<!-- Hero section -->
Infrastructure &
Security Automation
Engineer

PontoPe
I'm Pedro Martins, an infrastructure engineer who builds, hardens, and runs production systems - from AWS pipelines to a self-hosted server publishing a national journal with zero open ports.
<!-- Featured work -->
Most of the work below was built under NDA, so the source can't be published - only selected snippets. Happy to walk through a larger portion of the code 1-on-1.
Revista BRASILCON

Self-hosted OJS publishing platform for Brazil's consumer-law journal - officially recognized by BRASILCON
Hyundai Backend

Secure PII onboarding pipeline - least-privilege IAM, data minimization, zero exposure incidents
JBS Backend

High-throughput data processing system
pontosv

Hardened bare-metal Debian server I run solo - zero-open-port ingress for the BRASILCON journal
TrustStack
A practical reference for platform and security teams: govern AWS accounts, detect and safely remediate exposure, admit only verified images, and monitor hardened Kubernetes workloads
ZombiesWeb

Interactive CoD Zombies lore timeline and map guides
Docker Email Tracker
a Docker project that tracks email opens and clicks using FastAPI, Redis and PostgreSQL
BNPL Platform

Full-stack Buy Now Pay Later microservices in Go
CowRec

Computer Vision backend for livestock tracking
Clinical Chart

Local-first dental anamnesis - AES-256-GCM at the edge, LGPD by architecture, zero server
<!-- About, experience & capabilities -->
Professional Profile
Infrastructure Engineer with 2+ years building production automation and operating Linux/AWS/containerized systems, now specializing in DevSecOps and cloud security. My approach starts with the adversarial questions: how does this fail, and what leaks when it does?
I came up through backend automation - securing PII pipelines for enterprises like Hyundai - and discovered the part I couldn't stop thinking about was protecting the systems, not just building them. Today I practice secure-by-default engineering: least privilege, secrets management, hardening, and zero-open-port ingress.
Experience
Systems owned in production
Capabilities
How I secure, ship, and operate
Security & Infrastructure
- Linux Hardening (Debian/RHEL)
- Least-Privilege IAM
- Secrets Management
- Zero-Trust Ingress
- Firewall & DNS Management
- Incident Response & Runbooks
Cloud & DevOps
- AWS (S3, IAM, EC2)
- Docker & Kubernetes
- CI/CD Pipelines
- Terraform (IaC)
- nginx & systemd
- Self-Hosted Production Ops
Backend & Automation
- Python / FastAPI & Go
- Secure API Architecture
- Input Validation (OWASP)
- PII Handling & Data Minimization
- PostgreSQL / MariaDB / Redis
- Audit Logging & Traceability
<!-- Current certification focus -->
RHCSA
Red Hat Certified System Administrator
<!-- My tech stack -->












<!-- Take a break -->
Pixel
Perfect
Think you have an eye for detail? Spot the square with the slightly different color. The higher the score, the smaller the difference.
Color Spotter
Find the different block
Which data structure uses the LIFO (Last In, First Out) principle?
Knowledge
Check
Validating backend concepts and architecture patterns. Test your knowledge against these technical interview questions.
<!-- Get in Touch -->
Let's Work
Together
* Click terminal to type. Try 'help'.