CI&T / AWS Community Builder · Hashicorp Champions Amaury Borges Souza is a Cloud Security Engineer and postgraduate professor with 12+ years of experience in technology, specializing in AWS Security, DevSecOps, Infrastructure as Code, and AI-assisted security automation. FOTO DEL SPEAKER An international speaker and active member of the tech community, Amaury is a 4× AWS Community Builder, HashiCorp Ambassador, and HashiCorp User Group Leader. He regularly shares practical experiences in Cloud Security, DevSecOps, Terraform. DEVOPS DEVOPSDAYS.PE CLOUD SECURITY DEVSECOPS 02 / 45
I met platform engineers, security leaders, and Terraform practitioners facing the same challenge: How do we secure Terraform without friction into pipeline? DEVOPSDAYS.PE 03 / 45
delivery • Security teams want governance and compliance • Manual reviews create bottlenecks • Result: shadow IaC and risky deployments Question: How do we secure Terraform without blocking developers? DEVOPSDAYS.PE 08 / 45
Agents • Non-Human Identities • CI/CD • Artifacts • Third-party integration Security has never been as important as it is in this era. DEVOPSDAYS.PE 12 / 45
from the planning stage • Automated scanners and tests in the pipeline • Reduced risk of vulnerabilities in production • Meets compliance requirements without sacrificing agility DEVOPSDAYS.PE 17 / 45
the end of the pipeline. It needs to be embedded across infrastructure, networking, security services and the application layer. HASHICORP Infrastructure Networking Security Application Infrastructure as Code Service Registry & Discovery Secrets management Workload orchestration Compliance & Governance Secure Networking Encryption Application-centric networking Self-service infrastructure Service Mesh Advanced Data Protection Developer-centric application delivery Automated Networking DEVOPSDAYS.PE 21 / 45
completó correctamente. Track principal Charlas y talleres sobre cultura DevOps, plataformas internas y developer experience. INFO La próxima edición será del 21 al 22 de agosto. Ver agenda ADVERTENCIA Los cupos para talleres son limitados. CFP OPEN Postula tu charla ERROR No se pudo procesar el pago, intenta de nuevo. Comparte tu experiencia con la comunidad. El CFP está abierto hasta agosto. Postular DEVOPSDAYS.PE 30 / 45
as Code engine integrated with Terraform Cloud/Enterprise. Creates custom rules (Rego-like) that validate plans and apply compliance gates.. Checks Terraform, CloudFormation, ARM, Kubernetes, and Dockerfiles. Applies over 1,000 CIS/NIST policies and blocks insecure deployments before production. It implements CIS, NIST, PCI-DSS, and GDPR controls in an automated way. Example: blocks public buckets or roles with broad privileges. • Static analysis for Infrastructure as Code • Detects compliance drift • Enforces guardrails at plan and apply time • Integrates with Terraform Cloud run tasks DEVOPSDAYS.PE • Maps infrastructure to CIS, NIST, PCI-DSS, GDPR • Detects misconfigurations early in CI 34 / 45
AI Agents • Non-Human Identities • CI/CD • Artifacts • Third-party integration Security has never been as important as it is in this era. DEVOPSDAYS.PE 04 / 21
completó correctamente. Track principal Charlas y talleres sobre cultura DevOps, plataformas internas y developer experience. INFO La próxima edición será del 21 al 22 de agosto. Ver agenda ADVERTENCIA Los cupos para talleres son limitados. CFP OPEN Postula tu charla ERROR No se pudo procesar el pago, intenta de nuevo. Comparte tu experiencia con la comunidad. El CFP está abierto hasta agosto. Postular DEVOPSDAYS.PE 04 / 21