Magnet.cl
October 2022 - present
Designed, deployed, and managed scalable, secure AWS infrastructure (EC2, ECS, EKS, Lambda, S3, RDS, ALB, VPC, IAM) supporting backend platforms processing thousands of transactions daily under strict reliability and compliance requirements. Developed and maintained Kubernetes clusters on Amazon EKS in production — managing workload deployments, horizontal pod autoscaling (HPA), node operations, network policies, and incident response; also operated ECS services for containerized workloads. Implemented and optimized CI/CD pipelines in GitHub Actions automating application build, testing, and deployment — multi-stage workflows with validation, approval gates, and security checks — reducing average deployment time from 45 minutes to under 15 minutes and cutting failed releases by 40%; maintained existing Jenkins pipelines for legacy services. Provisioned and operated all infrastructure using Terraform as the primary IaC tool — modular, versioned, reusable across environments — reducing provisioning time by ~60% and eliminating environment drift. Managed Git-based version control across services, establishing branching strategies, pull-request review standards, and repository governance for consistent, auditable change management. Monitored, troubleshot, and improved system performance, availability, and reliability through centralized observability with Prometheus, Grafana, Datadog, and CloudWatch — dashboards, structured logging, and alerting that improved mean time to resolution for production incidents. Ensured infrastructure compliance with security best practices — IAM least-privilege across AWS environments, VPC network segmentation, KMS-backed key management, and Secret Manager integration aligned with compliance-oriented governance (patterns directly applicable to SOC 2 controls). Wrote Python and Bash automation for routine operations, infrastructure tasks, log processing, and CI/CD tooling — reducing manual operational toil across environments. Drove cost controls through quarterly reviews — rightsizing EC2 and RDS instances, decommissioning idle resources, and cleaning up unused EBS snapshots for systematic, workload-based spend optimization. Collaborated daily with development teams across fully distributed environments under Agile methodologies, integrating infrastructure solutions seamlessly and owning systems end-to-end with strong autonomy.