Amaury Borges Souza

Amaury Borges Souza

Cloud Security Specialist| Professor (FIAP MBA) | AI Security Engineering | Technical Leadership | AWS Community Builder

São Paulo, Brazil

Actions

Amaury is an active international conference speaker, presenting at events such as HashiTalks, HashiConf, AWS Community Days, DevOpsDays, SREday, and security conferences across different regions. His talks explore not only security tools, but the engineering and leadership challenges behind them: how to scale security, influence technical decisions, enable developer autonomy, and make the secure path the easiest path.

Beyond the conference stage, Amaury is an MBA Professor at FIAP and an Instructor at Alura, where he teaches and creates hands-on content around Cloud Security, Secure SDLC, Infrastructure as Code, and AI-assisted Security. He is passionate about turning real-world engineering challenges into practical learning experiences and helping professionals grow their technical skills and security mindset.

Area of Expertise

  • Information & Communications Technology

Topics

  • Security
  • Cloud Security
  • AWS Security
  • HashiCorp Ambassador
  • Identity & Access Management (IAM)
  • Artificial Intelligence (AI)
  • Professor
  • Leadership
  • Agentic AI
  • Engineering Culture & Leadership
  • Communicating with Clarity
  • tech speaker

Your Next Privileged User Is an AI Agent

Rethinking identity, permissions and trust in the age of agentic AI

AI agents are rapidly moving from assistants that suggest code to autonomous actors capable of calling APIs, modifying infrastructure, interacting with CI/CD pipelines, and accessing cloud environments.

This creates a new security problem: our next privileged user may not be human.

In this session, we'll explore how agentic AI changes the traditional identity and trust model. Through practical cloud and DevSecOps scenarios, we'll examine what happens when AI agents receive access to tools, credentials, pipelines, and production infrastructure, and what can go wrong when those permissions are poorly designed.

We'll look at practical approaches for securing agent identities using least privilege, short-lived credentials, workload identity, policy enforcement, human approval boundaries, and auditability.

Attendees will leave with a practical security model for answering a question that every engineering organization adopting AI agents will soon face: what should an AI agent actually be allowed to do?

Your Pipeline Passed. But Can You Trust What You Shipped?

Modern CI/CD pipelines can run dozens of security checks and still fail to answer a fundamental question: can we trust the artifact reaching production?

This session explores how platform teams can build software supply chain security directly into the developer workflow, from source and dependencies to SBOMs, artifact signing, provenance, policy enforcement and deployment.

Instead of adding more security tools for developers to manage, we'll look at how golden paths and platform guardrails can make secure software delivery the default.

Terraform at Scale: Security Without Friction

Security teams often become the final approval gate for infrastructure delivery, creating friction, delays, and frustration for developers.

But what if security could accelerate delivery instead of blocking it?

In this talk, I’ll share practical lessons from real-world cloud environments on how to integrate security directly into Terraform pipelines using policy-as-code, automated validation, and secure-by-default patterns.

We’ll cover how tools like Checkov, TFLint, GitHub Actions, and cloud governance controls help reduce misconfigurations, improve compliance, and enable developers to move faster with confidence.

This session is for engineers who want secure infrastructure without sacrificing speed, because DevSecOps should feel like enablement, not bureaucracy.

Kiro CLI para Cloud Engineers

Uma introdução prática ao AWS Kiro CLI mostrando como acelerar tarefas do dia a dia em cloud engineering, criação de recursos, troubleshooting e automação operacional.

AI-Assisted Cloud Security on AWS

As equipes de Cloud Security nunca tiveram tantas ferramentas de segurança disponíveis. Scanners de vulnerabilidades, análise de Infraestrutura como Código (IaC), SBOM, Security Hub, GuardDuty e diversos outros serviços produzem milhares de alertas diariamente. O desafio atual não é mais encontrar vulnerabilidades, mas entender quais realmente representam risco para o negócio.

Nesta palestra, veremos como a Inteligência Artificial pode atuar como um copiloto para equipes de Cloud Security, auxiliando na análise contextual, priorização de vulnerabilidades e aceleração da remediação sem comprometer a velocidade de entrega.

Ao final da sessão, os participantes compreenderão como combinar práticas modernas de DevSecOps, automação e IA para reduzir ruído operacional, melhorar a experiência dos desenvolvedores e fortalecer a segurança de aplicações executadas na AWS.

5 Kubernetes Security Mistakes I Keep Finding in Real Clusters

Kubernetes is powerful, but misconfigurations are still one of the leading causes of security incidents in real-world clusters.

In this session, I’ll walk through five common Kubernetes security mistakes I frequently encounter in production environments, covering RBAC misconfigurations, over-privileged containers, insecure secrets handling, missing network policies, and supply chain risks.

You’ll leave with practical guidance and actionable steps to secure your clusters without slowing down developer workflows.

Terraform com IA: Explorando Práticas de DevSecOps com Prompt Engineering no GitHub Copilot Chat

Nesta talk, vou explorar como o GitHub Copilot Chat pode ser um verdadeiro agente no seu fluxo com Terraform, desde a criação de recursos seguros, até a automação de validações com ferramentas como Checkov, tflint, GitHub Actions.

Secure Terraform without slowing down developers

In this talk, I’ll explore how to make Terraform environments more secure without slowing down development teams. Instead of relying on heavy gates and complex tools, we’ll focus on secure defaults, clear boundaries, and simple Terraform features that act as guardrails.

AWS Community Day Bolivia 2026 Sessionize Event

August 2026 Santa Cruz de la Sierra, Bolivia

DevOps Days Lima 2026

El punto de encuentro para Ingenieros de Software, Arquitectos, Líderes Técnicos, Ingenieros DevOps, Ingenieros de seguridad, CTOs y CIOs. Conecta con la comunidad, aprende de casos reales y acelera decisiones que impactan negocio y plataforma.█

August 2026 Lima, Peru

DevOps Days Rio de Janeiro 2026

Devopsdays is a worldwide series of technical conferences covering topics of software development, IT infrastructure operations, and the intersection between them. Each event is run by volunteers from the local area.

August 2026 Rio de Janeiro, Brazil

BSides São Paulo 2026

A Conferência Security BSides São Paulo (BSidesSP) é um evento gratuito organizado pela comunidade de segurança da informação.

May 2026 São Paulo, Brazil

Esquenta BSides RJ 2026

10 Verificações Rápidas para Saber se Sua Conta AWS Está Realmente Segura
Quando entro em uma conta AWS pela primeira vez, sigo um checklist claro: sem ferramenta milagrosa e sem teoria demais, apenas verificações práticas que revelam rapidamente o nível real de maturidade de segurança. Nesta palestra, Amaury compartilha as 10 análises que faz nos primeiros minutos, com uma abordagem simples, direta e baseada em experiências reais.

March 2026 Rio de Janeiro, Brazil

HashiTalks 2026 Sessionize Event

February 2026

SREDay Campinas

Proteja Pipelines de SRE Terraform e AWS: Aplicando o Shift Left na Confiabilidade.

December 2025 Hortolândia, Brazil

Hashicorp User Group Campinas

Segurança e IA em DevOps: Desafios e possibilidades

September 2025 Campinas, Brazil

HashiTalks: Brasil Sessionize Event

August 2025

CI&T Security Summit 2024

DevSecOps with Checkov.

October 2024 Campinas, Brazil

Campus Party 2024 (Dumont Hackerspace)

Práticas Seguras na Nuvem (AWS)

July 2024 São Paulo, Brazil

Security BSides São Paulo 2024

Defining your CI/CD pipeline in GitLab with the powerful Checkov integrated into Terraform.

May 2024 São Paulo, Brazil

Hashicorp User Group Campinas

IaC no dia a dia e casos de uso do Terraform

April 2024 Campinas, Brazil

Tosconf[4] (LHC Hackerspace)

Ansible para Engenheiros DevOps

March 2024 Campinas, Brazil

Amaury Borges Souza

Cloud Security Specialist| Professor (FIAP MBA) | AI Security Engineering | Technical Leadership | AWS Community Builder

São Paulo, Brazil

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top