I’m Javier Pulido, a Cloud Security Engineer specialized in AWS. Over the past several years I’ve built and secured multi-account AWS environments with infrastructure-as-code, identity federation, and continuous monitoring — the same patterns I write about here.

What I Help Teams With

Beyond writing, I take on selected consulting engagements. If your team is dealing with any of these, I can help:

  • AWS security audits — end-to-end review of your account structure, IAM, network exposure, logging, and detection posture. Findings prioritized by real risk, not compliance box-ticking.
  • GuardDuty, Security Hub & IR pipelines — deploy the detection layer, filter the noise, wire findings to Slack/PagerDuty/your SIEM, and build the response playbook around it.
  • IAM hardening — least-privilege refactor, migration from IAM users to SSO/IAM Identity Center, cross-account access design, permission boundary strategy.
  • Landing zones & governance — multi-account structure with Control Tower, secure baselines, guardrails, and cost/access controls that scale.
  • ISO 27001 preparation — AWS-native controls, evidence collection automation, and gap analysis for the technical clauses.

See how consulting engagements work →

Core Expertise

  • AWS Governance & Landing Zones — multi-account structures with Control Tower, Service Catalog, and secure baselines that enforce least-privilege and separation of duties
  • Identity & Access Management — AWS SSO via external IdPs, Terraform-managed permission sets, session tagging for CI/CD attribution
  • Infrastructure Automation — Terraform and CloudFormation for IAM, Config rules, Security Hub, and Lambda/SNS/SES notification pipelines
  • Incident Response & Forensics — dedicated IR accounts, AVML memory acquisition via SSM, evidence chain-of-custody with S3 lifecycle policies
  • DevSecOps Integrations — Slack bots and scheduled Lambdas that ingest Security Hub findings, correlate authorship via AWS Config, and route alerts to the right owner
  • ISO 27001 Compliance — AWS-native controls, automated remediation, and monitoring aligned to ISO 27001:2023

The Hidden Port

This blog is where I document what actually works — and what doesn’t — from the security engineering side of AWS. Topics include:

  • Cloud security tutorials and automation recipes
  • Detection engineering with GuardDuty, Security Hub, and CloudTrail
  • Incident response playbooks and forensic walkthroughs
  • Compliance guidance for ISO 27001 and SOC2 on small teams

Everything published here is written from real environments, not documentation summaries.

Contact

Based in Sevilla, Spain. Working remotely with clients across Europe.


“Trust but verify.”