Skip to content
View othiagorpantoja's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report othiagorpantoja

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
othiagorpantoja/README.md

Hi, I'm Thiago Pantoja — Principal Solutions Architect (Staff+)

Business Strategy × Platform Engineering · Multi-cloud · Cloud Governance · Security by Design · FinOps

LinkedIn Email WhatsApp SP WhatsApp AM Location Languages


Principal Solutions Architect (Staff+) at the intersection of business strategy and Platform Engineering.
I design multi-account/region architectures across AWS, Azure, GCP, and OCI with Cloud Governance, Security by Design, and FinOps at the core.
I standardize the SDLC with IaC (Terraform/CDK/Ansible/CloudFormation), Kubernetes (EKS/AKS/GKE/OKE), and CI/CD — delivering scale, reliability, and cost optimization in complex multi-cloud environments.

Quick links


What I do

  • Modernization & Migrations: landing zones, Organizations, policy-as-code; networking (TGW/DX); containers (ECS/Fargate/EKS); API Gateway; event-driven integrations (EventBridge/SQS/Step Functions/Lambda); service mesh.
  • Security & Compliance: Zero Trust, IAM/KMS, WAF/ALB, account segregation, DR/Backup with compliance — tying technical decisions to risk, cost, and time-to-market.
  • DevEx & Platform: IDP/Backstage with service catalog & golden paths (opinionated templates in Terraform/CDK/K8s), reusable pipelines (GitHub Actions), PR previews, and self-service with guardrails.
  • Observability & Reliability: Prometheus/Grafana/Loki/OpenTelemetry, SLOs from day one.

Tech stack

Tools and languages I use most often in platform & cloud architecture, delivery, and operations.

Languages & Runtimes

Java · C# · .NET · Node.js · TypeScript · JavaScript · PHP · Python · Go · Kotlin · Bash · PowerShell

Backend & Frameworks

Spring Boot · Quarkus · ASP.NET Core · Razor/Blazor · Express · NestJS · FastAPI · Laravel

Frontend & Mobile

React · Next.js · Vue · Angular · React Native

Datastores & Caching

PostgreSQL · MySQL · SQL Server · MongoDB · Redis/Valkey · DynamoDB

Messaging & Integration

SQS · SNS · EventBridge · Kafka/MSK · Kinesis · Step Functions · API Gateway · Apigee Edge · Camunda

Cloud Providers

AWS · Azure · GCP · Oracle Cloud (OCI)

Containers, Orchestration & Packaging

Docker · Kubernetes (EKS, AKS, GKE, OKE) · Helm · Karpenter · HPA/PDB · Service Mesh

IaC & Policy

Terraform · AWS CDK · CloudFormation · Ansible · OPA/Conftest · Policy as Code

CI/CD & GitOps

GitHub Actions · GitLab CI · Azure DevOps · Jenkins · Argo CD · Flux · Blue/Green & Canary

Observability & AIOps

OpenTelemetry · Prometheus · Grafana · Loki · CloudWatch · Azure Monitor · GCP Monitoring · Dynatrace · New Relic · Zabbix · Elasticsearch/Kibana · PagerDuty · incident.io

Security by Design

Zero Trust · WAF/ALB · IAM · KMS · Secrets Manager/Parameter Store/Vault · TLS 1.2/1.3 · Supply-chain security (SBOM, image signing with cosign)

Architecture & Practices

Platform Engineering · Platform Architect · SRE · System Design · Well-Architected · DORA · FinOps (CUR/Athena/Glue, tagging, rightsizing, Savings Plans) · LGPD · DevSecOps


Selected projects

FinOps Automation — CUR + Athena + Glue + PDF Insights
Automated cost ingestion (CUR), ETL with Glue, Athena queries, scheduled reports with serverless functions, and PDF/HTML insights for stakeholders.
Highlights: cost allocation by tag/account, rightsizing suggestions, Savings Plans/RIs coverage, monthly deltas and KPIs.

🔗 Repo: thiagorpantoja/finops-automation
Chatwoot on ECS Fargate — Multi-tenant + ALB + WAF
Production-grade deployment on ECS Fargate with RDS/Redis, ALB rules per host, WAF, TLS 1.2/1.3, and IaC modules.
Highlights: blue/green ready, autoscaling policies, least-privilege IAM, KMS, and observability pack.

🔗 Repo: thiagorpantoja/chatwoot-ecs
EKS Blueprints + Karpenter — SLO-first Platform
EKS with Karpenter, OTel, Prometheus, Grafana, Loki, and Golden Paths templates for app teams.
Highlights: IDP/Backstage onboarding, PR env previews, guardrails, SLOs from day one.

🔗 Repo: thiagorpantoja/eks-blueprints-slo

Work with me

“Platform done right multiplies value across every squad.”

Popular repositories Loading

  1. SistemaPepsus SistemaPepsus Public

    Forked from tailanefv/SistemaPepsus

    Prontuário Eletrônico do Paciente

    Python 1

  2. SistemaHospitalar SistemaHospitalar Public

    Forked from yasminvic/SistemaHospitalar

    Repositório para Sistema Hospitalar com Prontuário Eletrônico.

    C# 1

  3. Sistema-de-Gerenciamento-Hospitalar Sistema-de-Gerenciamento-Hospitalar Public

    Forked from Kauanesco/Sistema-de-Gerenciamento-Hospitalar

    Sistema de gerenciamento de pacientes, funcionários e prontuários.

    C# 1

  4. rabbitmq rabbitmq Public

    Smarty 1

  5. flutter_laravel_firebase_app flutter_laravel_firebase_app Public

    PHP 1

  6. easynext_finops_gcp easynext_finops_gcp Public

    Python 1