Gerardo Lucero
Solutions Architect | DevSecOps Engineer
Profile
Solutions Architect and DevSecOps Engineer with 7+ years building distributed systems across fintech and retail. Rare combination of platform architecture (Kafka, Kubernetes, IDP), security engineering (SAST/DAST, policy-as-code, container hardening), and technical product management. Track record of building Internal Developer Platforms, standardizing CI/CD pipelines at scale, and leading multi-team technical initiatives across AWS, GCP, and OpenShift. AI practitioner with applied experience in intelligent systems. Seeking remote roles in platform engineering, staff/principal engineering, or solutions architecture.
Experience
Designed and implemented secure CI/CD infrastructure for a financial institution with 1,200+ repositories and 3,000+ build artifacts across 15+ technology stacks (Java, React, Salesforce, on-premise, mobile, and more). Built reusable pipeline libraries covering SAST, DAST, quality gates, policy-as-code, and container hardening — enabling consistent secure delivery across the entire engineering organization.
- → Standardized CI/CD pipelines across 1,200+ repositories and 3,000+ artifacts — 15+ build types including Java, React, Docker, Salesforce, Kubernetes, Cloud Run and on-premise
- → Reusable GitHub Actions libraries with SAST, DAST, quality gates, policy-as-code and secret management
- → Container hardening, dependency scanning and golden path templates reducing defects across multi-stack deployments
- → Security pipeline architecture ensuring regulatory compliance (CNBV/Banxico) for a regulated financial institution
Founded and led the Architecture Squad — a cross-functional governance body that defined architecture standards, maturity frameworks, and reference architectures adopted across 7+ engineering teams. Designed cloud-native solutions on AWS (CodePipeline, CodeBuild, ECS, Lambda, Glue) and built an Internal Developer Platform (IDP) on Kubernetes enabling self-service infrastructure. Drove organizational alignment through ADRs, C4 documentation, and a 5-level maturity model covering architecture, security, infrastructure automation, and observability.
- → Founded Architecture Squad — governance model with maturity matrix (5 levels × 8 dimensions) and technology catalog adopted by 7+ teams
- → Reference architectures (DDD, EDA, hexagonal) and ADR/C4 documentation standards rolled out organization-wide
- → Internal Developer Platform (IDP) on Kubernetes — golden paths, multi-stack self-service deployments, AWS CodePipeline + CodeBuild pipelines
- → Batch system processing 1M employment history records in under 3 minutes — AWS Glue Jobs + RDS + Feature Store integration for ML workloads
- → Karpenter dynamic node scaling, centralized authentication layer, and Dynatrace observability with SLO/SLI definition
- → OpenShift transition strategy and coached 7+ engineering teams on architecture practices and cloud-native delivery
Led architecture and delivery across 3 multidisciplinary squads building customer-facing and internal systems for retail operations spanning 100+ stores. Collaborated with an external consultancy on solution design, standardizing infrastructure on AWS and virtualized environments. Introduced observability practices and proposed a microservices improvement initiative that reduced critical incident recovery times.
- → Coordinated 3 squads delivering customer-facing optimizations and internal admin systems (React, TypeScript, Node.js)
- → AWS API Gateway + Docker deployments on virtualized environments — standardized across retail operations in 100+ stores
- → Grafana implementation for real-time process monitoring and proactive incident detection
- → Critical incident resolution — restored production services and reduced recovery time for high-impact retail systems
- → Proposed microservices architecture improvement adopted by engineering leadership
Led the end-to-end digital transformation of a multi-unit lending and collections platform across 3 business units, managing a 12-person team (9 engineers, 2 QA, 1 DevOps). Architected and delivered event-driven systems on Kafka processing 400K monthly credit applications and a payments circuit handling 200M transactions — over 1B MXN processed in a single quarter. Designed state machines for credit origination, collections strategy, and decisioning, while building the full digital sales and collections infrastructure from the ground up.
- → 400K monthly credit applications — event-driven origination platform on Kafka with state machines deployed across 3 business units
- → 200M payment transactions — full payments circuit: Oxxo, PayNearMe, OpenPay, card payments, STP, bank direct debits (BBVA, Santander, HSBC)
- → 1B MXN processed in 3 months across digital payment channels
- → Collections decision engine: 1M batch jobs processed in 40 seconds using Spark + Python
- → Led 12-person engineering team — credit origination, payments, collections, and mobile sales app (Android, Kafka, Firebase)
- → Credit bureau (Buró de Crédito) integration for national lending operations
- → Employee of the Year — consecutive awards, youngest team member to receive the recognition
- → Platform remains in production and served as the architectural foundation for the next-generation lending system
Developed and implemented a web-based car rental system that optimized payment and booking workflows. Led the design and development of a real-time reservation system enabling dynamic pricing and availability management, ensuring an efficient and user-friendly experience.
- → Web-based car rental system with optimized payment workflows
- → Real-time reservation system with dynamic pricing
- → Full-stack development and team leadership
Skills
Management
Architecture
Cloud
Observability
Languages
Frameworks
Data
Tools
Education
Kafka Summit
Confluent
Diploma in Artificial Intelligence
Universidad del Valle de México
B.S. in Computer Systems Engineering
Instituto Tecnológico de La Paz
Robotics & Home Automation Competitions
Regional Academic Competitions
Competed in robotics and home automation (domotics) at regional level during high school — early foundation in embedded systems and hardware engineering.