← patriciocabrera.com

Patricio Cabrera

IT Operations & DevOps Engineer

San Fernando, Buenos Aires, Argentina (UTC-3) patricio@patriciocabrera.com linkedin.com/in/patncab github.com/PatricioCabrera

Profile

IT Operations and DevOps Engineer with 7+ years of experience across enterprise support, Microsoft 365, identity, infrastructure, and cloud operations. Hands-on with Exchange Online mail flow, connectors, shared mailboxes, online archives, and message tracing; Teams external collaboration controls; and SharePoint/OneDrive licensing, storage, and domain controls. Experienced with Microsoft Entra ID, OIDC/SAML integrations, app registrations, PowerShell automation, and business-critical support for 600+ users. Applies enterprise AI tools to accelerate complex automation across AWS IAM and Entra ID. Professional working English (B2/C1).

Selected Impact

  • Microsoft 365 operations. Administer Exchange Online mail flow, cloud connectors, mail flow rules, shared mailboxes, Online Archive, and message tracing; manage external-domain controls across Teams, SharePoint, and OneDrive, including licensing and storage expansion from 1 TB to 5 TB under E3.
  • Identity modernization. Migrated 4 legacy applications from NTLM to Microsoft Entra ID using OIDC/SAML, eliminating local credentials.
  • Terraform & IaC adoption. Introduced Terraform-based workflows in the AWS organization, driving the shift from manual operations to component-based infrastructure as code. Replaced manual DBA backup tasks with snapshot-driven automation as part of this transition.
  • Three production migrations to AWS. Owned end-to-end execution alongside AWS Professional Services, from Landing Zone Accelerator deployment to production go-live.
  • Secure CI/CD federation. Designed centralized OIDC identity federation (identity-as-code) between CI/CD pipelines and every AWS account - short-lived credentials scoped per repository, eliminating static access keys.
  • TLS / PKI governance. Built an internal certificate management tool for legacy on-prem applications and migrated production AWS workloads to ACM with auto-renewal, eliminating recurring certificate-expiration incidents.
  • FinOps & cost optimization (current). Driving AWS cost optimization across the organization - rightsizing, scheduling, storage-tier and licensing decisions - with projected savings presented monthly to management.
  • SAP S/4HANA RISE migration. Led the AWS infrastructure track - hybrid connectivity, fileserver migration, satellite app integrations via RFC, and cutover coordination with SAP and consulting partner for 600+ users.

Experience

Molinos Agro S.A.

- Present

Buenos Aires, Argentina

DevOps Engineer

- Present

Infrastructure Engineer

-

Promoted from Infrastructure to DevOps after leading the modernization of legacy on-premise systems and initial AWS adoption. Sole DevOps owner of a 7-account hub-and-spoke AWS organization (Networking, Apps PRD/QA, Shared Services, Log Archive, Audit, Management) - VPC design, Transit Gateway routing, hybrid VPN connectivity, IAM Identity Center, and centralized DNS.

  • Identity & application access. Design IAM least-privilege roles and OIDC/SAML integrations; administer Microsoft Entra ID groups, App Registrations, Enterprise Applications, permissions, and cross-account access patterns.
  • Monitoring & observability. CloudWatch cross-account dashboards with SSO access; contributed to Zabbix + Grafana monitoring rollout for hybrid infrastructure.
  • Production troubleshooting. Cross-stack issue resolution across Linux, Windows Server, SQL Server (RDS), VPC networking, DNS, mail flows, and identity systems in a live enterprise environment.
  • CI/CD modernization. Migrated TFS on-premise to Azure DevOps Cloud, modernizing repositories and pipelines for the development team.
  • High availability & load balancing. Deployed and supported HAProxy + Keepalived and Windows NLB clusters for on-prem critical apps.
  • Automation & AI-assisted operations. Python, Bash, and PowerShell scripting for repetitive tasks, including scoped AWS IAM access, Entra ID group-to-role mappings, and App Registration/Enterprise App provisioning developed with enterprise ChatGPT/Codex and Claude.
  • Hybrid & multi-cloud operations. AWS and Azure networking, compute, DNS, storage, backup, and site-to-site VPN connectivity, including VPC/Transit Gateway architecture on AWS and VMs, Blob Storage, and Backup Vaults on Azure.

IT Support & Microcomputing Roles

-

Febicom (assigned to Molinos Agro) · Textil Amesud · Six Working (assigned to Etex / Durlock)

Progressive 3.5-year track in end-user and infrastructure support: Active Directory administration, Domain Controller repair, JIRA triage and escalation, ERP/CRM support, mass equipment provisioning, and technical support to 150+ users. This trajectory built the operational foundation for the transition to infrastructure engineering at Molinos Agro.

Projects

CloudLaunchpad - AWS platform bootstrap

Personal project · in progress

Turns an empty AWS account into a production-ready environment in under 15 minutes. Modular Terraform for the full stack; GitHub Actions CI/CD authenticated via OIDC (no static credentials); Dockerized FastAPI service on ECS Fargate; RDS PostgreSQL; S3 + CloudFront delivery; SSM Parameter Store for secrets and configuration; CloudWatch logging and alarms. Built to practice secure-by-design, reproducible infrastructure end to end.

Technical Stack

  • AWS: IAM, EC2, VPC, RDS, Lambda, ECS Fargate, S3, CloudFront, Route 53, Transit Gateway, SSM Parameter Store, ACM, CloudWatch, SES, SQS, EventBridge, Control Tower, IAM Identity Center, Landing Zone Accelerator
  • Microsoft 365: Exchange Online, Teams, SharePoint Online, OneDrive, mail flow and connectors, shared mailboxes, Online Archive, message tracing, licensing, and storage management
  • Infrastructure as Code & Automation: Terraform (modular), Python, Bash, PowerShell, AI-assisted scripting with enterprise ChatGPT/Codex and Claude
  • CI/CD & Containers: GitHub Actions (OIDC federation), Azure DevOps Pipelines, Git, Docker
  • Security & Identity: Microsoft Entra ID, App Registrations, Enterprise Applications, OIDC/SAML, Active Directory, IAM least-privilege, TLS/ACM/PKI, SPF and mail-flow troubleshooting
  • ITSM: Jira Service Management
  • Networking: VPC design, Transit Gateway, hybrid AWS/Azure site-to-site VPN, private/public DNS, HAProxy, Keepalived, Windows NLB
  • Observability: AWS CloudWatch, Zabbix, Grafana
  • Systems & Databases: Linux (Ubuntu, CentOS, SUSE), Windows Server, SQL Server (RDS & on-prem), PostgreSQL, VMware ESXi/vCenter, Veeam
  • Cloud (secondary): Azure (VMs, DNS, Blob Storage, Backup Vaults, VPN); SAP S/4HANA RISE ecosystem (BTP, Cloud Connector, RFC)

Education & Certifications

  • AWS Solutions Architect - Associate · in progress (Adrian Cantrill course, learn.cantrill.io)
  • AWS Official Courses: Architecting on AWS · Advanced Architecting on AWS · DevOps Engineering on AWS
  • Windows Server Hybrid Advanced Services · Azure
  • Certified Tech Developer Bootcamp · Digital House - 2021-2023
  • Continuous learning: Platzi (platzi.com/@PatchXploit) - ongoing tech curriculum
  • Languages: Spanish (native) · English (B2/C1)