Kuberns logo

Carlos Herrera

About

Carlos Herrera is an Application Security Engineer based in Mexico City with 8 years of experience reviewing, auditing, and hardening deployment pipelines for SaaS companies across Latin America and the US. He has conducted security audits for over 40 engineering teams, with a focus on CI/CD pipeline vulnerabilities, secrets management failures, and the cloud IAM misconfigurations that are responsible for a disproportionate share of real-world breaches. Carlos holds an OSCP certification and has worked on SOC 2 Type II compliance implementations for four companies, each of which required significant changes to how environment variables, API keys, and deployment credentials were handled in their shipping workflows. He has a direct, technical writing style, focused on what developers can fix today, not theoretical threat models. At Kuberns, Carlos writes about security in deployment: how to build secure-by-default pipelines, what secrets management looks like in production, and the specific security shortcuts that teams take when shipping fast and why those shortcuts compound over time into real risk.

Articles