99.9%
Sustained uptime
Global e-commerce (Brazil, US, EU and Australia) on Linux and Nginx, with zero security breaches.
Available full-time or on contract · Remote
I bring security into the pipeline and the server without slowing delivery, and I back it with numbers: 99.9% uptime, zero breaches and −25% technical exposure. I show results, I don't promise them.
Measurable wins from real projects: every number came out of a production system, not a slide.
99.9%
Global e-commerce (Brazil, US, EU and Australia) on Linux and Nginx, with zero security breaches.
+30%
Alert fidelity in the SIEM/SOAR over six months, tuning custom detection rules.
−25%
Vulnerability management with Nessus and Nmap and remediation prioritised by ISO 27001 risk.
−40%
Web optimisation without trading security; services isolated with Docker and Podman.
Four fronts that come back in every project, from the pipeline down to the host.
Secret scanning, SAST, dependency and image scanning running on every pull request: what fails is the build, not production. Explicit severity policy and SARIF as evidence.
Key-only SSH on a non-standard port, default-deny firewall, fail2ban, auditd, kernel parameters and an idempotent deployment you can verify with one command.
SIEM with agents across the fleet, Grafana dashboards, custom rules and automated triage. Alerts you can explain and metrics you can decide with.
Inventory, authenticated scanning, prioritisation by real risk and a patch cycle with SLAs. Fewer open findings, more closable ones.
From financial operations to the SOC and the pipeline: 20+ years building, and lately defending what was built.
DevSecOps & IT Infrastructure Engineer · Brusque, SC · Remote
Founder & Cloud Infrastructure Consultant · Brazil · Remote
Cyber Security Analyst · Remote
IT Security & Systems Engineer · Bogotá, CO · Remote
General Manager & Marketing Strategist · Medellín, CO
Financial and customs operations · Colombia
Verifiable work: public repositories and a lab running in production.
A Linux fleet instrumented with Wazuh over a WireGuard overlay network, plus a triage engine of my own that runs every five minutes.
Five security gates inside GitHub Actions: secrets, SAST, dependencies, infrastructure configuration and container image.
Idempotent hardening for Debian/Ubuntu/RHEL servers with a verification mode: it applies the controls and proves they are in place.
Passive asset sweep from Certificate Transparency logs, with liveness checks and service fingerprinting.
Static portfolio generated with Python (standard library only), no framework, no cookies, no trackers and no third-party assets.
What I use day to day, no decoration: every item here has a story behind it.
The degree and post-graduate work behind the technical job.
Estácio · Brazil
Completed in 2026. Threat intelligence, vulnerability management, server hardening, application security, SOC operations and incident response.
Faculdade Metropolitana · Brazil
Software development life cycle, quality and testing, configuration management and IT governance.
Faculdade Metropolitana · Brazil
Network and web system security, storage infrastructure security, cryptography, ITIL and compliance.
Universidad Autónoma del Caribe · Colombia
Management, finance and process foundations I use to translate technical risk into business language.
Continuous training, newest first.
35 certifications, with verifiable credentials in (ISC)² CC, Pentest Profissional (Desec), Practical Ethical Hacking (TCM), ISO 27001/27002 and ITIL 4.
Send me the problem and the stack; I reply in English, Portuguese or Spanish and tell you straight whether I fit. Available full-time or on contract, remote.
Brazil. Remote for Brazil, LATAM, Europe and the US.