Information Security Consultant
Data Security Serviços em Segurança de Dados Ltda
Oct 2016 - Dec 2017 (1 year 3 months)
I worked as an information security consultant, leading compliance projects and audits in standards such as PCI/DSS, GDPR, ISO27001, ISO 22301, ISO 31000 and SOC 2. I developed the first SOC 2 Report (Type 2) for the Certisign Signature Portal, ensuring certification and approval in the LATAM accreditation process. Collaborated with SPC Brasil in the creation of Business Continuity Plans and Business Impact Analysis (BIA). On the technical front, I gained experience in OWASP standards, OSSTMM, NIST 800-115, SDLC and tools such as Kali, Nessus, Checkmarx DAST/SAST and Wikto. This experience allowed me to develop an innovative approach to Pentest (Web Application) in my undergraduate thesis. Later, I was invited to manage data protection in a