DevOps Engineer with experience designing secure, resilient, and automated cloud environments from the ground up. I work across cloud infrastructure, CI/CD, observability, security, and platform automation, with a strong focus on Infrastructure as Code, operational excellence, and reliable delivery workflows.
I am AWS Certified as DevOps Engineer - Professional and Solutions Architect - Associate, with additional focus on cloud architecture and security practices. My day-to-day work includes AWS, Terraform, GitLab CI, GitHub Actions, Docker, Prometheus, Grafana, Linux, Python, and modern CI/CD platforms.
I enjoy building systems that are not only deployed correctly, but also observable, maintainable, secure, and easy for engineering teams to operate. I am especially interested in Harness Engineering, Spec-Driven Development (SDD), AI-assisted engineering workflows, platform automation, disaster recovery, compliance-driven cloud environments, and mentoring teams around DevOps and cloud-native practices.
I design cloud infrastructure using Infrastructure as Code with tools such as Terraform, AWS CDK, AWS SAM, and CloudFormation. I care about making environments repeatable, versioned, auditable, and simple enough for teams to evolve safely.
I build CI/CD workflows with GitLab CI, GitHub Actions, and AWS-native services, connecting source control, automated validation, deployments, environment promotion, and operational feedback loops.
I work on observability and operations using CloudWatch, Prometheus, Grafana, logs, metrics, alarms, dashboards, and runbooks, with the goal of making systems easier to understand before and after production incidents.
I also focus on cloud security practices such as IAM least privilege, access controls, audit trails, account guardrails, key management, compliance-oriented configurations, and automated remediation patterns.
Hands-on AWS DevOps project with SAM and CDK applications focused on serverless APIs, CI/CD pipelines, observability, deployment safety, infrastructure validation, and production-style documentation. It includes architecture diagrams, runbooks, ADRs, automated tests, validation commands, and release documentation.
AWS security automation toolkit for account guardrails and event-driven remediation. It explores root user login notifications, stale IAM access key quarantine, compromised access key response, region restriction policy patterns, and CDK-based infrastructure with automated tests.
I am currently deepening my work around Harness Engineering, Spec-Driven Development (SDD), AI tools for software delivery, disaster recovery practices, compliance-aware cloud operations, and security automation for production environments.
- LinkedIn: cristian-montoya-devops
- GitHub: cr-montoya


