Kevin Jorquera · Security engineer & builder

I write about the systems I build—and how I try to break them.

InfoSecIQ is my working notebook for cloud security, software engineering, architecture decisions, and the useful lessons that rarely make it into documentation.

~/kevin/field-notes

$ currently_exploring

  • making secure defaults practical
  • designing resilient cloud systems
  • shipping software without the mystery

learning in public

About this space

A personal lab, with the door left open.

I was born in Valparaíso, Chile, and immigrated to the United States when I was four. I’m both a U.S. and Chilean citizen, and that dual identity is an important part of who I am and how I see the world.

At my core, I’m an engineer and builder—but I also understand what it takes for technical systems to operate within serious compliance requirements. I’ve worked in environments shaped by HITRUST, HIPAA, SOC 2 Type I and Type II, and FedRAMP, translating those requirements into practical engineering decisions instead of treating compliance as a paperwork exercise.

I build custom tools that save clients and employers substantial time and cost, and I design security architectures that reduce friction for engineering teams. My goal is to make the secure path the efficient path—protecting the organization without slowing down the people responsible for building it.

These notes favor useful detail over hot takes: patterns I would use again, mistakes I would not, and explanations I wish I had when I started. Writing is how I examine what I’ve built, challenge my assumptions, and keep learning in public.

Cloud securitySecurity architectureDevSecOpsHITRUST & HIPAASOC 2 & FedRAMPSoftware designDependency security
Start reading