Skip to content

Head of Infrastructure · Zyte

I keep large-scale platforms up — and build the teams that run them.

Twenty years in production infrastructure, nine of them leading the function. I design, migrate and operate high-availability platforms across public cloud and bare metal — and I am still the person who takes the page, reads the logs and runs the incident.

See selected work Download CV Uruguay · Remote · UTC−3
in production infrastructure
20 yrs in production infrastructure
engineers hired, trained and led
9 engineers hired, trained and led
of customer data migrated between clusters
500 TB of customer data migrated between clusters
recurring savings, no capacity lost
~$40k /mo recurring savings, no capacity lost
OS upgrades with zero user disruption
80 + OS upgrades with zero user disruption
internal users served worldwide
300 + internal users served worldwide

01 / About

Infrastructure engineer from Uruguay. I have spent a decade running the platform behind one of the largest web-data companies in the world.

I joined Zyte — then Scrapinghub, the company behind Scrapy — as a DevOps engineer in 2015, and have been Head of Infrastructure since 2017, reporting first to the CEO and later to the CTO. I built the infrastructure function from zero: interviewing, hiring, training and coaching every engineer on it, and growing it to a team of nine distributed across the globe.

The team owns everything underneath the product: bare-metal and cloud Kubernetes, multi-cloud estates, databases, streaming, observability, CI/CD, security operations, incident response, vendor relationships and the full infrastructure budget. We serve 300+ internal users and platforms that handle billions of requests.

I lead hands-on. The same person who writes the roadmap, negotiates with providers and presents to the leadership team also plans the zero-downtime migrations, chases the memory leak in a legacy storage cluster at 2am, and takes incident commander for the ones that matter. I have never wanted the kind of leadership job where you stop being able to read the stack trace.

Away from work I am a certified Ubiquiti AirMax engineer who builds long-distance wireless links for fun and out of necessity, a former ITF-certified tennis coach, and someone who genuinely believes remote teams run on trust, clear writing and blameless post-mortems.

  • Boring is a feature

    The best infrastructure work is invisible. Eighty-plus operating system upgrades and a full storage-cluster migration that nobody outside the team noticed is the result I am proudest of.

  • Cost is an engineering problem

    Multi-year optimisation across cloud and on-prem — commitments, right-sizing, storage and logging, provider migrations — reaching roughly $40k a month in recurring savings without giving up performance or capacity.

  • Calm is a deliverable

    Reorganisations, security incidents, cluster failures. My job in those moments is to absorb the noise so nine engineers can keep working, and to be the person other teams call for context.

02 / Experience

Twenty years, four employers

  1. Aug 2017 — Present

    Remote

    Head of Infrastructure

    Zyte (formerly Scrapinghub)

    Own all infrastructure for a global web-data extraction platform — multi-cloud and bare metal, data and streaming, observability, security operations, incident response, vendor management and the infrastructure budget. Built and lead the team behind it.

    • Built the infrastructure team from scratch to nine engineers across the globe — hiring, onboarding, career paths and coaching — supporting 300+ internal users and every production platform.
    • Planned and led the migration of the company's platform storage: a Hadoop/HBase cluster holding roughly 500 TB of customer data, taken through full production cutover and legacy hardware decommissioning.
    • Drove the Mesos-to-Kubernetes transition, replacing a 140-node Mesos cluster with on-prem Kubernetes, alongside 100+ node managed clusters (GKE, EKS) and 170+ node highly available bare-metal estates.
    • Ran a multi-year cost programme across cloud and on-prem — committed-use discounts, storage and logging optimisation, workload right-sizing, and a full cloud-provider exit — reaching about $40k in monthly recurring savings with no loss of performance or capacity.
    • Delivered the infrastructure workstream for ISO 27001: rewrote processes and security policies, co-led audit reporting across the database, storage and directory backends, and signed off validated results.
    • Designed and implemented the company-wide incident response process, established the post-mortem culture behind it, and act as incident commander for the highest-severity incidents.
    • Completed 80+ OS upgrades and legacy decommissions with zero user disruption, upgraded foundational systems untouched since their original deployment, enabled IPv6, modernised the web load-balancer tier and standardised a highly available monitoring stack.
    • Led the technical response to a sensitive customer-facing security incident — forensics, root-cause analysis, executive reporting and a joint presentation with Legal — retaining the customer's trust and their business.
    • Own the infrastructure budget end to end: cost allocation, forecasting with Finance, and vendor negotiation across bare-metal and GPU providers, including expanding GPU capacity at cost-neutral spend.
    • Kubernetes
    • AWS
    • GCP
    • OCI
    • Bare metal
    • Helm
    • Hadoop / HBase
    • MySQL · Percona XtraDB
    • Kafka · Confluent
    • Elasticsearch
    • Nginx Plus
    • RabbitMQ
    • Prometheus
    • Grafana
    • Zabbix
    • SaltStack
    • Ansible
    • Python
  2. Mar 2015 — Aug 2017

    Remote

    DevOps Engineer · Systems Administrator

    Scrapinghub

    Core DevOps engineer for a fast-growing web-scraping platform, running the clusters, databases and pipelines behind every product.

    • Operated production Mesos clusters of 100+ nodes running Zookeeper, Marathon, Consul, HAProxy and Nginx for both product and internal applications.
    • Wrote the Python automation that took the platform from manual on-prem deploys to fully automated cloud provisioning on AWS EC2, and later GCP — cutting deploy time and the number of engineers needed to run it. Introduced SaltStack for role-based configuration of the fleet.
    • MySQL DBA for a Percona XtraDB cluster, with a tested disaster-recovery plan built on several in-sync offsite replicas.
    • Built and ran a 7-broker Apache Kafka cluster, a ClickHouse cluster, and a hot/warm Elasticsearch architecture for internal logging.
    • Developed CI/CD pipelines, managed the AWS estate end to end (EC2, load balancers, Route53, CloudFront, S3, RDS, IAM, KMS), and supported developers shipping containerised applications.
    • Mesos
    • AWS
    • SaltStack
    • Ansible
    • Kafka
    • ClickHouse
    • Elasticsearch
    • Percona XtraDB
    • Docker
    • Drone CI
    • Python
  3. Apr 2007 — Feb 2015

    Montevideo · 60% remote

    Head of Information Technology

    Ikatu · Bang & Olufsen Uruguay

    Led the IT department of a multinational operation, designing and running network, telephony and server infrastructure across several countries.

    • Designed and deployed VoIP infrastructure on Asterisk across 10+ branch offices in multiple countries, plus a dedicated client-monitoring VPN network built on OpenWRT and OpenVPN.
    • Built centralised monitoring for ~70 network devices and servers with Zabbix and SMS/XMPP alerting — years before anyone called it observability.
    • Administered Debian, Ubuntu, FreeBSD and Windows estates, KVM/QEMU virtualisation, mail (Postfix, Qmail), DNS, OpenLDAP, firewalls, Cisco layer-3 switching and Juniper routing.
    • Delivered company-wide backup on Bacula, self-hosted collaboration and ticketing, and IPsec/OpenVPN connectivity between sites.
    • Asterisk
    • OpenWRT
    • OpenVPN
    • Zabbix
    • Debian
    • FreeBSD
    • KVM
    • Cisco
    • Juniper
    • Bacula
  4. Sep 2004 — Apr 2007

    Montevideo

    Systems Administrator · Assistant Professor (Gr. 1)

    Instituto Crandon · Universidad de la República

    Early career, running real infrastructure young: a 250-desktop, 20-server school network on Exchange, Active Directory and Fortinet, and at the university's nursing faculty, the institution's first firewall and its mail and web infrastructure — while teaching and supporting users.

03 / Selected work

Selected work

Four pieces of work that describe the job better than a bullet list does. Figures are rounded and internal system names generalised.

Planned and led · Zyte

500 TB of customer data, moved without anyone noticing

The platform's entire scraped-data store lived on an ageing Hadoop/HBase cluster — every customer's data, on hardware that had to go. I planned the migration, coordinated it across teams, ran it through to full production cutover and decommissioned the legacy hardware afterwards. Years later, when a stack upgrade on the successor cluster introduced a serious memory leak, I led the investigation across several squads, found the root cause and got the fix in — keeping the platform on a supported stack instead of frozen on an unsupported one.

  • Hadoop / HBase
  • Zero-downtime migration
  • Root-cause analysis
  • Cross-team lead

Designed and drove · Zyte

Mesos to Kubernetes, 140 nodes at a time

Replaced a 140-node Mesos cluster with on-premises Kubernetes, while running 100+ node managed clusters on GKE and EKS and 170+ node highly available bare-metal estates alongside it. The interesting part was never the technology — it was sequencing the change so that product teams kept shipping throughout, and upgrading a core orchestration platform that had not been touched since the day it was first deployed.

  • Kubernetes
  • Mesos
  • Helm
  • On-prem + multi-cloud

Owned end to end · Zyte

Roughly $40k a month, found and kept

A multi-year cost programme rather than a one-off cut: committed-use discounts, storage and logging optimisation, workload right-sizing, a complete exit from one cloud provider down to zero spend, and provider negotiations that expanded GPU capacity at cost-neutral spend. Around $40k in recurring monthly savings, delivered incrementally and safely, with no performance or capacity given up — plus the cost-attribution dashboards that keep it from creeping back.

  • FinOps
  • Vendor negotiation
  • Budget ownership
  • Cost dashboards

Led · Zyte

The unglamorous half: 80+ upgrades, zero disruption

Legacy work is where reliability is actually won. Over 80 operating-system upgrades and legacy decommissions with zero user disruption; a main database cluster moved onto new hardware without a service break; the container registry behind every internal image rebuilt end to end — hardware, OS, cache layer and cloud components — with no customer impact; the web load-balancer tier standardised across data centres; IPv6 enabled; CI migrated off a sunset build system; and the monitoring stack consolidated and put behind proper backups and version control.

  • Reliability
  • Legacy modernisation
  • Nginx Plus
  • IPv6
  • CI/CD

04 / Wireless

Wireless & side projects

Certified Ubiquiti AirMax engineer since 2012. I design and build long-distance point-to-point and point-to-multipoint links over the unlicensed 2.4 and 5 GHz bands — for myself, for neighbours, and commercially.

Fibre-grade internet, 1.5 km through the air

I moved three kilometres outside a small town in Uruguay and discovered no ISP could deliver usable internet there. So I engineered the link myself: a 5 GHz point-to-point shot from the nearest fibre coverage to my house, Fresnel-zone maths included, on NanoBeam M5 radios with OpenWRT routing and a UPS-backed watertight enclosure mounted on a water tank. It delivered around 90 Mbps over the air for roughly $274 in parts, and later ended up shared with the neighbours. Zyte published the full write-up on their engineering blog.

Read the full story on the Zyte blog

  • 5 GHz PtP
  • Ubiquiti NanoBeam M5
  • OpenWRT
  • Link budget & Fresnel-zone design

Commercial & personal PtP / PtMP deployments

Point-to-point and point-to-multipoint networks built over unlicensed spectrum for businesses and for rural connectivity: site surveys, link planning, tower and mast mounting, alignment, and the routing layer behind them. Hardware across the Ubiquiti range — Rocket Prism 5AC, LiteBeam, NanoBeam, NanoStation, UAP-AC-LR — with Mikrotik doing the routing.

  • Rocket Prism 5AC
  • LiteBeam · NanoBeam · NanoStation
  • UAP-AC-LR
  • Mikrotik
  • 2.4 & 5 GHz

05 / Skills

Skills

Cloud & platforms

  • Kubernetes (GKE, EKS, on-prem)
  • AWS
  • Google Cloud
  • Oracle Cloud
  • Bare metal
  • Mesos
  • Helm
  • Docker

Data & streaming

  • Hadoop / HBase
  • MySQL · Percona XtraDB
  • Apache Kafka · Confluent
  • Elasticsearch
  • ClickHouse
  • Ceph
  • RabbitMQ
  • Zookeeper

Automation & delivery

  • SaltStack
  • Ansible
  • Python
  • Shell scripting
  • Jenkins
  • CircleCI
  • CI/CD design
  • Infrastructure as code

Observability & reliability

  • Prometheus
  • Grafana
  • Zabbix
  • Elastic stack
  • Percona PMM
  • Incident response
  • Post-mortems
  • Capacity planning

Networking & wireless

  • Nginx · Nginx Plus
  • HAProxy
  • IPv6
  • Ubiquiti AirMax (certified)
  • Mikrotik
  • OpenWRT
  • OpenVPN · IPsec
  • Asterisk VoIP

Leadership & operations

  • Team building & hiring
  • Coaching & career development
  • Budget ownership
  • Vendor negotiation
  • ISO 27001
  • Security operations
  • Executive communication
  • Remote team leadership

Credentials

Certifications

  • Ubiquiti AirMax Certified Engineer Ubiquiti Networks · 2012
  • Introduction to .NET platform technologies Microsoft · 2011

Education

  • Computer Science, Engineering programme Universidad de la República, Uruguay · 2015 · 400 of 450 credits
  • Computer Analyst Universidad de la República, Uruguay · 2010
  • First Certificate in English University of Cambridge · 1998

Languages

  • Spanish Native
  • English Bilingual proficiency
  • Portuguese Basic

06 / Contact

Get in touch

Open to conversations about infrastructure leadership, platform engineering and reliability. Always happy to talk about long-distance wireless links, whether or not there is a job attached.