Skip to content
View tmmuniz's full-sized avatar
  • Sรฃo Paulo, Brazil
  • 02:54 (UTC -03:00)
  • LinkedIn in/tmmuniz

Block or report tmmuniz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
tmmuniz/README.md

Taynan Mina Muniz

Information Security Specialist (MSc) | Cloud Security Engineer & DevSecOps

LinkedIn GitHub Portfolio


๐Ÿ’ผ Business & Professional Overview (B2B Consulting)

I am an independent Information Technology Consultant and Security Engineer specializing in Cloud Infrastructure, DevSecOps, and Information Security. I design, automate, and secure highly scalable cloud environments using Infrastructure as Code (IaC).

Through my consulting services, I provide specialized engineering, compliance automation, and architectural security solutions to global technology companies and startups under a remote Business-to-Business (B2B) engagement model.

๐Ÿ› ๏ธ Core Services Provided

  • Cloud Security & Compliance: Designing and enforcing automated cloud security controls, Policy-as-Code (PaC), and Compliance-as-Code to align cloud workloads with international standards (ISO 27001, LGPD/GDPR, NIST CSF, CIS Controls, SOC 2, WebTrust, BACEN, and Open Finance).
  • DevSecOps & Security Automation: Building hardened automated CI/CD pipelines incorporating federated authentication (OIDC), Shift-Left security mechanisms (SAST, DAST, SCA), and Cloud Security Posture Management (CSPM).
  • Infrastructure as Code (IaC): Developing dry, decoupled, secure, and modular cloud architectures using Terraform to prevent manual drift and ensure high availability.

Note: All business operations, client acquisitions, and technical projects are executed under my professional identity as a single-member consultant. This profile and its associated repositories serve as my active verification hub and business portfolio.


๐Ÿ› ๏ธ Technical Expertise & Skills

  • Cloud & Infrastructure: AWS, Cloud Security & Governance, Terraform (IaC), Kubernetes & Container Security, Hybrid Infrastructures, Enterprise Networking (Cisco, Juniper, Fortigate, Dell, HP).
  • DevSecOps & Automation: CI/CD Pipelines (GitHub Actions), OIDC Identity Federation, Policy-as-Code (OPA/Rego), Vulnerability Management, SAST, DAST, SCA, CSPM (Prowler, Trivy, Ansible).
  • Identity, Access & Cryptography: PKI, ICP-Brasil (maximum-trust secure vaults), IAM, RBAC/ABAC, Hardware Security Modules (HSM), Identity Federation & SSO, Privileged Access Management (PAM), OpenSSL (PKI APIs, cryptographic automation, TLS/SSL hardening).
  • GRC & Compliance: ISO/IEC 27001, LGPD/GDPR, NIST CSF, CIS Controls, SOC 2, WebTrust Audits, Risk Management.
  • Network & Systems Security: Linux Administration & Hardening, WAF, IDS/IPS, DNS, NTP, VLANs, Routing Policies, Traffic Filtering & Deep Packet Inspection (DPI).
  • Programming & Scripting: Python, Bash, PHP, C++, SQL.

๐ŸŽ–๏ธ Professional Certifications

  • AWS Certified Solutions Architect โ€“ Associate (SAA) โ€” Issued Jun 2026
  • HashiCorp Certified: Terraform Associate โ€” Issued Feb 2026
  • GitHub Foundations Certification โ€” Issued Feb 2026
  • AWS Certified Cloud Practitioner (CCP) โ€” Issued Jan 2026
  • EXIN: Privacy and Data Protection Essentials based on LGPD โ€” Issued Jun 2024
  • EXIN: ISO 27001 Foundation โ€” Issued Nov 2023
  • Linux Professional Institute: LPIC-1 Certification โ€” Issued Mar 2017

๐Ÿ“‚ Active Security Portfolio & Projects

An implementation of Post-Quantum Cryptography (PQC) based on crypto-agility principles, complete with telemetry and aligned with NIST recommendations.

  • Tech Stack: C++, OpenSSL (EVP API), liboqs, Python, OPA/Rego, AWS, Telemetry, GitHub Actions.
  • Key Deliverable: Integrates and evaluates classical and post-quantum cryptographic algorithms in real-time to guarantee seamless transition capabilities without service disruption.

A fully automated AWS environment leveraging Infrastructure as Code (IaC) and Policy-as-Code (PaC) aligned directly with CIS Controls, NIST CSF, and ISO 27001.

  • Tech Stack: AWS, Terraform, OPA/Rego, Ansible, Trivy, Prowler, GitHub Actions.
  • Key Deliverable: Employs OIDC-based federated authentication, Shift-Left security (SAST/SCA), automatic vulnerability scanning, IAM least-privilege enforcement, and real-time CSPM assessments.

A highly resilient pipeline focusing on automated cloud governance, enforcing Compliance-as-Code framework mappings.

  • Tech Stack: AWS, Terraform, OPA/Rego, Python, GitHub Actions.
  • Key Deliverable: Implements multi-framework security validation (GDPR, LGPD, NIST CSF, ISO 27001, PCI DSS, SOC 2, BACEN, Open Finance) using decoupled control catalogs adhering strictly to DRY principles.

๐Ÿ“ˆ Executive & Technical Achievements

  • 100% Audit Approval Rate: Commanded and successfully executed annual audits including ICP-Brasil (Brazilian PKI), WebTrust, ABNT, and ISO 27001 consecutively over a 9-year span.
  • 80% Time Reduction Portal: Built a custom corporate portal that eliminated inter-team manual dependency, streamlining and securing internal electronic evidence delivery.
  • Biometric Cluster Engineering: Spearheaded a biometric verification and high-availability database cluster managing over 10 million records with rigorous compliance controls.
  • Data Center Vault Room Governance: Served as the physical and logical security lead for a mission-critical, maximum-trust datacenter environment at a major Certificate Authority.
  • 3 Major Infrastructure Migrations: Led full migration architectures from legacy on-premises datacenters to AWS/OCI using the 6Rs framework, with high resilience and minimal downtime.

๐Ÿ’ผ Professional Experience

Soluti Digital โ€“ Certification Authority (ICP-Brasil)

Information Security Manager (Feb 2022 โ€“ Jan 2026)

  • Coordinated and developed technical DevSecOps and cloud security teams in heavily regulated environments.
  • Improved organizational security posture, automated compliance controls, and led risk mitigation strategies across hybrid environments.
  • Advanced management of Hardware Security Modules (HSM), PAM, and cryptographic workflows.
  • Acted as a strategic bridge interfacing between technical engineering, executive leadership (C-Suite), and external auditors.

Infrastructure Analyst (Nov 2015 โ€“ Jan 2022)

  • Maintained production Kubernetes clusters, AWS/OCI infrastructure, and advanced Linux OS hardening.
  • Engineered hybrid-cloud network topologies using hardened firewalls, VPNs, and segmented routing.
  • Automated secure sensitive data transfers to government authorities using Python, Bash, PHP, and SQL.

๐ŸŽ“ Education & Research

  • M.Sc. in Computer Engineering (Professional Master's) โ€” IPT (Instituto de Pesquisas Tecnolรณgicas do Estado de SP) | 2017 โ€“ 2020
    • Research Focus: Security Engineering, IoT Cryptography, and PKI.
    • Thesis Highlight: Developed a lightweight hierarchical authentication and secure key agreement model (C++ / OpenSSL) optimized for IoT environments. It achieved 6x higher performance in key generation compared to ECC-based approaches on Raspberry Pi.
  • Postgraduate Specialization in Computer Networks & System Security โ€” UFG (Universidade Federal de Goiรกs) | 2015 โ€“ 2017
    • Research Highlight: Engineered hybrid-identity encryption using challenge-response, nonces, and one-time pads.
  • Technology Degree in Computer Networks โ€” FATESG | 2010 โ€“ 2013

Pinned Loading

  1. cloud-security-automation cloud-security-automation Public

    Fully automated cloud security environment with IaC, policy-as-code, CSPM and DevSecOps CI/CD pipelines using Terraform, OPA/Rego, Trivy, Ansible e Prowler.

    HCL

  2. cloud-compliance-pipeline cloud-compliance-pipeline Public

    Cloud Security Compliance Pipeline for AWS with automated multi-framework governance, Compliance-as-Code, Policy-as-Code and audit reporting using Python, Terraform, OPA/Rego and GitHub Actions.

    Python

  3. pqc-tls-agility-telemetry pqc-tls-agility-telemetry Public

    An implementation of Post-Quantum Cryptography (PQC) based on the principles of crypto-agility, combined with telemetry capabilities and aligned with NIST standards and recommendations.

    Python