Irving García Mendoza

IT Controls & Compliance | Information Security & Infrastructure Manager

Remote — Mexico · hola@irving.bio


Professional Summary

Information Security and Infrastructure leader with 15+ years across IT risk, security consulting, and cloud operations — currently Infrastructure & Information Security Manager at Clara, a pre-IPO LATAM fintech. Owns the IT control environment protecting financial operations across Mexico, Brazil, and Colombia: design and operation of IT General Controls (logical access, change management, security operations) over a 70-account, two-region AWS Organization with a ~USD $2.9M annual cloud and SaaS footprint. Combines hands-on cloud security engineering with audit-evidence discipline (Sprinto, Prowler, Steampipe/Turbot) and a production AI platform practice — security-bounded LLM agents on AWS Bedrock. Earlier career delivering regulatory and information-security consulting to banks, insurers, and government on fintech frameworks and Latin-American data-protection law. An ownership mindset suited to building an IT controls function ahead of an IPO, not merely maintaining one.


Career Highlights


Core Competencies

IT Risk & Compliance - IT General Controls (ITGC) and IT Application Controls (ITAC) over financial data flows - IT risk identification, control-gap assessment, remediation, and findings management - Audit support and evidence collection for internal and external auditors - SOX (IT component) control concepts; SOC 2, ISO 27001, PCI DSS, NIST CSF awareness - Compliance automation (Sprinto) and continuous control monitoring

Information Security - Identity lifecycle (joiner/mover/leaver), least privilege, segregation of duties - Organization-scale vulnerability/CVE remediation and configuration hardening - Threat detection and logging: GuardDuty, CloudTrail, Security Lake, Inspector, SIEM - Posture management (Prowler) and cross-account governance (Steampipe/Turbot Pipes) - Zero Trust access (Cloudflare WARP/Gateway), WAF, KMS encryption, secrets management, email authentication (SPF/DKIM/DMARC) at multi-domain scale

Cloud Infrastructure, FinOps & Resilience - AWS multi-account Organizations (70 accounts), SCPs, StackSets, multi-region operations - Infrastructure as Code: Terraform, Terragrunt, CloudFormation; Python/Bash/TypeScript automation - Cost decomposition, anomaly root-cause analysis, platform business cases, AWS Marketplace subscription and vendor-contract administration - Backup/recovery and BCP/DRP controls across jurisdictions

AI Platform Engineering & Automation - Production LLM agents on AWS Bedrock (Anthropic Claude) with layered read-only enforcement - RAG architectures: Bedrock Knowledge Bases, Aurora pgvector, OpenSearch - Serverless automation on Cloudflare Workers (Workflows, Durable Objects, D1, AI Gateway) - Workflow automation (n8n), MCP server development, AI governance and spend tiering


Professional Experience

Clara — Infrastructure & Information Security Manager

Pre-IPO fintech (corporate cards & spend management), LATAM — Mexico, Brazil, Colombia · 2020 – Present

Owns the IT control environment and cloud security posture for a regulated, pre-IPO fintech operating a 70-account AWS Organization across three countries and two AWS regions.

IT General Controls — Logical Access - Operates the engineering identity lifecycle — 60+ documented offboardings enforcing timely revocation, least privilege, and segregation of duties across AWS, Okta/Auth0, and SaaS. - Led an organization-wide IAM Identity Center security audit (65 accounts, 165 SSO users, 52 permission sets), remediating dormant users, over-privileged assignments, and offboarding gaps; runs a recurring credential-hygiene program (87 user/key remediations, organization-wide credential reporting). - Migrated 240 users from legacy OpenVPN to Cloudflare Zero Trust (WARP/Gateway) via a phased, MDM-driven rollout across three countries, then decommissioned the VPN estate.

IT General Controls — Change & Configuration Management - Governs infrastructure change through an auditable ticketed workflow — 400+ completed change/security tickets and 40+ projects led through a staged pipeline (change approval, functionality test, proof of success, rollback verification). - Builds hardened Amazon Linux 2023 golden AMIs on a quarterly cadence for all accounts and regions; directed lifecycle programs spanning DocumentDB engine upgrades (7 clusters), OpenSearch engine upgrades, EOL Lambda runtime remediation (78 functions), and launch template / EC2 Image Builder standardization.

Security Operations & Vulnerability Management - Led the organization-wide AWS GuardDuty deployment — 70 accounts, two regions, delegated administration, StackSet auto-enrollment, KMS-encrypted publishing — with centralized EventBridge alerting of high-severity findings to Slack. - Drove fleet-wide remediation: critical CVEs patched across all accounts, SSH disabled on 174 EC2 instances, vulnerable kernel module removed across 13 accounts via SSM, followed by continuous SSH compliance monitoring with daily organization-wide reporting. - Ran the email anti-spoofing program: 31 corporate domains audited, authentication driven to 96% compliance across 18 AWS SES sending domains (SPF hard-fail, DKIM, DMARC enforcement). - Conducted an organization-wide WAFv2 effectiveness review (21 Web ACLs protecting 65 load balancers) and operates container-image scanning with automated triage to Slack.

Network Segmentation & Resilience - Led and completed the VPC Peering to AWS Transit Gateway migration (80+ connections, multi-region, cross-account) with atomic route cutover and instant-rollback design. - Redesigned 6 partner site-to-site IPSec VPNs across 6 accounts from static routing to BGP dynamic routing with hardened cryptography (IKEv2-only) and automatic failover, validated on a staging canary before production cutover. - Manages backup/recovery and BCP/DRP controls (AWS Backup, snapshot policies, cross-account backup account) across multiple operating jurisdictions.

Data Platform Controls & Operations - Remediated high-availability risk across an 8-cluster Amazon MSK (Kafka) estate — 740+ topics brought to replication and MinISR standards with zero downtime, including response to an AWS Health high-risk event on a production payments cluster; re-architected Kafka observability onto Amazon Managed Prometheus and Grafana. - Raised OpenSearch lifecycle (ISM) coverage from 18.5% to 98.6% across a 1,703-index security-logging cluster; remediated write-saturation and shard-distribution incidents on production search clusters. - Supports data-integrity controls over financial pipelines: AWS DMS change-data-capture (13 replication instances, 213 tasks) with latency alerting, encryption at rest/in transit, and access controls over an estate of 86 Aurora PostgreSQL clusters, DocumentDB, OpenSearch, MSK, Databricks, MWAA (Airflow), and QuickSight.

AI Platform Engineering - Designed and operates five autonomous LLM agents on AWS Bedrock (Anthropic Claude) serving infrastructure operations over Slack — conversational diagnostics, ECS operations, Kafka alarm triage, FinOps reporting — under a four-layer read-only security model (IAM boundaries, pre-execution guard hooks, toolset restriction, prompt contracts). - Built an LLM-driven support-intake bot on Cloudflare Workers (Workflows, Durable Objects, D1, AI Gateway) converting Slack requests into structured, tracked tickets; replaced third-party SaaS automations with auditable Workers. - Deployed a self-hosted agent memory platform on ECS and a compliance-documentation RAG architecture (Bedrock Knowledge Bases on Aurora pgvector) supporting a PCI DSS environment; operates an n8n automation platform with 13+ production alerting workflows; governs organization Bedrock access and AI spend through inventory audits and model-tiering analysis.

FinOps, Vendor & Audit Governance - Stewards the ~USD $2.9M annual cloud and SaaS footprint: cost observability pipelines, monthly service-level decomposition, anomaly root-cause analysis, and centralized cross-account CloudWatch observability spanning 64 accounts. - Administers the AWS Marketplace subscription portfolio (11 products — Databricks, Auth0/Okta, Red Hat OpenShift, LaunchDarkly, Splunk, Fortinet, Turbot, and observability platforms) including renewals, private offers, and a contract-to-contract observability vendor migration; produced the ROSA-versus-EKS business case identifying ~31% run-rate savings. - Generates audit and control evidence via Sprinto; built and delivered a compliance knowledge base consolidating control documentation as a single source of truth.

Grow Mobility — Chief Security Officer & Infrastructure Manager

Advanced Solutions 2H Mexico — Solutions & Services Manager

Independent Information Security & Regulatory Consultant

Early Career — Systems Administration


Technical Skills


Certifications & Professional Development


Languages


Education


Additional