Carlos Herrera
About
Carlos Herrera is an Application Security Engineer based in Mexico City with 8 years of experience reviewing, auditing, and hardening deployment pipelines for SaaS companies across Latin America and the US. He has conducted security audits for over 40 engineering teams, with a focus on CI/CD pipeline vulnerabilities, secrets management failures, and the cloud IAM misconfigurations that are responsible for a disproportionate share of real-world breaches. Carlos holds an OSCP certification and has worked on SOC 2 Type II compliance implementations for four companies, each of which required significant changes to how environment variables, API keys, and deployment credentials were handled in their shipping workflows. He has a direct, technical writing style, focused on what developers can fix today, not theoretical threat models. At Kuberns, Carlos writes about security in deployment: how to build secure-by-default pipelines, what secrets management looks like in production, and the specific security shortcuts that teams take when shipping fast and why those shortcuts compound over time into real risk.