UpstaffSign up
Rafael R., Senior Cloud Architect/Platform Engineering  (AWS, AI)
Rafael R.
🇧🇷Brazil (UTC-03:00)
Created AtUpstaffer since September, 2026
🔥 Get Rafael R. rates & availability. We respond within one business day
Book a Call Download Profile PDF

Rafael R. — Senior Cloud Architect/Platform Engineering (AWS, AI)

Expertise in Cloud Infrastructure Engineer, Information Security and Compliance Officer.

 Last verified on September, 2026

Bio Summary

  • 10+ years in IT infrastructure and AWS solutions architecture; leads a 12-person cross-functional platform team running 100+ microservices across 2 AWS regions.
  • IaC expertise: Terraform + GitLab CI/CD at ~95% coverage; built an Internal Developer Platform, cutting provisioning from 1 day to under 15 minutes.
  • Compliance and network segmentation experience: zero-trust VPC/Security Group/NACL architecture (KMS/TLS) as sole security engineer, delivering PCI DSS Level 1 in ~6 weeks; DPO under LGPD.
  • Skilled in low-code AI workflow automation: GPT-4 + n8n in production resolving ~70% of 1,000+ daily tickets under $100/month.
  • AWS Solutions Architect Associate, PCI DSS PCIP, AI Agents Advanced.

Technical Skills

Programming Languages Python
AI & Machine Learning AI, GPT, n8n
Security AWS Security, AWS Security Groups, GuardDuty, IAM, Incident response, NIST, PCI DSS, Pentests
Cloud Platforms, Services & Computing AWS
Amazon Web Services AWS ALB, AWS API Gateway, AWS Aurora, AWS Cloudformation, AWS CloudTrail, AWS CloudWatch, AWS EC2, AWS ECS (Amazon Elastic Container Service), AWS Elastic Kubernetes Service, AWS EventBridge, AWS Fargate, AWS IAM, AWS KMS, AWS Lambda, AWS S3, AWS Security, AWS Security Groups, AWS SNS, AWS SQS, AWS VPC
Azure Cloud Services Hyper-V
Deployment, CI/CD & Administration Ansible, ArgoCD, CI/CD, Configuration Policies, GitLab CI, GitOps, Helm, istio, Jenkins, KEDA
SDK / API and Integrations AWS API Gateway
Scripting and Command Line Interfaces Bash
Logging and Monitoring Datadog, Grafana, Prometheus
Virtualization, Containers and Orchestration Docker, Kubernetes, Terraform, VmWare
Version Control Github Actions, GitLab
Methodologies, Paradigms and Patterns IaC, ITIL, Kanban, Scrum
QA, Test Automation, Security KMS, WAF
Project Management & Administration SLAs
Mail / Network Protocols / Data transfer TLS, VPN
Web/App Servers, Middleware Windows Server
Other Technical Skills APM, Argo, LGPD, NACLs, NLB, PCI DSS Compliance, RDS, SRE

Work Experience

Senior Platform Engineer & Team Lead, Q2 Ingressos (Platform Engineering)

Duration: Aug. 2023 - Present

Summary: Leading platform engineering for one of Brazil's largest ticketing platforms, managing 100+ microservices across 2 AWS regions. The project focuses on designing scalable, resilient, and secure cloud architectures and building an Internal Developer Platform to accelerate service provisioning.

Responsibilities:

  • Lead a 12-person cross-functional team (DevOps, DBA, QA, Security, Architecture) owning all infrastructure for one of Brazil's largest ticketing platforms - 100+ microservices across 2 AWS regions.
  • Designed and maintained AWS reference architecture diagrams (C4 context/container level) for the entire microservices landscape, enabling team onboarding and architectural decision-making across 12 engineers.
  • Applied AWS Well-Architected Framework reviews across reliability, security, cost optimization, and operational excellence pillars - driving structured improvement cycles for critical services.
  • Evaluated and documented architecture trade-offs for ECS Fargate vs. EKS migration, active-passive vs. active-active multi-region, and synchronous vs. event-driven patterns - aligning technical decisions with business risk and cost constraints.
  • Built an Internal Developer Platform (IDP) with Terraform and GitLab CI/CD, cutting service provisioning from 1 day to under 15 minutes; supports 80+ production services.
  • Implemented GitOps workflow with automated drift detection and policy enforcement, reaching ~95% IaC coverage.
  • Managed AWS budget through 10x service growth, keeping spend increase to ~35% through systematic FinOps practices.
  • Architected ECS Fargate to EKS migration strategy with Karpenter autoscaling and Spot Instances, projecting 30% cost reduction and 40% improved resource efficiency.
  • Deployed Datadog with APM and distributed tracing across 100+ services, reducing MTTR from ~4h to ~1h.
  • Integrated GPT-4 + n8n support automation resolving ~70% of 1,000+ daily tickets at under $100/month.
  • Led migration of monolithic components to event-driven microservices (Docker, ECS), enabling 4-5 daily deployments.
  • Serve as company DPO: structured LGPD data protection policies, implemented PII masking in logs via Datadog Sensitive Data Scanner.

Technologies: AWS (ECS Fargate, EKS, Lambda, RDS Aurora, S3, VPC, IAM, KMS, CloudTrail, Config, GuardDuty, WAF, EventBridge, SQS, SNS), Terraform, GitLab CI/CD, GitOps, Karpenter, Spot Instances, Datadog (APM, tracing), Docker, GPT-4, n8n.

AWS Security Architect/DevOps Engineer, Hyperlocal (Hyperlocal Multi-Region AWS Infrastructure and Security)

Duration: Oct. 2021 - Aug. 2024

Summary: Sole infrastructure and security engineer supporting 6 business units with 100+ services across a multi-region AWS environment. The project involved architecture design, security program development, and PCI DSS Level 1 certification.

Responsibilities:

  • Sole infrastructure and security engineer supporting 6 business units with 100+ services across a multi-region AWS environment.
  • Produced architecture diagrams (network topology, data flow, and security boundary diagrams) for all 6 business units, serving as primary documentation for PCI DSS audit evidence.
  • Conducted AWS Well-Architected Framework reviews focused on Security and Reliability pillars, identifying and remediating critical gaps ahead of PCI DSS Level 1 certification.
  • Led PCI DSS Level 1 certification in ~6 weeks - designed full network segmentation (VPCs, security groups) and implemented end-to-end encryption (KMS, TLS).
  • Built security program from scratch: AWS WAF, CloudTrail, Config, GuardDuty; ran 2 annual pentests with 100% critical vulnerability remediation.
  • Achieved ~90% IaC coverage with Terraform across 6 business units using a reusable module library.
  • Reduced monthly AWS spend from R$400K to R$290K (~27%, ~R$1.3M/year) through Reserved Instances, rightsizing, and cleanup automation.
  • Maintained SLAs across all 6 business units while establishing incident response procedures from the ground up.

Technologies: AWS (VPC, Security Groups, KMS, TLS, WAF, CloudTrail, Config, GuardDuty), Terraform, PCI DSS compliance tools.

Security Analyst/PCI-ISA, Quero 2 Pay (Quero 2 Pay PCI DSS Compliance and Security Architecture)

Duration: Mar. 2021 - Oct. 2021

Summary: Supported the company's PCI DSS certification process as PCI Internal Security Assessor. Designed AWS security architecture and conducted security assessments to improve compliance and security posture.

Responsibilities:

  • Acted as PCI Internal Security Assessor (ISA), mapping controls, identifying compliance gaps, and directly supporting the company's PCI DSS certification process.
  • Designed AWS security architecture: network segmentation with VPCs, security groups and NACLs, encryption in transit and at rest (KMS, TLS).
  • Conducted security assessments identifying 20+ vulnerabilities with risk-prioritized remediation plans.
  • Worked closely with development teams to embed security practices into the application lifecycle.

Technologies: AWS (VPC, Security Groups, NACLs, KMS, TLS), PCI DSS compliance.

IT Manager, Di Fiorenna Ind. e Com. Ltda (Operations Management)

Duration: May 2010 - Apr. 2021

Summary: Managed all IT operations including physical infrastructure, server virtualization, backup routines, and end-user support for over 11 years, ensuring business continuity and operational efficiency.

Responsibilities:

  • Managed all IT operations for 11 years — from physical infrastructure to end-user support.
  • Administered full on-premise infrastructure: physical servers, structured cabling, switches, and network assets.
  • Implemented server virtualization, increasing availability and reducing reliance on dedicated hardware.
  • Designed and managed backup routines ensuring business continuity and corporate data protection.
  • Managed IT assets, licensing, and vendor relationships, keeping operations within budget and with minimal downtime.

Technologies: VMware, Hyper-V, Windows Server, structured cabling, backup management.

Education

  • Bachelor of Computer Science
    Universidade de Franca, Franca, SP

Certification

  • AWS Solutions Architect Associate
    2023 - 2026
  • PCI DSS PCIP
    2022
  • Datadog SRE
    2023
  • GitOps with ArgoCD
    2023
  • AWS FinOps
    2023
  • GitLab CI/CD Pipelines
    2024
  • AI Agents Advanced
    2025
  • Uncomplicating EKS
    2025

How to hire with Upstaff

1

Talk to Our Talent Expert

Our journey starts with a 30-min discovery call to explore your project challenges, technical needs and team diversity.

2

Meet Carefully Matched Talents

Within 1-3 days, we’ll share profiles and connect you with the right talents for your project. Schedule a call to meet engineers in person.

3

Validate Your Choice

Bring new talent on board with a trial period to confirm you hire the right one. There are no termination fees or hidden costs.

Why Upstaff

Upstaff is a technology partner with expertise in AI, Web3, Software, and Data. We help businesses gain competitive edge by optimizing existing systems and utilizing modern technology to fuel business growth.

Real-time project team launch

<24h

Interview First Engineers

Upstaff's network enables clients to access specialists within hours & days, streamlining the hiring process to 24-48 hours, start ASAP.

x10

Faster Talent Acquisition

Upstaff's network & platform enables clients to scale up and down blazing fast. Every hire typically is 10x faster comparing to regular recruitement workflow.

Vetted and Trusted Engineers

100%

Security And Vetting-First

AI tools and expert human reviewers in the vetting process is combined with track record & historically collected feedbacks from clients and teammates.

~50h

Save Time For Deep Vetting

In average, we save over 50 hours of client team to interview candidates for each job position. We are fueled by a passion for tech expertise, drawn from our deep understanding of the industry.

Flexible Engagement Models

Arrow

Custom Engagement Models

Flexible staffing solutions, accommodating both short-term projects and longer-term engagements, full-time & part-time

Sharing

Unique Talent Ecosystem

Candidate Staffing Platform stores data about past and present candidates, enables fast work and scalability, providing clients with valuable insights into their talent pipeline.

Transparent

$0

No Hidden Costs

Price quoted is the total price to you. No hidden or unexpected cost for for candidate placement.

x1

One Consolidated Invoice

No matter how many engineers you employ, there is only one monthly consolidated invoice.

Rafael R., Senior Cloud Architect/Platform Engineering  (AWS, AI)
Ready to hire Rafael R.
or someone with similar Skills?
Rafael R. is available
for hire 🔥
Book a call with Rafael R.
Looking for Someone Else? Join Upstaff access to All profiles and Individual Match
Start Hiring
Request Rafael R. Rates & Availability
Attachment File attachment Arrow

Upload File. Drag and Drop or

At Upstaff we respect confidentiality, privacy and value your information.Terms, conditions and legal information.

Thank you! 🎉

Your message has been successfully sent. We’ll review it and get back to you as soon as possible.

Create an account to save your details and track your applications.

Sign up
Download Candidate Profile (PDF)

Please leave your details and we'll email you the resume right away.

At Upstaff we respect your privacy.

Confidential (C) UPSTAFF LTD, England and Wales, #12727246 17 Montgomery Drive, Tavistock, United Kingdom PL19 8KX

Terms, conditions and legal information.