JEFF ×07+YEARS XPCOINS ×00BLOG POSTSWORLD 2026CALI · UTC-5
WORLD 2026 · JEFFINCLOUD.COM

JEFF IN
CLOUD

Jeffry Hernández — Senior SRE & Platform Engineer (CKAD). I build and run Azure + Kubernetes platforms, and write about what breaks along the way.

MYSTERY CRATES

Bump a crate to drop its power-up.
ITEM BOX · 0/8
Empty. Bump a crate above.
CONTAINERS & COMPUTEKubernetes (AKS, k3s)DockerHelmKEDAHPAApp ServiceAzure FunctionsVMSS
AZURE NETWORKINGVNetsNSGsPrivate Link / EndpointsApplication GatewayFront DoorAzure FirewallVPN GatewayAzure DNSPrivate DNS zonesHub-spoke
IDENTITY & SECURITYMicrosoft Entra IDManaged IdentitiesAzure Key VaultRBACWorkload identity federationHashiCorp VaultCyberArk PAS
IAC & CI/CDTerraformAzure DevOpsJenkinsGitLabGitOpsBashPowerShellPythonAzure CLI
OBSERVABILITYDatadogPagerDutyAzure MonitorLog AnalyticsApplication InsightsSLOsOn-call designAlert tuning
DATA & MESSAGINGAzure SQL Managed InstanceConfluent Cloud (Kafka)
AI PLATFORMKServevLLMNVIDIA GPU OperatorDCGMLangfuseAzure AI FoundryAI SearchMCP + Kubernetes
SYSTEMS & NETWORKINGLinuxWindows Server / IISTCP/IPDNSLoad balancingFirewall / WAF (Cisco, Fortinet)

WORLD SELECT

DOWNLOAD CV ↓
B-SECURE
2019 – 2020
PERFICIENT
2020 – 2021
EPAM
2022
WIZELINE
2022 – NOW
NEXT LEVEL
SOON
LEVEL 4-1 · WIZELINE2022 – NOW · Remote · Fortune 100 US media & entertainment client
Senior Site Reliability Engineer
  • Operate production on AKS, App Service, Azure Functions and VMSS across multiple environments for a global advertising platform — fully managed as code with Terraform.
  • Led near-zero-downtime migrations across Kubernetes clusters and from AWS to Azure over a hub-spoke topology (VNets, NSGs, Private Endpoints, App Gateway, Azure Firewall, VPN Gateway) with Private DNS zones.
  • Secured app-to-database connectivity to Azure SQL Managed Instance with Private Endpoints + Private DNS, keeping traffic off the public internet.
  • Drove the Splunk → Datadog migration: Helm-templated APM agents, Azure and Confluent Kafka integrations, monitors and alerts as Terraform code.
  • Designed a new on-call workflow integrating PagerDuty, Azure DevOps and Datadog, reducing alert noise and improving incident response.
  • Tuned HPAs and adopted KEDA for event-driven autoscaling; hardened secrets with Key Vault + Managed Identities, enforced RBAC, shipped audit logs to SIEM.
  • Deployed ML models with KServe, Azure AI Foundry and AI Search; integrated MCP-based agents with Kubernetes clusters.
1-1B-SECURE ◀ JEFF2019 – 2020
Security Architect
Cali, Colombia
  • Designed, deployed and supported CyberArk Core PAS (Vault, CPM, PVWA, PSM, PTA, PSMP) with HA, DR and replication for enterprise clients.
  • Implemented on-prem and cloud firewalls (Cisco, Fortinet), published web apps via cloud WAF, and ran core network services (DNS, DHCP, HTTP, SMTP, proxy).
  • Containerized internal apps with Docker; managed Windows Server and Linux. Earned CyberArk CDE and Fortinet NSE 1–3.
2-1PERFICIENT ◀ JEFF2020 – 2021
DevOps Engineer
Cali, Colombia
  • Migrated AWS monolithic applications to Azure AKS microservices, replacing manual configuration with Terraform-managed infrastructure.
  • Implemented HashiCorp Vault for secrets and a remote-access Cisco VPN integrated with Microsoft Entra ID.
  • Standardized Jenkins CI/CD pipelines to reduce lead time for changes.
3-1EPAM ◀ JEFF2022
Systems Engineer (DevOps / Cloud)
Medellín, Colombia · Remote
  • Managed Azure DevOps CI/CD configurations and automated manual tasks with PowerShell and Azure CLI.
  • Designed RBAC strategies across Azure tenants and remediated cloud security vulnerabilities.
4-1WIZELINE ◀ JEFF2022 – NOW
Senior Site Reliability Engineer
Remote · Fortune 100 US media & entertainment client
  • Operate production on AKS, App Service, Azure Functions and VMSS across multiple environments for a global advertising platform — fully managed as code with Terraform.
  • Led near-zero-downtime migrations across Kubernetes clusters and from AWS to Azure over a hub-spoke topology (VNets, NSGs, Private Endpoints, App Gateway, Azure Firewall, VPN Gateway) with Private DNS zones.
  • Secured app-to-database connectivity to Azure SQL Managed Instance with Private Endpoints + Private DNS, keeping traffic off the public internet.
  • Drove the Splunk → Datadog migration: Helm-templated APM agents, Azure and Confluent Kafka integrations, monitors and alerts as Terraform code.
  • Designed a new on-call workflow integrating PagerDuty, Azure DevOps and Datadog, reducing alert noise and improving incident response.
  • Tuned HPAs and adopted KEDA for event-driven autoscaling; hardened secrets with Key Vault + Managed Identities, enforced RBAC, shipped audit logs to SIEM.
  • Deployed ML models with KServe, Azure AI Foundry and AI Search; integrated MCP-based agents with Kubernetes clusters.
5-?NEXT LEVEL ◀ JEFFSOON
Your team?
Remote · B2B
  • Open to remote contractor / B2B engagements with US & EU companies.
  • Flexible overlap with US and CET business hours — see the Save Point below.
TUTORIAL ZONE:B.Sc. Software Engineering — Politécnico Grancolombiano (completed while working full-time)Technologist — SENA (Servicio Nacional de Aprendizaje)

BONUS STAGE

CERTIFICATIONS

STARCKADCertified Kubernetes Application Developer — Linux Foundation / CNCF
LOADING…CKACertified Kubernetes Administrator — renewal in progress
EARNEDCyberArk CDECyberArk Defender
EARNEDFortinet NSE 1–3Network Security Expert

TALKS

SPEAKER · KCD COLOMBIA 2025HABLÁNDOLE A TU CLÚSTER DE KUBERNETESAI agents & MCP on Kubernetes — co-presented with Guillermo Esguerra.
SPEAKER · CNCG CALIMEETUPS & LABSSessions on Kubernetes autoscaling (HPA/KEDA), observability and platform engineering.

COMMUNITY

CO-ORGANIZERKCD COLOMBIAKubernetes Community Days (CNCF) national organizing team — program curation, speaker coordination, community growth.
CHAPTER ORGANIZERCNCG CALILocal CNCF chapter: recurring meetups, hands-on labs and workshops on Kubernetes and cloud-native tech.

COIN HEAVEN · BLOG

ALL POSTS →
NO COINS YETThe first post is loading… follow along via RSS.

SAVE POINT

Open to remote contractor / B2B engagements with US & EU companies — flexible overlap with US and CET business hours.