I’m Javier Pulido, a Cloud Security Engineer specialized in AWS. Over the past several years I’ve built and secured multi-account AWS environments with infrastructure-as-code, identity federation, and continuous monitoring — the same patterns I write about here.
What I Help Teams With
Beyond writing, I take on selected consulting engagements. If your team is dealing with any of these, I can help:
- AWS security audits — end-to-end review of your account structure, IAM, network exposure, logging, and detection posture. Findings prioritized by real risk, not compliance box-ticking.
- GuardDuty, Security Hub & IR pipelines — deploy the detection layer, filter the noise, wire findings to Slack/PagerDuty/your SIEM, and build the response playbook around it.
- IAM hardening — least-privilege refactor, migration from IAM users to SSO/IAM Identity Center, cross-account access design, permission boundary strategy.
- Landing zones & governance — multi-account structure with Control Tower, secure baselines, guardrails, and cost/access controls that scale.
- ISO 27001 preparation — AWS-native controls, evidence collection automation, and gap analysis for the technical clauses.
See how consulting engagements work →
Core Expertise
- AWS Governance & Landing Zones — multi-account structures with Control Tower, Service Catalog, and secure baselines that enforce least-privilege and separation of duties
- Identity & Access Management — AWS SSO via external IdPs, Terraform-managed permission sets, session tagging for CI/CD attribution
- Infrastructure Automation — Terraform and CloudFormation for IAM, Config rules, Security Hub, and Lambda/SNS/SES notification pipelines
- Incident Response & Forensics — dedicated IR accounts, AVML memory acquisition via SSM, evidence chain-of-custody with S3 lifecycle policies
- DevSecOps Integrations — Slack bots and scheduled Lambdas that ingest Security Hub findings, correlate authorship via AWS Config, and route alerts to the right owner
- ISO 27001 Compliance — AWS-native controls, automated remediation, and monitoring aligned to ISO 27001:2023
The Hidden Port
This blog is where I document what actually works — and what doesn’t — from the security engineering side of AWS. Topics include:
- Cloud security tutorials and automation recipes
- Detection engineering with GuardDuty, Security Hub, and CloudTrail
- Incident response playbooks and forensic walkthroughs
- Compliance guidance for ISO 27001 and SOC2 on small teams
Everything published here is written from real environments, not documentation summaries.
Contact
Based in Sevilla, Spain. Working remotely with clients across Europe.
- Consulting inquiries: book a free 30-min call or email [email protected]
- General questions or feedback: same email, or the comments on any post
- Elsewhere: GitHub · LinkedIn
“Trust but verify.”