About

I architect and build security platforms, and I'm credentialed to govern them. Most leaders do one or the other. I've taken security from prototype to revenue: 230K+ endpoints, 60% MTTD reduction, compliance architected in from the first commit. I can sit with a CISO on Monday and a detection engineer on Thursday, and the architecture decisions that come out of those conversations are the same ones. That's not natural. I worked to make it natural.

CISSP, ISO 27001/42001 Lead Auditor, leading a 7-engineer security organization across detection engineering, platform, and threat intelligence. Built and commercially launched Zerum Titan, one of Brazil's first LLM-native threat intelligence platforms, delivering 85% cost reduction and ROI in under a year.

Experience

Head of Security Architecture and Engineering

Zerum IT Jun 2026 - Present

  • Own technical security strategy and design across two flagship products, driving multi-tenancy, localization, and compliance adaptation for new-market entry.
  • Lead a 7-engineer org spanning detection engineering, platform, and threat intelligence.
  • Direct detection and response design: coverage mapped to MITRE ATT&CK and NIST CSF, built to withstand adversarial scrutiny.
  • Ensure ISO 27001/42001 and LGPD/GDPR compliance by design: controls embedded in the architecture, not retrofitted after audit.

Head of Cybersecurity Innovation

Zerum IT Sep 2024 - Jun 2026

  • Owned the security innovation roadmap and 150K USD annual budget. Led cross-functional team of 8+ (Product, Engineering, SOC, Legal, Sales) to deliver Zerum Titan from prototype to commercial adoption in 6 months, 60% MTTD reduction across 5 clients, establishing Zerum's first recurring SaaS security revenue.
  • Engineered 85% cost reduction (43K USD/year) through vendor consolidation and in-house tooling, freeing budget for AI R&D.
  • Drove Zerum's first formal GRC initiative: ISO 27001, ISO 27701, LGPD certification. Chaired the SGSI committee and presented the multi-year compliance roadmap to the board, securing full executive sponsorship.
  • Pioneered LLM orchestration for automated detection workflows and executive reporting, one of Brazil's first commercial AI-orchestrated SOC deployments.

SOC Senior Analyst

Zerum IT Aug 2022 - Sep 2024

  • Scaled SOC operations (Wazuh SIEM + Zerum Lynx NDR) to 230K endpoints across 5 enterprise and government clients.
  • Cut analyst investigation time 40% with automated playbooks and 40+ custom detection rules. Onboarded and trained 2 junior analysts on threat hunting methodology.
  • Detected and contained an active ransomware campaign within 2 hours via UEBA behavioral analysis, preventing encryption of a sensitive government network, $2M+ in projected recovery costs averted.
  • Maintained zero critical breaches across 230K-endpoint multi-tenant environment over 2 years.

System Administrator (Security-Focused)

IAFIS Group Jan 2022 - May 2022

  • Bridge role transitioning into SOC engineering. Hardened Windows and Linux environments for classified government material; administered access controls and validated DR procedures for mission-critical systems.

GRC Consultant and Agile Lead

Quantum Leap Sep 2021 - Dec 2021

  • Steered ISO 27001 certification to completion: remediated 3 non-compliances, passed external audit on first attempt.
  • Delivered GDPR/LGPD-compliant security architecture for the Nommo IoT water pump, launched at Web Summit Lisbon 2021.

IT Infrastructure Technician, Level 2

CTIS / SONDA Oct 2019 - Sep 2021

  • Delivered secure IT infrastructure across 30+ federal government offices (TJDFT, MAPA), enforcing security controls over judiciary process data.
  • Managed endpoint security and incident triage across 1,000+ workstations in high-compliance federal environments.

Projects

Zerum Lynx Cloud 2026 - Ongoing

A cloud-native Network Detection and Response (NDR) platform targeting Brazilian fintechs, cooperatives, and government agencies. Portuguese-first, LGPD-native, with dual deployment for multi-tenant SaaS and air-gapped appliance.

Zerum Omnivision 2024 - Ongoing

A unified AI security operations platform for the Zerum product ecosystem. Provides AI-assisted alert triage, threat intel enrichment, and cross-platform detection workflows under a multi-tenant, LGPD-compliant architecture.

Zerum Titan 2024 - 2025

An LLM-native threat intelligence platform that aggregates open, commercial, and internal sources into a single orchestrated response engine. Built from prototype to commercial adoption in 6 months, operating across the existing 230K-endpoint environment with 60% MTTD reduction and 85% cost reduction. ROI in under a year.

Earlier Work

Nommo Smart Water Pump 2021

IoT-enabled smart water pump with embedded systems and edge AI for a bottled-water order-and-delivery ecosystem. Led project management and technical implementation from firmware to cloud integration.

Learn more

Onomastic Index of Empire Senators 2017 - 2019

Public index of Brazilian senator pronouncements (1826-1889), built as an open-data resource for the Federal Senate. Connected historical legislative records to a searchable public interface.

Learn more

Geoprocessing of Licenses in the PNLA 2016 - 2017

Integrated database connecting multiple environmental agencies to produce interactive licensing maps for the National Environmental Licensing Portal (PNLA).

Learn more

Key Achievements

Ransomware Prevention, $2M+ Averted

2023

Sole analyst to identify and contain an active government ransomware campaign within 2 hours via UEBA behavioral analysis, preventing encryption of classified infrastructure. Post-incident playbooks adopted organization-wide.

Zero Critical Breaches Over 2 Years

Maintained zero critical breach events across 230K-endpoint multi-tenant environment through proactive threat hunting and detection methods aligned with ISO 27001 and NIST CSF.

First AI-Orchestrated SOC in Brazil

2025

Deployed one of the country's first commercial LLM-native threat intelligence platforms, establishing Zerum's first recurring SaaS security revenue stream and shifting the SOC from reactive triage to proactive threat hunting.

Core Competencies

Executive Leadership

Security Strategy, Board Reporting, Executive Advisory, Budget & P&L, Roadmap Development, Product Commercialization

GRC and Compliance

ISO 27001, ISO 42001, LGPD/GDPR, NIST CSF/AI RMF, SGSI Committee Chair, Cyber Risk Quantification, Third-Party Risk

Security Operations and AI

Threat Intelligence, LLM Orchestration, AI-Driven Detection, SOAR Automation, SOC Engineering, Incident Response, Detection Engineering

Technology Stack

SIEM (Wazuh, Elastic), NDR, Cloud Security (AWS, Azure), MISP/OpenCTI, DevSecOps, Zero Trust, LGPD Data Engineering

Threat Hunting and Detection

Beaconing & C2 Detection, DGA Analysis, Lateral Movement, Exfiltration Detection, MITRE ATT&CK Mapping, Kill-Chain Correlation, Deep Packet Inspection

Languages and Tools

Rust, Python, TypeScript, SQL, Docker, Kubernetes/Helm, Git, CI/CD, OCSF/STIX/TAXII

Education

B.Sc. in Computer Science

Universidade de Brasília (UnB)

2022

Languages

Portuguese Native
English C2 - Fluent
German B2 - Intermediate
Spanish B1
French A2