Senior Platform Engineer & Team Lead, Q2 Ingressos (Platform Engineering)
Duration: Aug. 2023 - Present
Summary: Leading platform engineering for one of Brazil's largest ticketing platforms, managing 100+ microservices across 2 AWS regions. The project focuses on designing scalable, resilient, and secure cloud architectures and building an Internal Developer Platform to accelerate service provisioning.
Responsibilities:
- Lead a 12-person cross-functional team (DevOps, DBA, QA, Security, Architecture) owning all infrastructure for one of Brazil's largest ticketing platforms - 100+ microservices across 2 AWS regions.
- Designed and maintained AWS reference architecture diagrams (C4 context/container level) for the entire microservices landscape, enabling team onboarding and architectural decision-making across 12 engineers.
- Applied AWS Well-Architected Framework reviews across reliability, security, cost optimization, and operational excellence pillars - driving structured improvement cycles for critical services.
- Evaluated and documented architecture trade-offs for ECS Fargate vs. EKS migration, active-passive vs. active-active multi-region, and synchronous vs. event-driven patterns - aligning technical decisions with business risk and cost constraints.
- Built an Internal Developer Platform (IDP) with Terraform and GitLab CI/CD, cutting service provisioning from 1 day to under 15 minutes; supports 80+ production services.
- Implemented GitOps workflow with automated drift detection and policy enforcement, reaching ~95% IaC coverage.
- Managed AWS budget through 10x service growth, keeping spend increase to ~35% through systematic FinOps practices.
- Architected ECS Fargate to EKS migration strategy with Karpenter autoscaling and Spot Instances, projecting 30% cost reduction and 40% improved resource efficiency.
- Deployed Datadog with APM and distributed tracing across 100+ services, reducing MTTR from ~4h to ~1h.
- Integrated GPT-4 + n8n support automation resolving ~70% of 1,000+ daily tickets at under $100/month.
- Led migration of monolithic components to event-driven microservices (Docker, ECS), enabling 4-5 daily deployments.
- Serve as company DPO: structured LGPD data protection policies, implemented PII masking in logs via Datadog Sensitive Data Scanner.
Technologies: AWS (ECS Fargate, EKS, Lambda, RDS Aurora, S3, VPC, IAM, KMS, CloudTrail, Config, GuardDuty, WAF, EventBridge, SQS, SNS), Terraform, GitLab CI/CD, GitOps, Karpenter, Spot Instances, Datadog (APM, tracing), Docker, GPT-4, n8n.
AWS Security Architect/DevOps Engineer, Hyperlocal (Hyperlocal Multi-Region AWS Infrastructure and Security)
Duration: Oct. 2021 - Aug. 2024
Summary: Sole infrastructure and security engineer supporting 6 business units with 100+ services across a multi-region AWS environment. The project involved architecture design, security program development, and PCI DSS Level 1 certification.
Responsibilities:
- Sole infrastructure and security engineer supporting 6 business units with 100+ services across a multi-region AWS environment.
- Produced architecture diagrams (network topology, data flow, and security boundary diagrams) for all 6 business units, serving as primary documentation for PCI DSS audit evidence.
- Conducted AWS Well-Architected Framework reviews focused on Security and Reliability pillars, identifying and remediating critical gaps ahead of PCI DSS Level 1 certification.
- Led PCI DSS Level 1 certification in ~6 weeks - designed full network segmentation (VPCs, security groups) and implemented end-to-end encryption (KMS, TLS).
- Built security program from scratch: AWS WAF, CloudTrail, Config, GuardDuty; ran 2 annual pentests with 100% critical vulnerability remediation.
- Achieved ~90% IaC coverage with Terraform across 6 business units using a reusable module library.
- Reduced monthly AWS spend from R$400K to R$290K (~27%, ~R$1.3M/year) through Reserved Instances, rightsizing, and cleanup automation.
- Maintained SLAs across all 6 business units while establishing incident response procedures from the ground up.
Technologies: AWS (VPC, Security Groups, KMS, TLS, WAF, CloudTrail, Config, GuardDuty), Terraform, PCI DSS compliance tools.
Security Analyst/PCI-ISA, Quero 2 Pay (Quero 2 Pay PCI DSS Compliance and Security Architecture)
Duration: Mar. 2021 - Oct. 2021
Summary: Supported the company's PCI DSS certification process as PCI Internal Security Assessor. Designed AWS security architecture and conducted security assessments to improve compliance and security posture.
Responsibilities:
- Acted as PCI Internal Security Assessor (ISA), mapping controls, identifying compliance gaps, and directly supporting the company's PCI DSS certification process.
- Designed AWS security architecture: network segmentation with VPCs, security groups and NACLs, encryption in transit and at rest (KMS, TLS).
- Conducted security assessments identifying 20+ vulnerabilities with risk-prioritized remediation plans.
- Worked closely with development teams to embed security practices into the application lifecycle.
Technologies: AWS (VPC, Security Groups, NACLs, KMS, TLS), PCI DSS compliance.
IT Manager, Di Fiorenna Ind. e Com. Ltda (Operations Management)
Duration: May 2010 - Apr. 2021
Summary: Managed all IT operations including physical infrastructure, server virtualization, backup routines, and end-user support for over 11 years, ensuring business continuity and operational efficiency.
Responsibilities:
- Managed all IT operations for 11 years — from physical infrastructure to end-user support.
- Administered full on-premise infrastructure: physical servers, structured cabling, switches, and network assets.
- Implemented server virtualization, increasing availability and reducing reliance on dedicated hardware.
- Designed and managed backup routines ensuring business continuity and corporate data protection.
- Managed IT assets, licensing, and vendor relationships, keeping operations within budget and with minimal downtime.
Technologies: VMware, Hyper-V, Windows Server, structured cabling, backup management.