Skip to content
View RochaCrypt's full-sized avatar
💭
Let’s go!
💭
Let’s go!

Block or report RochaCrypt

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
RochaCrypt/README.md

Summary

Cybersecurity leader with over 14 years of IT experience, including 7+ years specialising in Information Security, Security Operations and Cybersecurity Consulting. I combine deep technical expertise with a strategic mindset to help organisations strengthen their security posture, reduce risk and protect business continuity.

Based in Dublin, Ireland, I lead cybersecurity initiatives across enterprise and multi-tenant environments, aligning security strategy with business objectives so that technical decisions translate into measurable value for clients and stakeholders. My expertise spans Security Operations, Incident Response, Vulnerability Management, Penetration Testing, Threat Detection & Response, Security Architecture, EDR/XDR and Cybersecurity Strategy — applied across Private, Public and Hybrid Cloud, with alignment to NIST CSF, ISO 27001 and MITRE ATT&CK.

Throughout my career I have led programmes spanning SOC development, EDR/XDR deployments, vulnerability remediation, offensive security engagements and cloud security initiatives, translating complex technical findings into clear, actionable insight for both engineering teams and executive stakeholders — ensuring security investments deliver tangible business outcomes.

Role Lead Cybersecurity Engineer
Focus Purple Team · Offensive Security · Detection & Response
Location Dublin, Ireland
Languages Portuguese (native) · English (professional) · Spanish (basic)
Frameworks MITRE ATT&CK · OWASP · NIST CSF · ISO 27001
Focus now LLM application security · offensive AI
Credentials CEH · CCFA · CLLMSP

Latest in Cybersecurity

Cyber Pulse

FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers
An FTC spokesperson confirmed the investigation but declined further comment. The post FTC is Investigating OpenAI and Anthropic Over Possible risks…
SecurityWeek

US sanctions 10 over ATM malware scheme tied to Tren de Aragua
Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the…
The Record

Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
Dark Reading

Trump, Tech Giants Strike Voluntary AI Safety Accord
The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety.
Dark Reading

Russian state hackers use new RedFlick technique to push malware
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse…
BleepingComputer

Automakers routinely share personally identifiable connected-car data with third parties, report says
A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem.
The Record

DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day…
BleepingComputer

After reports on suicide deaths, Pentagon puts Cyber Command on notice
An August 31 memo obtained by Recorded Future News shows that the Pentagon's assistant secretary for cyber policy made specific demands of U.S. Cyber…
The Record

Auto-updated every 6 hours from The Hacker News, BleepingComputer, Krebs on Security, Dark Reading, SecurityWeek, The Record and CISA advisories. Headlines link to the original source.


Core Expertise

Area Focus
Offensive Security & Pentest Web application, network and infrastructure penetration testing; manual exploitation; controlled threat simulation
Purple Teaming Bridging red and blue — validating detections and hardening defences against real attack techniques
Vulnerability & Risk Management Qualys VMDR/WAS, Nessus, OpenVAS; asset discovery, custom QQL, risk analysis and remediation planning
Threat Detection & Response SOC operations, threat hunting, incident response, EDR/XDR/MDR (CrowdStrike Falcon), threat intelligence
Security Operations SIEM engineering (FortiSIEM), log correlation, monitoring use cases, dashboards, SOC development
Network & Perimeter Firewalls (FortiGate), WAF, IPS/IDS, VPN, web filtering; FortiManager / FortiAnalyzer
Identity & Access IAM, access control, Active Directory, Windows Server
Cloud Security AWS, Azure and GCP across Private, Public and Hybrid Cloud
Governance & Compliance ISO 27001, ISO 27032, NIST CSF, MITRE ATT&CK, OWASP; audits and policy
Awareness & Reporting Security awareness (KnowBE4); technical, executive and analytical reporting

Engagement approach: Reconnaissance → Assessment → Exploitation → Post-exploitation → Detection review (purple-team) → Technical & executive reporting


How I Deliver Value

I treat security as a business function: every technical decision is measured by the value it creates, the risk it removes and the efficiency it adds.

Business value

  • Translate complex technical findings into clear, executive-level insight that shows where security investment delivers the most return.
  • Build and mature Security Operations Centre (SOC) capability, giving the business continuous visibility and faster detection.
  • Lead offensive security engagements (penetration testing) that surface real weaknesses before attackers can exploit them.
  • Support pre-sales and customer workshops, positioning security as an enabler of new business rather than a blocker.
  • Mentor security teams, compounding capability across the whole organisation.

Risk management

  • Run risk-based vulnerability management — prioritising remediation by real exploitability and business impact, not raw scores.
  • Lead threat detection, incident response and threat-intelligence analysis to contain issues quickly and limit impact.
  • Review and approve security architectures before production, catching risk at design time.
  • Enforce identity and access controls and least-privilege access across environments.
  • Align delivery to NIST CSF and ISO 27001, sustaining certifications and audit readiness.

Operational efficiency

  • Engineer SIEM correlation rules, use cases and dashboards (FortiSIEM) that cut alert fatigue and speed up triage.
  • Standardise monitoring, detection and remediation into repeatable processes and playbooks.
  • Centralise and consolidate tooling (EDR/XDR, centralised firewall and log management) to reduce operational overhead.
  • Deliver technical, executive and analytical reporting that keeps stakeholders aligned and reduces rework.

Tip: add measurable outcomes as you quantify them — reduction in mean time to detect/respond, vulnerabilities remediated, audit findings closed. Real numbers make this section land hardest.


Experience

Claranet

March 2019 – Present · 7+ years · Managed security and cloud services provider

Lead Cybersecurity Engineer — March 2026 – Present · Dublin, Ireland (Remote)

  • Lead technical cybersecurity initiatives across managed security and cloud environments, supporting Private, Public and Hybrid Cloud customers
  • Lead penetration testing engagements across infrastructure, network and web application environments
  • Design, implement and manage EDR/XDR solutions, including CrowdStrike Falcon
  • Provide Level 3 technical support and escalation for security incidents and complex projects
  • Lead incident response investigations and threat analysis activities
  • Perform vulnerability assessments, risk analysis and remediation planning; support the design of SOC capabilities
  • Review and approve security architectures for customer projects
  • Deliver executive and technical security reports and provide technical mentoring to security teams
  • Ensure alignment with NIST CSF, MITRE ATT&CK, OWASP and ISO 27001

Senior Cybersecurity Analyst — September 2024 – March 2026 · São Paulo, Brazil (Hybrid)

  • Led security operations, threat detection and vulnerability management across managed customer environments
  • Conducted Proof of Concepts and technical evaluations of cybersecurity solutions; managed EDR, MDR and XDR platforms
  • Designed and deployed firewalls, IDS/IPS, WAF and DDoS protection solutions
  • Built SIEM use cases, correlation rules and monitoring dashboards
  • Investigated security incidents, coordinated response actions and supported ISO 27001 governance initiatives

Cybersecurity Engineer — June 2021 – September 2024 · Brazil (Hybrid)

  • Designed and implemented secure network and cybersecurity architectures, from project initiation through production deployment
  • Deployed and managed firewalls, IDS/IPS, WAF, Web Filtering and Application Control solutions
  • Implemented centralised log management and SIEM integrations
  • Developed and enforced security policies using FortiManager
  • Supported pre-sales teams in customer workshops and technical demonstrations
Earlier roles at Claranet

Information Security Analyst — June 2020 – July 2021 · Brazil (On-site)

  • Supported cybersecurity operations, vulnerability management and customer security projects within managed service environments
  • Monitored and investigated security alerts; assisted with vulnerability assessments and remediation activities

Junior Information Security Analyst — March 2019 – June 2020 · Barueri, Brazil (On-site)

  • Monitored security events and alerts, supported vulnerability scanning and participated in incident response processes

Amistad Networks

July 2015 – March 2019 · 3 years 9 months

Network & Telecommunications Engineer · Technical Support Specialist

Network & Telecommunications Engineer — April 2017 – March 2019 · Brazil

  • Designed, deployed and supported telecommunications, networking and infrastructure solutions for enterprise customers
  • Installed, configured and managed enterprise network infrastructure including routers, switches and firewalls; supported VPN, VLAN, NAT and routing services
  • Supported the implementation of information security controls and secure network architectures; participated in network incident investigation and service restoration

Technical Support Specialist — July 2015 – April 2017 · Brazil

  • Provided first-line technical support for telecommunications and network services
  • Supported VoIP deployments and infrastructure troubleshooting

Technologies

Platforms and tools I operate in production and assessment environments.

Domain Technologies
Offensive & Assessment Nmap, Burp Suite, Metasploit, Kali Linux, Qualys VMDR / WAS, OWASP methodology
Detection & Response CrowdStrike Falcon (RTR), FortiEDR, FortiSIEM
Network & Perimeter FortiGate, FortiManager, IDS/IPS, Web Filtering, Application Control, Cloudflare (WAF/DDoS)
Identity & Cloud Keycloak, AWS, Private / Public / Hybrid Cloud
Automation & Scripting Python, PowerShell, Bash, Docker

Projects and Knowledge Base

Open resources I build and maintain.

Repository Description Stack
Cyber Pulse Auto-updating cybersecurity news portal, refreshed every 3 hours. Live. Python · HTML · Actions
Arsenal Interactive catalog of 366 security tools plus my own operational scripts. Live. Bash · Python · PowerShell · HTML
Security Knowledge Base 50 certification and framework references — what each is, what it validates, key concepts and a mind map. Docs · Mermaid

Certifications and Education

Certifications

Education

  • Postgraduate Degree, Cybersecurity — Instituto Daryus (2023 – 2024)
  • Bachelor's Degree, Information Security Management — UNINOVE (2018 – 2021)

Activity

Top languages Contribution streak



Contribution calendar Contribution graph

All techniques and tooling are used exclusively in authorised engagements.

Popular repositories Loading

  1. AD_Miner AD_Miner Public

    Forked from AD-Security/AD_Miner

    AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses

    JavaScript

  2. rengine rengine Public

    Forked from yogeshojha/rengine

    .

    Python

  3. lynis lynis Public

    Forked from CISOfy/lynis

    Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

    Shell

  4. faraday faraday Public

    Forked from infobyte/faraday

    Open Source Vulnerability Management Platform

    Python

  5. rapidscan rapidscan Public

    Forked from skavngr/rapidscan

    🆕 The Multi-Tool Web Vulnerability Scanner.

    Python

  6. kics kics Public

    Forked from Checkmarx/kics

    Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

    Open Policy Agent