Security • Identity • Platform

Security & Cloud Architect
IAM/PAM | Zero Trust | Multi-Cloud

I design identity-driven architectures for secure, resilient, and scalable multi-cloud environments, combining deep technical background with architectural decision-making across banking, telecom, and enterprise platforms.

About

I am a Security and Platform Architect with more than 25 years of experience evolving from hands-on technical roles into architecture and system design. My work has spanned critical environments such as banking, telecommunications, and engineering.

My approach combines real operational knowledge with architectural thinking. I design systems that are not only theoretically sound, but also practical to operate, secure, and resilient over time. I specialize in identity governance, Zero Trust architectures, and multi-cloud platform security.

What I Do

My focus is on secure architecture, identity governance, and platform design for distributed environments.

Identity Architecture

Design of IAM and PAM models for hybrid and multi-cloud environments, with centralized governance and auditable privileged access.

Zero Trust

Security models based on identity, context, segmentation, and continuous verification rather than implicit network trust.

Multi-Cloud Governance

Architectures that decouple identity and access from cloud providers such as OpenStack, AWS, Azure, and GCP.

Operational Resilience

Observability, automation, and recovery-oriented architectures that reduce operational risk and improve service continuity.

Architecture Initiatives

Personal architecture initiatives that reflect my current direction: identity governance, operational resilience, design automation, and controlled system authority.

AEGIS

Identity Fabric

A reference architecture for unified identity governance across hybrid and multi-cloud environments. It integrates IAM and PAM under a Zero Trust model and centralizes access control across distributed systems.

ARGOS

Operational Resilience

An architecture focused on automated remediation driven by observability, following a model of detection, reasoning, action, and verification to reduce manual intervention and recovery time.

DAEDALUS

Design Automation

An architecture initiative aimed at automating the generation of Low-Level Design for hybrid cloud infrastructure, improving consistency and scalability across multiple platforms.

ATLAS

Governed Source of Truth

A governed authority system for asset lifecycle, topology, runbooks, and operational readiness, designed to bring structure and trust to infrastructure and production processes.

Selected Experience

ING Bank (via HCL Technologies)
Platform & Security Architecture in regulated banking environments
  • CI/CD architecture and platform automation
  • Observability design with Prometheus, Grafana, and ELK
  • Security segmentation and compliance-aligned platform controls
  • Network governance and traceability through Atlas
Telefónica
Infrastructure, monitoring, and private cloud architecture
  • Distributed infrastructure monitoring architectures
  • Unified remote access design using Apache Guacamole
  • Private cloud architecture based on OpenStack
  • Security and infrastructure audits in international environments
Wolters Kluwer
Security strategy, identity architecture, and high availability systems
  • IT security strategy and vulnerability assessments
  • Identity and access architecture based on Active Directory
  • High availability data platforms and disaster recovery strategies
  • Security perimeter architecture and virtualization design

CV

This site is intended as a concise professional overview. Full background and detailed experience are available in the CV.

Contact

Based in Alicante, Spain. Open to architecture-focused opportunities in security, identity, and multi-cloud platform design.

Email: baltasar.collantesginer@gmx.es

Location: Alicante, Spain

Website: aegis-identityfabric.com