I am an independent Information Technology Consultant and Security Engineer specializing in Cloud Infrastructure, DevSecOps, and Information Security. I design, automate, and secure highly scalable cloud environments using Infrastructure as Code (IaC).
Through my consulting services, I provide specialized engineering, compliance automation, and architectural security solutions to global technology companies and startups under a remote Business-to-Business (B2B) engagement model.
- Cloud Security & Compliance: Designing and enforcing automated cloud security controls, Policy-as-Code (PaC), and Compliance-as-Code to align cloud workloads with international standards (ISO 27001, LGPD/GDPR, NIST CSF, CIS Controls, SOC 2, WebTrust, BACEN, and Open Finance).
- DevSecOps & Security Automation: Building hardened automated CI/CD pipelines incorporating federated authentication (OIDC), Shift-Left security mechanisms (SAST, DAST, SCA), and Cloud Security Posture Management (CSPM).
- Infrastructure as Code (IaC): Developing dry, decoupled, secure, and modular cloud architectures using Terraform to prevent manual drift and ensure high availability.
Note: All business operations, client acquisitions, and technical projects are executed under my professional identity as a single-member consultant. This profile and its associated repositories serve as my active verification hub and business portfolio.
- Cloud & Infrastructure: AWS, Cloud Security & Governance, Terraform (IaC), Kubernetes & Container Security, Hybrid Infrastructures, Enterprise Networking (Cisco, Juniper, Fortigate, Dell, HP).
- DevSecOps & Automation: CI/CD Pipelines (GitHub Actions), OIDC Identity Federation, Policy-as-Code (OPA/Rego), Vulnerability Management, SAST, DAST, SCA, CSPM (Prowler, Trivy, Ansible).
- Identity, Access & Cryptography: PKI, ICP-Brasil (maximum-trust secure vaults), IAM, RBAC/ABAC, Hardware Security Modules (HSM), Identity Federation & SSO, Privileged Access Management (PAM), OpenSSL (PKI APIs, cryptographic automation, TLS/SSL hardening).
- GRC & Compliance: ISO/IEC 27001, LGPD/GDPR, NIST CSF, CIS Controls, SOC 2, WebTrust Audits, Risk Management.
- Network & Systems Security: Linux Administration & Hardening, WAF, IDS/IPS, DNS, NTP, VLANs, Routing Policies, Traffic Filtering & Deep Packet Inspection (DPI).
- Programming & Scripting: Python, Bash, PHP, C++, SQL.
- AWS Certified Solutions Architect โ Associate (SAA) โ Issued Jun 2026
- HashiCorp Certified: Terraform Associate โ Issued Feb 2026
- GitHub Foundations Certification โ Issued Feb 2026
- AWS Certified Cloud Practitioner (CCP) โ Issued Jan 2026
- EXIN: Privacy and Data Protection Essentials based on LGPD โ Issued Jun 2024
- EXIN: ISO 27001 Foundation โ Issued Nov 2023
- Linux Professional Institute: LPIC-1 Certification โ Issued Mar 2017
An implementation of Post-Quantum Cryptography (PQC) based on crypto-agility principles, complete with telemetry and aligned with NIST recommendations.
- Tech Stack: C++, OpenSSL (EVP API), liboqs, Python, OPA/Rego, AWS, Telemetry, GitHub Actions.
- Key Deliverable: Integrates and evaluates classical and post-quantum cryptographic algorithms in real-time to guarantee seamless transition capabilities without service disruption.
๐ก๏ธ Cloud Security Automation Lab
A fully automated AWS environment leveraging Infrastructure as Code (IaC) and Policy-as-Code (PaC) aligned directly with CIS Controls, NIST CSF, and ISO 27001.
- Tech Stack: AWS, Terraform, OPA/Rego, Ansible, Trivy, Prowler, GitHub Actions.
- Key Deliverable: Employs OIDC-based federated authentication, Shift-Left security (SAST/SCA), automatic vulnerability scanning, IAM least-privilege enforcement, and real-time CSPM assessments.
โ๏ธ Cloud Compliance Pipeline
A highly resilient pipeline focusing on automated cloud governance, enforcing Compliance-as-Code framework mappings.
- Tech Stack: AWS, Terraform, OPA/Rego, Python, GitHub Actions.
- Key Deliverable: Implements multi-framework security validation (GDPR, LGPD, NIST CSF, ISO 27001, PCI DSS, SOC 2, BACEN, Open Finance) using decoupled control catalogs adhering strictly to DRY principles.
- 100% Audit Approval Rate: Commanded and successfully executed annual audits including ICP-Brasil (Brazilian PKI), WebTrust, ABNT, and ISO 27001 consecutively over a 9-year span.
- 80% Time Reduction Portal: Built a custom corporate portal that eliminated inter-team manual dependency, streamlining and securing internal electronic evidence delivery.
- Biometric Cluster Engineering: Spearheaded a biometric verification and high-availability database cluster managing over 10 million records with rigorous compliance controls.
- Data Center Vault Room Governance: Served as the physical and logical security lead for a mission-critical, maximum-trust datacenter environment at a major Certificate Authority.
- 3 Major Infrastructure Migrations: Led full migration architectures from legacy on-premises datacenters to AWS/OCI using the 6Rs framework, with high resilience and minimal downtime.
- Coordinated and developed technical DevSecOps and cloud security teams in heavily regulated environments.
- Improved organizational security posture, automated compliance controls, and led risk mitigation strategies across hybrid environments.
- Advanced management of Hardware Security Modules (HSM), PAM, and cryptographic workflows.
- Acted as a strategic bridge interfacing between technical engineering, executive leadership (C-Suite), and external auditors.
- Maintained production Kubernetes clusters, AWS/OCI infrastructure, and advanced Linux OS hardening.
- Engineered hybrid-cloud network topologies using hardened firewalls, VPNs, and segmented routing.
- Automated secure sensitive data transfers to government authorities using Python, Bash, PHP, and SQL.
- M.Sc. in Computer Engineering (Professional Master's) โ IPT (Instituto de Pesquisas Tecnolรณgicas do Estado de SP) | 2017 โ 2020
- Research Focus: Security Engineering, IoT Cryptography, and PKI.
- Thesis Highlight: Developed a lightweight hierarchical authentication and secure key agreement model (C++ / OpenSSL) optimized for IoT environments. It achieved 6x higher performance in key generation compared to ECC-based approaches on Raspberry Pi.
- Postgraduate Specialization in Computer Networks & System Security โ UFG (Universidade Federal de Goiรกs) | 2015 โ 2017
- Research Highlight: Engineered hybrid-identity encryption using challenge-response, nonces, and one-time pads.
- Technology Degree in Computer Networks โ FATESG | 2010 โ 2013

