Agustin De MozziCloud Security Engineer | DevSecOps

ABOUT

Security that works
in the real world.

I’m a Cloud Security Engineer with over four years of experience securing AWS and GCP infrastructure across banking e-commerce platforms, energy, and pharmaceutical environments.

I design preventive and detective security controls for multi-account cloud environments: identity and privileged access management, Kubernetes security, AWS WAF, and network protection. I connect CloudTrail, EventBridge, Security Hub, and GuardDuty with custom Python solutions to automate detection and remediation.

My work also includes securing AI agents built with Amazon Bedrock AgentCore and designing AWS organizational foundations with Terraform. Other projects include a Temporary Elevated Access Management (TEAM) mechanism for AWS and an open-source SIEM implementation. As a security consultant, I assess cloud architectures against security standards and recommend concrete improvements.

Outside of work, I explore offensive security, practice web application penetration testing in labs, and write about solutions I’ve implemented throughout my career. I’m naturally curious: understanding how things work is what keeps me learning.

SERVICES

Practical security
for AWS environments.

I help teams assess, design, and improve secure cloud environments through practical engineering and automation.

01 / ASSESSMENT

AWS Cloud Security Assessments

Assess AWS architectures against security standards and best practices, identify risks, and deliver a prioritized improvement roadmap.

AWSWell-ArchitectedCISNIST

02 / ARCHITECTURE

Secure AWS Foundations & IAM

Design secure AWS organizations with Organizations, OUs, IAM Identity Center, guardrails, centralized logging, Terraform, and emergency access.

AWS OrganizationsIAMIAM Identity Center

03 / AUTOMATION

Detection, Logging & Security Automation

Build cloud detection and response workflows and connect security signals to your existing SOC or SIEM.

CloudTrailEventBridgeGuardDutyLambda

04 / AI SECURITY

AI Agent Security

Secure agentic workloads with Bedrock AgentCore, guardrails, IAM, encryption, network controls, event logging, and controlled red team assessments.

Bedrock AgentCoreGuardrails

05 / EFFICIENCY

Cloud Cost Optimization

Review cloud security, logging, and infrastructure costs to identify savings opportunities while preserving the required security coverage.

AWSFinOps

EXPERIENCE

Hands-on.

View full résumé ↗

NOV 2025 — PRESENT

Sr. Cloud Security Engineer

Netrix Global · Remote

I work on production cloud security projects across industries, from AI agent infrastructure to AWS organizational foundations and cross-cloud connectivity.

AI agent security. Secured infrastructure for an energy-sector organization’s agent built with Amazon Bedrock AgentCore, implementing encryption, network security controls, event logging, and AWS-provided guardrails.

AWS foundations. Co-designed and implemented an AWS organization using Terraform for a US-based cell engineering technology company, following the AWS Well-Architected Framework and client requirements. The foundation includes organizational units, IAM Identity Center, security guardrails, and centralized logging. I also designed and implemented a custom break-glass access mechanism.

SOC visibility. Built a serverless integration with Lambda and S3 Event Notifications to normalize WAF logs into CloudWatch format and feed an existing Kinesis Data Streams pipeline to Splunk, closing a security visibility gap for the SOC.

Cross-cloud networking. Configured the AWS side of a production site-to-site VPN connecting an AWS VPC with an Azure VNet for private connectivity.

Amazon Bedrock AgentCoreAmazon Bedrock GuardrailsAWS OrganizationsIAM Identity CenterAWS IAMTerraformAWS WAFAWS LambdaAmazon S3Amazon CloudWatchKinesis Data StreamsSplunkAmazon VPCAWS Site-to-Site VPN

JAN 2024 — OCT 2025

Cybersecurity Analyst Ssr.

Aper · Remote

I designed Kubernetes policies with OPA and Gatekeeper aligned with the OWASP Kubernetes Top 10, and managed application and network protection with AWS WAF, Firewall Manager, and GCP security tools.

I automated detection and remediation with Lambda, CloudWatch, CloudTrail, and EventBridge, deployed infrastructure with Terraform, and supported secure, highly available e-commerce architectures aligned with NIST, CIS, and PCI requirements.

Alongside security engineering, I led AWS cost optimization initiatives that delivered recurring savings of up to 90% in targeted monthly costs and over $10,000 annually.

AWSGCPKubernetesOPA / GatekeeperTerraformAWS WAFAWS Firewall ManagerAWS LambdaAmazon CloudWatchAWS CloudTrailAmazon EventBridgeAWS Security HubAmazon GuardDutyAmazon InspectorAWS Secrets ManagerAWS KMSAmazon EC2Amazon VPCAmazon Route 53Amazon CloudFront

SEP 2022 — JAN 2024

Cybersecurity Analyst

Aper · Remote

I managed users, roles, and permissions across AWS, GCP, GitLab, and Google Workspace, applying least-privilege access across the platforms.

I also analyzed and resolved CrowdStrike Falcon security alerts. This role built my foundation in day-to-day security operations, identity management, and incident investigation.

AWS IAMGCPGitLabGoogle WorkspaceCrowdStrike Falcon

SHARED RESOURCES

Writing, tools & talks

All articles ↗

I write technical articles about solutions I’ve built and lessons from my work in cloud security. Here you’ll find articles I’ve written, open-source tools I develop, and talks where I share my experience with the community.

Open sourceSecurity automation

AWS WAF Report Builder

A CLI I built to analyze WAF logs in S3 with Athena and generate shareable HTML reports. Evaluate Count rules before enforcement and investigate blocked traffic across resources.

PythonAthenaS3AWS WAF
ArticleDevSecOps

Security reviews that understand your project.

Using AWS Security Agent with custom security requirements to catch vulnerabilities in pull requests.

ArticleCloud architecture

Better visibility starts with better logs.

Centralizing AWS WAF logs with Firehose, Lambda, and S3 across AWS accounts.

LiveAI security

Hack the Agent

I took the red team role in a live AI agent security event, demonstrating the offensive perspective on attacking and defending agents in a controlled environment.

Speaker · Red Team / Live demoNetrix Global · Buenos Aires · August 13

GET IN TOUCH

Let’s build something
worth securing.

Have a project, a question, or an idea to exchange?
I’d be happy to hear from you.

agudemozzi@gmail.com