Security • Identity • Platform

Architecting Control & Resilience
in Critical Systems

Security & Platform Architect with 20+ years of experience in critical and regulated environments, including banking and telecommunications. I design identity-driven architectures that ensure control, traceability and operational resilience across hybrid and multi-cloud environments.

I design systems where failure is not an option.

About

I am a Security and Platform Architect with more than 20 years of experience working in critical environments where system failure has direct business impact, including banking and telecommunications sectors.

My work focuses on designing architectures where control, identity and observability are core elements. I bridge the gap between architecture and operations, ensuring that systems are not only well designed, but also secure, traceable and resilient under real conditions. My experience includes regulated environments aligned with European and enterprise security frameworks.

What I Do

I design systems where security, identity and operational control are embedded by design, not added as an afterthought.

Identity Architecture

Design of IAM and PAM models for hybrid and multi-cloud environments, with centralized governance and auditable privileged access.

Zero Trust

Security models based on identity, context, segmentation, and continuous verification rather than implicit network trust.

Multi-Cloud Governance

Architectures that decouple identity and access from cloud providers such as OpenStack, AWS, Azure, and GCP.

Operational Resilience

Observability, automation, and recovery-oriented architectures that reduce operational risk and improve service continuity.

Architecture Initiatives

Personal architecture initiatives that reflect my current direction: identity governance, operational resilience, design automation, and controlled system authority.

AEGIS

Identity Fabric

AEGIS addresses a common failure in modern architectures: lack of centralized control over identity and access. It defines a unified identity fabric across hybrid and multi-cloud environments, enabling Zero Trust, full traceability and consistent governance across distributed systems. The goal is simple: ensure that every access is controlled, auditable and aligned with operational and security policies.

Explore AEGIS →

ARGOS

Operational Resilience

An architecture focused on automated remediation driven by observability, following a model of detection, reasoning, action, and verification to reduce manual intervention and recovery time.

Explore ARGOS →

DAEDALUS

Design Automation

An architecture initiative aimed at automating the generation of Low-Level Design for hybrid cloud infrastructure, improving consistency and scalability across multiple platforms.

Explore DAEDALUS →

ATLAS

Governed Source of Truth

A governed authority system for asset lifecycle, topology, runbooks, and operational readiness, designed to bring structure and trust to infrastructure and production processes.

Explore ATLAS →

Architecture Approach

In complex systems, the main challenge is not technology — it is control.

  • Identity as the control plane: access must be governed centrally
  • Traceability: every action must be auditable
  • Operational resilience: systems must be designed to fail safely

Selected Experience

ING Bank (via HCL Technologies)
Platform & Security Architecture in regulated banking environments
  • Architecture design and platform governance in regulated environments
  • Definition of observability, control and resilience models
  • Security and compliance alignment with regulatory frameworks
  • End-to-end traceability across infrastructure, platform and application layers
Telefónica
Infrastructure, monitoring, and private cloud architecture
  • Design of large-scale infrastructure and monitoring architectures
  • Implementation of private cloud environments (OpenStack)
  • Security audits and infrastructure governance in complex environments
  • Development of centralized control and remote access systems
Wolters Kluwer
Security strategy, identity architecture, and high availability systems
  • IT security strategy and vulnerability assessments
  • Identity and access architecture based on Active Directory
  • High availability data platforms and disaster recovery strategies
  • Security perimeter architecture and virtualization design

Contact

Based in Alicante, Spain. Open to architecture-focused opportunities in security, identity, and multi-cloud platform design.

Email: baltasar.collantesginer@gmx.es

Portfolio: baltasar.collantesginer.net

Location: Alicante, Spain