Skip to content
View brunodearruda's full-sized avatar

Block or report brunodearruda

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
brunodearruda/README.md

Bruno Arruda

Cloud Security & Infrastructure Professional

AWS • Cloud Security • Secure Architecture • DevSecOps

Dublin, Ireland

Website · Cloud Security Portfolio · LinkedIn

About

Cloud Security & Infrastructure Professional with 15+ years of experience across technology, infrastructure, enterprise systems, project and governance environments, and information security. I am currently deepening my specialization in AWS Cloud Security through certification study, hands-on architecture, security labs, and technical documentation.

My work connects an infrastructure foundation with security controls, governance requirements, and practical AWS implementation.

Current Focus

  • AWS Cloud Security and secure AWS architecture
  • Identity and access management
  • Cloud logging, monitoring, and auditability
  • Secure CI/CD and DevSecOps practices
  • Security architecture decisions and trade-offs

Featured Cloud Security Project

AWS Security Portfolio — brunoarruda.com

A security-first personal website and technical portfolio built with Astro and deployed on AWS. Beyond the website itself, the project is a hands-on Cloud Security case study documenting architecture decisions, implemented controls, deployment identity, monitoring, and operational trade-offs.

Live Website · Architecture Article · Hands-on LAB · Source Repository

Architecture at a glance

  • Public delivery: User → Route 53 / DNSSEC → CloudFront → Origin Access Control → private S3 origin
  • Deployment identity: GitHub Actions → OIDC → AWS STS → scoped IAM role → S3 deployment / CloudFront invalidation

Implemented controls include:

  • Private S3 origin with S3 Block Public Access and CloudFront Origin Access Control
  • Route 53, DNSSEC, TLS, security headers, and Content Security Policy
  • AWS WAF operating in monitor mode
  • CloudWatch and SNS for monitoring and notifications
  • CloudTrail for audit visibility into configured management events
  • GitHub Actions OIDC and AWS STS for temporary deployment credentials through a scoped IAM role

Technical Focus

Cloud & AWS

AWS architecture, Amazon S3, Amazon CloudFront, Amazon Route 53, IAM, AWS STS, CloudWatch, CloudTrail, and AWS WAF.

Security

Cloud security architecture, identity and access, security controls, logging and monitoring, auditability, security governance, and vulnerability management.

DevSecOps

GitHub Actions, OIDC federation, temporary AWS credentials, secure deployment workflows, and CI/CD security validation.

Background & Certifications

  • Project Management Professional (PMP), achieved in 2025
  • Previous certifications include CompTIA Security+ and AWS Certified Cloud Practitioner; these credentials are no longer active

Currently Learning

  • AWS Certified Solutions Architect – Associate — current focus
  • AWS Certified Security – Specialty — planned next specialization
  • Hands-on AWS security architecture and lab implementation

Contact

Pinned Loading

  1. brunoarruda.com brunoarruda.com Public

    Cloud Security portfolio built with Astro and AWS, using private S3, CloudFront, DNSSEC, GitHub OIDC, monitoring, and audit logging.

    Astro