Cloud Security Best Practices
Nine practical habits I use to make cloud environments harder to misuse, easier to observe, and calmer to recover.
Open the notebookKevin Jorquera · Security engineer & builder
InfoSecIQ is my working notebook for cloud security, software engineering, architecture decisions, and the useful lessons that rarely make it into documentation.
~/kevin/field-notes$ currently_exploring
learning in public
About this space
I was born in Valparaíso, Chile, and immigrated to the United States when I was four. I’m both a U.S. and Chilean citizen, and that dual identity is an important part of who I am and how I see the world.
At my core, I’m an engineer and builder—but I also understand what it takes for technical systems to operate within serious compliance requirements. I’ve worked in environments shaped by HITRUST, HIPAA, SOC 2 Type I and Type II, and FedRAMP, translating those requirements into practical engineering decisions instead of treating compliance as a paperwork exercise.
I build custom tools that save clients and employers substantial time and cost, and I design security architectures that reduce friction for engineering teams. My goal is to make the secure path the efficient path—protecting the organization without slowing down the people responsible for building it.
These notes favor useful detail over hot takes: patterns I would use again, mistakes I would not, and explanations I wish I had when I started. Writing is how I examine what I’ve built, challenge my assumptions, and keep learning in public.