tracking systems (ATS).
PythonHTML/CSSCSP estrictaCloudflare

05Stack and tools

What I use day to day, no decoration: every item here has a story behind it.

Cloud and infrastructure

Oracle Cloud (OCI)AWSCloudflare (DNS/WAF/Tunnel)WireGuardDocker/PodmanKubernetesLinux (Debian/Ubuntu/RHEL)

Security and SOC

SOC OperationsVulnerability ManagementLinux Hardening (CIS)Wazuh (SIEM/XDR)GrafanaNessusNmapfail2banauditdISO 27001NIST CSFOWASP Top 10

DevSecOps and CI/CD

GitHub ActionsGitLab CICI/CDSAST/DASTGitleaksSemgrepTrivySARIFAnsiblecloud-initHardening CIS

Code and data

PythonBashPHPJavaScript/TypeScriptSQL (MySQL/MariaDB)Java (JUnit)GitPowerShell

Services and platforms

NginxPHP-FPMHestiaCPcPanelWordPress/WooCommercen8nimapsyncsystemd

Automation and AI

n8n (automatización)OllamaCursorRoo CodePrompting para triaje

06Education

The degree and post-graduate work behind the technical job.

  1. Cyber Defense

    Jan 2024 — Jun 2026

    Estácio · Brazil

    Completed in 2026. Threat intelligence, vulnerability management, server hardening, application security, SOC operations and incident response.

  2. MBA, Software Engineering

    Nov 2020 — Nov 2021

    Faculdade Metropolitana · Brazil

    Software development life cycle, quality and testing, configuration management and IT governance.

  3. Postgraduate specialisation, Information Security

    2020

    Faculdade Metropolitana · Brazil

    Network and web system security, storage infrastructure security, cryptography, ITIL and compliance.

  4. BBA, Business Administration

    Jul 1999 — Jun 2004

    Universidad Autónoma del Caribe · Colombia

    Management, finance and process foundations I use to translate technical risk into business language.

07Certifications

Continuous training, newest first.

  • Bootcamp DevOps com IA Full Cycle 2025
  • Segurança em Cloud Estácio 2025
  • Fundamentos de Ciberseguridad Industrial (Essentials) Diplomados en Ciberseguridad 2025
  • Pentest Profissional Desec Security 2024
  • Modern Threat Hunting Strategies to Identify Attacks LinkedIn Learning 2024
  • ITIL® 4 Foundation LinkedIn Learning 2024
  • Malware Analysis & Incident Response for IT Technicians Udemy 2024
  • JUnit 5, Mockito, TDD, BDD & ATDD Udemy 2024
  • DevOps Beginner to Advanced: Introduction to DevOps EC-Council 2023
  • Practical Cyber Threat Intelligence EC-Council 2023
  • Microsoft Cybersecurity Pro Track: Threat Detection EC-Council 2023
  • Applied Threat Hunting EC-Council 2023
  • Practical Malware Analysis & Triage TCM Security 2022
  • Official (ISC)² Certified in Cybersecurity (CC) ISC2 2022
  • EF SET English Certificate 62/100 (C1 Advanced) EF SET 2022
  • HPE Fortify — Secure Code Analysis Noble Work Foundation 2022
  • TypeScript Udemy 2022
  • Web Hacking: Become a Professional Web Pentester Udemy 2022
  • Ransomware Survival Guide CodeRed 2022
  • OSINT for Hackers and Penetration Testers CodeRed 2021
  • Black Hat Python: Python for Pentesters CodeRed 2021
  • Linux Forensics CodeRed 2021
  • Pentesting con Cobalt Strike Backtrack Academy 2021
  • Análisis y Gestión de Riesgo Backtrack Academy 2021
  • Nessus para Pentester Backtrack Academy 2021
  • Implementando SOC con OSSIM Backtrack Academy 2021
  • Especialidad — Information Security Analyst Backtrack Academy 2021
  • Implementación ISO 27001 Backtrack Academy 2021
  • ISO/IEC 27002:2013 Backtrack Academy 2021
  • Inteligencia de Amenazas Cibernéticas Avanzada Backtrack Academy 2021
  • SCRUM Foundation Professional Certificate (SFPC) Certiprof 2021
  • Practical Ethical Hacking TCM Security 2021
  • A Nova Geração em Pentest Profissional Desec Security 2021
  • Anonymity Guide for Ethical Hackers Udemy 2021
  • First Certified Ethical Hacking (FCEH) Comunix 2020

35 certifications, with verifiable credentials in (ISC)² CC, Pentest Profissional (Desec), Practical Ethical Hacking (TCM), ISO 27001/27002 and ITIL 4.

08Does my profile fit? Let's talk

Send me the problem and the stack; I reply in English, Portuguese or Spanish and tell you straight whether I fit. Available full-time or on contract, remote.

Brazil. Remote for Brazil, LATAM, Europe and the US.