Platform & Cloud Security Engineer with ~20 years across Identity & Access Management (IAM/IGA), cloud security, and infrastructure engineering. I've operated identity platforms at large enterprise scale and built the tooling and automation around them.
Most of my work is under NDA in private repositories, so instead of code dumps I write about how I solve the hard problems 👇
- Identity & Access Management — IAM/IGA/PAM, SailPoint, Okta, Microsoft/OpenText Identity Manager, Keycloak/Red Hat SSO, RACF. Protocols end to end: SAML 2.0, OAuth 2.0/OIDC, SCIM 2.0, FIDO2/WebAuthn, Zero Trust (NIST SP 800-207).
- Cloud security — GCP & AWS Well-Architected reviews, Security Hub/GuardDuty/SCC, least-privilege IAM, compliance alignment (SOC 2, ISO 27001, NIST 800-53/63).
- Platform & protocol engineering — from-scratch systems in Go/Python, including a multi-tenant mail-protocol gateway and a cross-platform access-auditing tool with a dozen identity-source connectors.
- Infrastructure as code — Terraform & Ansible at fleet scale, observability (Prometheus/Grafana/Loki), hardened container deployments.
Google Cloud Professional Cloud Architect · Google Cloud Associate Cloud Engineer · AWS Security – Specialty · HashiCorp Terraform Associate → credly.com/users/dferraes
I document the hard problems I solve in engineering-notes — deep dives on identity, protocols, and platform security, no proprietary code.
Go · Python · Terraform · Ansible · GCP · AWS · Kubernetes ·
PostgreSQL · Prometheus/Grafana/Loki · IAM platforms (Okta, SailPoint, Keycloak)



