You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Sorin FluerasSF

Sorin Flueras

AWS Security Architect

€800/day
Timișoara, RO
3-7 years

Average response time: 1 hour

About Sorin

I help AI and SaaS startups secure their AWS environments so they can ship fast, pass security audits and customer reviews, and avoid the 3am incident calls.

Over the past 6 years I've built and hardened AWS for previous employers, and a portfolio of growth-stage clients through my consultancy, Secure Stack Consulting. Background includes AWS Security Specialty, Solutions Architect Associate, SysOps Administrator Associate, and HashiCorp Terraform Associate certifications.

▸ What I deliver:
• Blast Radius Framework — structured AWS security assessment that maps real attack propagation paths. Most tools flag misconfigurations; BRF answers "if one resource is compromised, how far can the attacker actually reach?" → secure-stack-consulting.com/blast-radius-framework
• Multi-account AWS Landing Zones with IAM Identity Center, SCPs, centralized logging — migrate off IAM users without breaking anything
• DevSecOps CI/CD pipelines that catch IaC misconfigs, secrets, and policy violations before production (Bitbucket, GitHub Actions, ECS runners for isolation + cost)
• Reusable Terraform / CloudFormation modules — secure-by-default, not bolted on after the audit
• Hybrid AWS + Cloudflare Zero Trust (mTLS tunnels, WAF, DNS routing) with centralized logging
• Threat detection + incident response: GuardDuty, Security Hub, Inspector + automated playbooks. I've restored a compromised AWS account live

▸ Compliance:
• PCI-DSS — AWS workloads in Cardholder Data Environments, network segmentation for scope reduction
• SOC 2 / ISO 27001 — audit-readiness, control mapping, evidence automation
• Comfortable working alongside QSAs, auditors, customer security reviewers

Stack: AWS, Terraform, CloudFormation, Python, Bash, Go, GitHub Actions, Bitbucket, Docker, ECS, Lambda, Cloudflare Zero Trust + WAF, GuardDuty, Security Hub, Inspector.
  • Romanian

    Native or bilingual

  • English

    Fluent

Remote only
Primarily works remotely

Experience

  • Secure Stack Consulting S.R.L.
    DevSecOps Engineer
    April 2022 - Today (4 years and 2 months)
    Timișoara, TM, Romania
    Architected and enforced AWS security at scale: Designed multi‑account AWS security architecture with IAM Identity Center, SCPs and centralized logging; migrated from IAM users to an SSO Landing Zone integrated with Google Workspace; automated threat detection and incident‑response playbooks. Built and maintained security‑focused CI/CD pipelines: Developed a DevSecOps pipeline framework that integrates security checks, IaC scanning and policy validation; implemented dynamic Bitbucket/GitHub runners on ECS to reduce cost and improve isolation. Engineered secure, reproducible infrastructure: Created reusable Terraform and CloudFormation modules for VPCs, ALBs, ECS clusters, Lambda/API Gateway workflows and other AWS resources, enabling environment‑agnostic, security‑first deployments. Implemented hybrid cloud and Zero Trust solutions: Designed AWS + Cloudflare architectures with mTLS tunnels, DNS routing and automated WAF policies; integrated Cloudflare logs into centralized monitoring for better visibility. Automated internal tools and processes: Built Slack bots and CLI scripts to streamline internal security workflows, credential rotation and resource audits; created dashboards to track vulnerabilities and configuration drift kickresume.com. Led incident response and security governance: Handled live AWS security incident, assessed blast radius, and restored compromised account; instituted weekly security reviews and trained teams on best practices.
    AWS Cybersecurity DevSecOps GenAI AWS Security
  • Atos
    Cloud Security Engineer
    July 2020 - April 2022 (1 year and 9 months)
    Romania
    For a while I was responsible for the automation part of a BigData project, using python scripts. Also here I used Ansible to install and configure Kerberos in HA mode and to configure other BigData specific tools Worked on enhancing Office365 security by creating scripts in Powershell that automatically configured the desired settings. In parallel, I worked on a Vulnerability Assessment project where I used Nessus. Learned Terraform and deployed various resources in AWS and GCP Worked on a DevSecOps project on AWS where I took part in both the design and implementation phases - IaC (using Terraform and Pytest with TFtest or Golang for the testing part) Also here (and on other projects) I use CI / CD pipelines in Github or Gitlab. Gained working experience with most of the AWS Services included in the AWS Solutions Architect - Associate certification
    AWS Security DevSecOps Cybersecurity Cloud Security
  • IBM
    Security & Compliance Administrator
    November 2018 - July 2020 (1 year and 8 months)
    Timișoara, TM, Romania
    IBM
    I was responsible for running and developing scripts for various health check and vulnerability assessment processes. I worked closely together with the SysOps Team and I learned how to fix most of the detected vulnerabilities. Used technologies: Bash, Powershell, Ansible, Ansible Tower, Nessus, Linux/Windows Administration, ServiceNow
    Cybersecurity

Recommendations

Be the first to recommend Sorin

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Bachelor's Degree In Computers
    Polytechnic University of Timisoara
    2019
    Bachelor's Degree In Computers
  • AWS Certified SysOps Administrator - Associate Amazon Web Services
    AWS
    2023
    AWS Certified SysOps Administrator - Associate Amazon Web Services

Categories