Cybersecurity leader with over 14 years of IT experience, including 7+ years specialising in Information Security, Security Operations and Cybersecurity Consulting. I combine deep technical expertise with a strategic mindset to help organisations strengthen their security posture, reduce risk and protect business continuity.
Based in Dublin, Ireland, I lead cybersecurity initiatives across enterprise and multi-tenant environments, aligning security strategy with business objectives so that technical decisions translate into measurable value for clients and stakeholders. My expertise spans Security Operations, Incident Response, Vulnerability Management, Penetration Testing, Threat Detection & Response, Security Architecture, EDR/XDR and Cybersecurity Strategy — applied across Private, Public and Hybrid Cloud, with alignment to NIST CSF, ISO 27001 and MITRE ATT&CK.
Throughout my career I have led programmes spanning SOC development, EDR/XDR deployments, vulnerability remediation, offensive security engagements and cloud security initiatives, translating complex technical findings into clear, actionable insight for both engineering teams and executive stakeholders — ensuring security investments deliver tangible business outcomes.
| Role | Lead Cybersecurity Engineer |
| Focus | Purple Team · Offensive Security · Detection & Response |
| Location | Dublin, Ireland |
| Languages | Portuguese (native) · English (professional) · Spanish (basic) |
| Frameworks | MITRE ATT&CK · OWASP · NIST CSF · ISO 27001 |
| Focus now | LLM application security · offensive AI |
| Credentials | CEH · CCFA · CLLMSP |
FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers
An FTC spokesperson confirmed the investigation but declined further comment. The post FTC is Investigating OpenAI and Anthropic Over Possible risks…
SecurityWeek
US sanctions 10 over ATM malware scheme tied to Tren de Aragua
Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the…
The Record
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
Dark Reading
Trump, Tech Giants Strike Voluntary AI Safety Accord
The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety.
Dark Reading
Russian state hackers use new RedFlick technique to push malware
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse…
BleepingComputer
Automakers routinely share personally identifiable connected-car data with third parties, report says
A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem.
The Record
DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day…
BleepingComputer
After reports on suicide deaths, Pentagon puts Cyber Command on notice
An August 31 memo obtained by Recorded Future News shows that the Pentagon's assistant secretary for cyber policy made specific demands of U.S. Cyber…
The Record
Auto-updated every 6 hours from The Hacker News, BleepingComputer, Krebs on Security, Dark Reading, SecurityWeek, The Record and CISA advisories. Headlines link to the original source.
| Area | Focus |
|---|---|
| Offensive Security & Pentest | Web application, network and infrastructure penetration testing; manual exploitation; controlled threat simulation |
| Purple Teaming | Bridging red and blue — validating detections and hardening defences against real attack techniques |
| Vulnerability & Risk Management | Qualys VMDR/WAS, Nessus, OpenVAS; asset discovery, custom QQL, risk analysis and remediation planning |
| Threat Detection & Response | SOC operations, threat hunting, incident response, EDR/XDR/MDR (CrowdStrike Falcon), threat intelligence |
| Security Operations | SIEM engineering (FortiSIEM), log correlation, monitoring use cases, dashboards, SOC development |
| Network & Perimeter | Firewalls (FortiGate), WAF, IPS/IDS, VPN, web filtering; FortiManager / FortiAnalyzer |
| Identity & Access | IAM, access control, Active Directory, Windows Server |
| Cloud Security | AWS, Azure and GCP across Private, Public and Hybrid Cloud |
| Governance & Compliance | ISO 27001, ISO 27032, NIST CSF, MITRE ATT&CK, OWASP; audits and policy |
| Awareness & Reporting | Security awareness (KnowBE4); technical, executive and analytical reporting |
Engagement approach: Reconnaissance → Assessment → Exploitation → Post-exploitation → Detection review (purple-team) → Technical & executive reporting
I treat security as a business function: every technical decision is measured by the value it creates, the risk it removes and the efficiency it adds.
- Translate complex technical findings into clear, executive-level insight that shows where security investment delivers the most return.
- Build and mature Security Operations Centre (SOC) capability, giving the business continuous visibility and faster detection.
- Lead offensive security engagements (penetration testing) that surface real weaknesses before attackers can exploit them.
- Support pre-sales and customer workshops, positioning security as an enabler of new business rather than a blocker.
- Mentor security teams, compounding capability across the whole organisation.
- Run risk-based vulnerability management — prioritising remediation by real exploitability and business impact, not raw scores.
- Lead threat detection, incident response and threat-intelligence analysis to contain issues quickly and limit impact.
- Review and approve security architectures before production, catching risk at design time.
- Enforce identity and access controls and least-privilege access across environments.
- Align delivery to NIST CSF and ISO 27001, sustaining certifications and audit readiness.
- Engineer SIEM correlation rules, use cases and dashboards (FortiSIEM) that cut alert fatigue and speed up triage.
- Standardise monitoring, detection and remediation into repeatable processes and playbooks.
- Centralise and consolidate tooling (EDR/XDR, centralised firewall and log management) to reduce operational overhead.
- Deliver technical, executive and analytical reporting that keeps stakeholders aligned and reduces rework.
Tip: add measurable outcomes as you quantify them — reduction in mean time to detect/respond, vulnerabilities remediated, audit findings closed. Real numbers make this section land hardest.
March 2019 – Present · 7+ years · Managed security and cloud services provider
Lead Cybersecurity Engineer — March 2026 – Present · Dublin, Ireland (Remote)
- Lead technical cybersecurity initiatives across managed security and cloud environments, supporting Private, Public and Hybrid Cloud customers
- Lead penetration testing engagements across infrastructure, network and web application environments
- Design, implement and manage EDR/XDR solutions, including CrowdStrike Falcon
- Provide Level 3 technical support and escalation for security incidents and complex projects
- Lead incident response investigations and threat analysis activities
- Perform vulnerability assessments, risk analysis and remediation planning; support the design of SOC capabilities
- Review and approve security architectures for customer projects
- Deliver executive and technical security reports and provide technical mentoring to security teams
- Ensure alignment with NIST CSF, MITRE ATT&CK, OWASP and ISO 27001
Senior Cybersecurity Analyst — September 2024 – March 2026 · São Paulo, Brazil (Hybrid)
- Led security operations, threat detection and vulnerability management across managed customer environments
- Conducted Proof of Concepts and technical evaluations of cybersecurity solutions; managed EDR, MDR and XDR platforms
- Designed and deployed firewalls, IDS/IPS, WAF and DDoS protection solutions
- Built SIEM use cases, correlation rules and monitoring dashboards
- Investigated security incidents, coordinated response actions and supported ISO 27001 governance initiatives
Cybersecurity Engineer — June 2021 – September 2024 · Brazil (Hybrid)
- Designed and implemented secure network and cybersecurity architectures, from project initiation through production deployment
- Deployed and managed firewalls, IDS/IPS, WAF, Web Filtering and Application Control solutions
- Implemented centralised log management and SIEM integrations
- Developed and enforced security policies using FortiManager
- Supported pre-sales teams in customer workshops and technical demonstrations
Earlier roles at Claranet
Information Security Analyst — June 2020 – July 2021 · Brazil (On-site)
- Supported cybersecurity operations, vulnerability management and customer security projects within managed service environments
- Monitored and investigated security alerts; assisted with vulnerability assessments and remediation activities
Junior Information Security Analyst — March 2019 – June 2020 · Barueri, Brazil (On-site)
- Monitored security events and alerts, supported vulnerability scanning and participated in incident response processes
July 2015 – March 2019 · 3 years 9 months
Network & Telecommunications Engineer · Technical Support Specialist
Network & Telecommunications Engineer — April 2017 – March 2019 · Brazil
- Designed, deployed and supported telecommunications, networking and infrastructure solutions for enterprise customers
- Installed, configured and managed enterprise network infrastructure including routers, switches and firewalls; supported VPN, VLAN, NAT and routing services
- Supported the implementation of information security controls and secure network architectures; participated in network incident investigation and service restoration
Technical Support Specialist — July 2015 – April 2017 · Brazil
- Provided first-line technical support for telecommunications and network services
- Supported VoIP deployments and infrastructure troubleshooting
Platforms and tools I operate in production and assessment environments.
| Domain | Technologies |
|---|---|
| Offensive & Assessment | Nmap, Burp Suite, Metasploit, Kali Linux, Qualys VMDR / WAS, OWASP methodology |
| Detection & Response | CrowdStrike Falcon (RTR), FortiEDR, FortiSIEM |
| Network & Perimeter | FortiGate, FortiManager, IDS/IPS, Web Filtering, Application Control, Cloudflare (WAF/DDoS) |
| Identity & Cloud | Keycloak, AWS, Private / Public / Hybrid Cloud |
| Automation & Scripting | Python, PowerShell, Bash, Docker |
Open resources I build and maintain.
| Repository | Description | Stack |
|---|---|---|
| Cyber Pulse | Auto-updating cybersecurity news portal, refreshed every 3 hours. Live. | Python · HTML · Actions |
| Arsenal | Interactive catalog of 366 security tools plus my own operational scripts. Live. | Bash · Python · PowerShell · HTML |
| Security Knowledge Base | 50 certification and framework references — what each is, what it validates, key concepts and a mind map. | Docs · Mermaid |
Certifications
Education
- Postgraduate Degree, Cybersecurity — Instituto Daryus (2023 – 2024)
- Bachelor's Degree, Information Security Management — UNINOVE (2018 – 2021)