Available for opportunitiesΒ·Montreal, QC

Mario de Jesus

DevSecOps Engineer Β· Technical Lead Β· Cloud Architect

Building secure, scalable cloud systems with AI-powered automation. 15+ years turning complex security challenges into measurable business outcomes.

111+
Vulnerabilities Remediated
92%
Compliance Score
99.9%
Uptime Maintained
46%
AWS Cost Reduction

Security-first engineer with a bias for automation

DevSecOps Engineer and Technical Lead with 15+ years driving security-first initiatives, cloud transformation, and cross-functional team leadership. I specialize in AWS security architecture, vulnerability remediation at scale, and building resilient systems with measurable business impact. Currently based in Montreal (open work permit, no sponsorship required) and open to opportunities across Canada.

Enterprise Security Transformation
Led remediation of 111+ critical findings across 23 AWS services, improving compliance from 45% to 92% in under a year
Infrastructure Cost Optimization
Reduced AWS infrastructure costs by 46% through right-sizing, lifecycle policies, and automated resource management
Technical Leadership
Led cross-functional teams of 14+ professionals across development, QA, and DevOps disciplines
AI/ML Innovation
Designed and shipped a machine learning product recommendation system with real-time Elasticsearch pipelines
Current
DevSecOps Engineer / Technical Lead
ArkusNexus
March 2020 – Present

Leading enterprise AWS security architecture, automated vulnerability remediation, and DevSecOps culture adoption for a cross-functional team of 14.

Tech Lead / Full Stack Developer
Front Runner
January 2019 – March 2020

Led security-first development for containerized e-commerce platforms, CI/CD pipelines, and a team of 6 engineers.

Senior Developer – Security Focus
Softtek
August 2012 – January 2019

Conducted enterprise security audits and penetration testing across Java, .NET, PHP, and database stacks.

Tools & technologies I work with

Cloud & AWS

AWS EC2AWS RDSAWS LambdaAWS ECS/ECRAWS S3CloudFrontRoute53WAFGuardDutySecurity HubCloudWatchKMS

DevOps & CI/CD

GitHub ActionsAzure DevOpsDockerTerraformBlue/Green DeploySAST/DASTTrivySemgrepSonarQubeOWASP Dep-Check

Security

CIS BenchmarksSOC2 PrepIAM / Zero TrustVPC ArchitectureModSecurityBurp SuiteMetasploitPen TestingIncident ResponseOWASP Top 10

Languages & Automation

PythonBoto3TypeScriptNode.jsPHPBashElasticsearchscikit-learnpandasFirebase

Real problems, measurable outcomes

A selection of security and infrastructure challenges I've solved in production environments.

AWS Security Transformation

From 45% to 92% compliance in 8 months

Led an enterprise-wide security overhaul addressing 111+ critical vulnerabilities across 23 AWS services, establishing automated compliance monitoring and zero-downtime remediation workflows.

111+
Vulnerabilities resolved
45β†’92%
Compliance score
0
Security incidents
Read case study

AWS Cost Optimization

46% cost reduction without performance trade-offs

Designed and implemented a comprehensive cost optimization program using Python/Boto3 automation, right-sizing analysis, and lifecycle policies β€” fully automated and repeatable.

46%
Infrastructure cost reduction
3mo
Time to deliver
100%
Automated reporting
Read case study

CI/CD Security Pipeline

Security-first deployments at 10Γ— the velocity

Replaced manual deployment bottlenecks with GitHub Actions pipelines featuring automated SAST/DAST gates, container scanning, and blue/green deployments β€” eliminating manual steps entirely.

10Γ—
Deployment frequency
0
Manual deployment steps
<5min
Rollback time
Read case study

Multi-Tenant AI Agent Platform

Zero open ports. Per-tenant isolation. Production AI agents.

Designed and built a production cloud platform to run OpenClaw β€” an autonomous AI agent β€” for multiple isolated tenants. Evolved from single-tenant EC2 to Docker-containerized multi-tenancy with SSM-only access and zero open inbound ports.

2
AWS regions
87%
IaC quality score
0
Open inbound ports
Read case study

Cybersecurity Compliance Program

29% β†’ 87% compliance across 5 security frameworks

Led an end-to-end compliance program for a multi-carrier insurance platform β€” from gap analysis to automated controls β€” achieving 87% compliance against ISO 27001, CIS Controls v8, and LFPDPPP in under 6 weeks while managing 5 simultaneous insurer security questionnaires.

29β†’87%
Compliance score
<6wk
Program timeline
12+
Formal deliverables
Read case study