Introduction
Hello from ST,
Welcome to my digital space. I am a senior Cloud Architect and DevSecOps Security Engineer with more than 10 years of experience designing, automating and securing enterprise technology environments.
I specialize in AWS, Azure, Kubernetes, infrastructure as code, secure CI/CD pipelines, cloud migrations, cybersecurity and platform engineering.
My recent work also includes securing AI-enabled applications through threat modeling, identity and access controls, architecture reviews and protection against risks such as prompt injection and unauthorized model access.
I combine cloud architecture, automation and security to build scalable, resilient and compliant technology platforms.
10+
Years of Experience
20+
projects completed
About
Building Secure and Scalable Cloud Platforms
Through DevOps, Automation and Cybersecurity
I am a Cloud Architect and DevSecOps Security Engineer experienced in designing secure, highly available and automated platforms across AWS, Azure and Google Cloud.
My background includes enterprise cloud architecture, Kubernetes, Terraform, CI/CD automation, vulnerability management, observability, compliance, disaster recovery and cloud migration.
I have led infrastructure and security initiatives in complex enterprise environments, helping teams improve delivery speed, operational resilience and security governance.
My certifications include AWS Solutions Architect, AWS Security, Azure DevOps Engineer Expert, Certified Kubernetes Administrator and CompTIA Security+.
resume
Education & Experience
Lead DevOps & Security Engineer
Cloud Infrastructure, Security Governance and AI Workload Protection
Cloud DevSecOps Architect
Multi-Cloud Architecture, Kubernetes and Security Automation
Cloud Data & DevOps Architect
Cloud Data Platforms, Infrastructure Automation and Governance
Cloud DevOps Engineering Lead
Enterprise Cloud Migration, CI/CD and Platform Engineering
Cloud & DevOps Engineer
AWS Infrastructure, Automation and Container Platforms
Bachelor of Science
Biotechnology with a Minor in Information Technology - George Mason University
Services
My Specializations
Cloud & DevSecOps Architecture
Designing secure, scalable cloud platforms, infrastructure as code, Kubernetes environments and automated delivery pipelines.
12 ProjectsCloud & Cybersecurity Engineering
Strengthening cloud environments through security architecture, IAM, vulnerability management, monitoring, compliance and incident-response controls.
8 ProjectsAI Security Engineering
Securing AI-enabled applications through threat modeling, access controls, architecture reviews and protection against emerging AI security risks.
6 Projectsmy skills
My Tech Stack
AWS
Microsoft Azure
Terraform
Kubernetes
Docker
Python
GitHub Actions
Grafana
Splunk
Claude AI
OpenAI
Nessus
testimonial
Trusted by Clients
Paolo Donati
Essen Corp - Argentina
Forza helped us simplify a complex cloud environment and establish a secure, scalable architecture. The work was well organized, clearly documented, and delivered with a strong understanding of both engineering and business priorities.
Project
Christina Morillon
Product Manager - Strike Systems - France
Forza brought structure and clarity to our DevSecOps process. Security controls, automation, and deployment workflows were integrated without slowing down delivery, and our team received practical guidance throughout the engagement.
Project
Alistaire Landings
Director - Swan Apps Inc - Australia
The engagement improved the reliability, visibility, and security of our platform. Forza combined strong cloud expertise with a practical approach to automation, monitoring, and risk reduction, giving us a foundation we can confidently scale.
Projectwork with 60+ brands worldwide
pricing
My Pricing
basic
Cloud, DevOps and Security
Tasks
$60 / hour
- Architecture review
- Cloud troubleshooting and configuration
- Infrastructure-as-code support
- CI/CD pipeline improvements
- Security and vulnerability assessment
- Remote delivery during business days
- Six months of support
premium
Cloud, DevOps and Security
Projects
$85 / hour
- End-to-end solution architecture
- Cloud migration and modernization
- Kubernetes and platform engineering
- Infrastructure and CI/CD automation
- Cloud and AI security integration
- Flexible weekday and weekend delivery
- Twelve months of support
- Priority project support
Need a different scope or engagement model?
Contact me to create a solution tailored to your technical and business requirements. Contact Us
portfolio
Featured Projects
FAQ
Frequently Asked Questions
Answers to common questions about my cloud, cybersecurity, DevSecOps, AI security, and data engineering services.
I help organizations design, build, secure, automate, and modernize their technology environments. My services include cloud architecture, DevSecOps, cloud infrastructure management, Infrastructure as Code, Kubernetes, CI/CD automation, Cybersecurity Consulting, Penetration Testing, AI Workload Security, data engineering, ETL and ELT pipelines, cloud migrations, and technical leadership.
Engagements can include architecture and advisory work, hands-on implementation, security assessments, modernization projects, troubleshooting, mentoring, and ongoing technical support.
I primarily work with Amazon Web Services and Microsoft Azure, including hybrid and multi-cloud environments.
I help organizations build secure, reliable, scalable, and cost-conscious cloud platforms using services for compute, networking, identity, storage, databases, containers, monitoring, security, automation, and data processing.
Yes. I help organizations design, operate, secure, and improve cloud infrastructure.
This may include network architecture, identity and access management, infrastructure automation, monitoring, logging, backup and recovery, cost optimization, reliability improvements, security hardening, operational documentation, and ongoing platform management.
I can work independently or alongside an existing infrastructure, engineering, DevOps, or security team.
Yes. I help organizations plan and execute secure, low-risk migrations from on-premises environments to AWS or Microsoft Azure.
Cloud Migrations services may include:
- Application and server migrations
- Database migrations
- Storage and file migrations
- Network redesign
- Identity integration
- Landing-zone design
- Infrastructure as Code
- Hybrid-cloud connectivity
- Security controls
- Backup and rollback planning
- Post-migration optimization
Each migration is planned around business continuity, security, resilience, automation, and minimal disruption.
Yes. I support cloud-to-cloud migrations, including AWS-to-Azure and Azure-to-AWS transitions.
This can include migrating applications, virtual machines, containers, databases, storage, data pipelines, networking, identity integrations, security controls, and monitoring platforms.
I also help organizations evaluate which services should be rehosted, replatformed, modernized, or redesigned during the migration rather than simply copying the existing environment into another cloud.
Yes. I design and improve secure software delivery pipelines that integrate security throughout the development and deployment lifecycle.
Services may include:
- CI/CD pipeline architecture
- Infrastructure as Code using Terraform
- Automated testing
- SAST and DAST integration
- Dependency and container scanning
- Secret detection and management
- Policy as Code
- Deployment approvals
- Environment promotion controls
- Artifact security
- Kubernetes deployment automation
- Compliance evidence collection
- Monitoring and rollback controls
The goal is to help teams release software faster while reducing security and operational risk.
Yes. I help small and growing businesses establish a complete, practical cybersecurity posture based on their actual risks, systems, budget, and regulatory needs.
Cybersecurity Consulting services may include:
- Cybersecurity posture assessments
- Identity and access management
- Multi-factor authentication
- Least-privilege access
- Microsoft 365 or Google Workspace security
- Endpoint protection
- Email security
- Cloud security
- Network hardening
- Secure remote access
- Vulnerability management
- Backup and recovery planning
- Logging and monitoring
- Incident-response preparation
- Security policies and documentation
- Employee security-awareness guidance
The objective is to reduce real business risk without creating unnecessary complexity.
Yes. I provide authorized Penetration Testing, vulnerability assessments, cloud configuration reviews, and security architecture assessments.
Depending on the engagement, testing may cover:
- Internet-facing systems
- Internal networks
- Web applications
- Cloud environments
- Identity and access controls
- Containers and Kubernetes
- Network segmentation
- Security-group and firewall configurations
- Exposed services
- Misconfigurations
- Privilege escalation paths
Testing is performed only with written authorization and a clearly defined scope.
Clients receive documented findings, risk ratings, supporting evidence, remediation guidance, and a prioritized action plan.
Absolutely. I evaluate the current environment, identify the most important risks, and develop a practical improvement roadmap.
The work may include identity security, endpoint protection, cloud hardening, network security, vulnerability management, monitoring, backup, disaster recovery, incident readiness, governance, policies, and user awareness.
Recommendations are prioritized so the organization can address the highest-risk issues first rather than trying to implement every possible security tool at once.
Yes. I help organizations secure AI workloads, supporting infrastructure, data access, and cloud services.
AI Workload Security controls may include:
- Least-privilege access
- Strong IAM roles and policies
- Separation of duties
- Workload identities
- Service accounts
- Short-lived credentials
- Secrets management
- Network segmentation
- Private endpoints
- Encryption
- Data-access restrictions
- Logging and monitoring
- Model and artifact protection
- Secure CI/CD pipelines
- AI governance controls
- Protection against unauthorized use of models and data
The goal is to ensure that users, applications, agents, models, and services receive only the access required to perform their approved functions.
I review how users, applications, services, pipelines, and workloads access systems and data.
I then help reduce unnecessary permissions by implementing IAM and Least Privilege practices such as:
- Role-based access control
- Least-privilege IAM policies
- Separate administrative and daily-use accounts
- Workload identities
- Temporary credentials
- Just-in-time access
- Multi-factor authentication
- Permission boundaries
- Conditional-access controls
- Service-control policies where appropriate
- Regular access reviews
- Logging and alerting for privileged activity
This reduces the impact of compromised credentials, configuration mistakes, and unauthorized access.
Yes. I design and implement secure, scalable data solutions for moving, transforming, integrating, storing, and analyzing data.
Data Engineering & ETL Pipelines services may include:
- ETL and ELT pipelines
- Batch data processing
- Near-real-time and event-driven pipelines
- Cloud data lakes
- Data warehouses
- Data integration
- API-based ingestion
- Database migration
- Data transformation
- Workflow orchestration
- Data validation
- Monitoring and failure recovery
- Access controls and encryption
- Analytics platform integration
Technologies may include Azure Data Factory, AWS Glue, Amazon S3, Azure Data Lake Storage, Amazon Athena, Azure Synapse Analytics, Databricks, SQL databases, APIs, event-streaming services, and related cloud tools.
Yes. I help organizations secure data throughout its lifecycle, including collection, transmission, storage, processing, access, backup, and deletion.
Controls may include encryption, key management, access restrictions, private networking, data classification, retention policies, audit logging, secrets management, tokenization, backup protection, and secure data-pipeline design.
Yes. I design, deploy, secure, troubleshoot, and improve containerized platforms using technologies such as Docker, Amazon EKS, Azure AKS, Kubernetes, Helm, and Infrastructure as Code.
Services may include:
- Cluster architecture
- Secure networking
- Workload identity
- Role-based access control
- Container image security
- Admission controls
- Secrets management
- Ingress and service configuration
- Observability
- Autoscaling
- Backup and recovery
- CI/CD integration
- Cost and performance optimization
Absolutely. I regularly collaborate with engineering, security, DevOps, platform, cloud, infrastructure, application, and data teams.
I can contribute as a cloud architect, security consultant, DevSecOps engineer, technical lead, advisor, mentor, or hands-on implementation specialist.
The engagement can supplement internal expertise, accelerate a specific project, resolve a difficult technical problem, or help establish standards and repeatable processes.
Yes. For larger, highly specialized, or multidisciplinary engagements, I can team up with trusted and highly skilled colleagues.
This extended capability may include experienced:
- Cloud architects
- Cybersecurity specialists
- Penetration testers
- DevSecOps engineers
- Platform engineers
- Network engineers
- Data engineers
- Database specialists
- AI and machine-learning specialists
- Compliance and governance professionals
This approach allows us to support broader and more advanced work while maintaining clear communication, coordinated delivery, and a single engagement strategy. It is an available option based on project size, scope, and technical requirements rather than a default for every engagement.
I work with startups, small businesses, mid-sized organizations, enterprises, government teams, nonprofit organizations, consulting firms, and other organizations that need support with cloud infrastructure, cybersecurity, DevSecOps, AI security, data engineering, or modernization.
The engagement is tailored to the organization’s size, maturity, risk profile, goals, and internal capabilities.
Engagements can range from a focused consultation, architecture review, security assessment, or troubleshooting session to a multi-month implementation, migration, modernization, or transformation project.
Typical engagement models may include:
- Advisory and architecture support
- Fixed-scope assessments
- Project-based implementation
- Technical leadership
- Team augmentation
- Ongoing consulting
- Security improvement programs
- Cloud and infrastructure management
The appropriate model should be determined after understanding the client’s environment, priorities, timeline, and desired outcomes.
Use the website contact form or listed email address to request an initial consultation.
The first discussion should cover:
- Business goals
- Current environment
- Technical challenges
- Security concerns
- Project scope
- Desired timeline
- Internal team capabilities
- Expected outcomes
After the initial discussion, I recommend an appropriate engagement approach and clear next steps.
contact
Let's Work Together!
forza@forza-dev.com
* Marked fields are required to fill.