CYBERSECURITY • AI SECURITY • TECHNOLOGY LEADERSHIP

AI-driven
Cyber Defense

I design defensive security operations that connect telemetry, automation and large language models to improve risk assessment, incident triage and decision-making.

Defensive, authorized and human-supervised security engineering.

LIVE SECURITY PIPELINEONLINE
SIEMWazuh / Sentinel
SOARn8n workflows
AILLM risk analysis
HIGH

Privileged identity anomaly

Correlated
MED

Endpoint behavior deviation

Enriched
LOW

Configuration risk finding

Reviewed

01 — FOCUS

Current focus

Security engineering at the intersection of SIEM, SOAR, cloud platforms and applied AI.
01

Wazuh SIEM

Deployment, telemetry engineering, rules, alert analysis and risk visibility.

02

Microsoft Sentinel

Cloud-native SIEM, analytics, investigation workflows and security operations.

03

Microsoft Security

Defender ecosystem, identity security and broader Microsoft security controls.

04

n8n Security Automation

Event orchestration, enrichment, routing, reporting and repeatable response workflows.

05

LLM Risk Analysis

Contextual evaluation, prioritization and structured summaries with human oversight.

06

Cloud & Infrastructure

Kubernetes, Linux, IAM, hardening, resilience, monitoring and secure architecture.

02 — ARCHITECTURE

AI-assisted security operations

A practical workflow currently used to transform security events into contextual, reviewable risk intelligence.
Endpoints & Cloud
Wazuh / Sentinel
n8n orchestration
LLM analysis
Risk score
MITRE context
Response guidance

HUMAN REVIEW & AUTHORIZED DEFENSIVE ACTION

Operational outcomes

  • Risk scoring and prioritization
  • Alert enrichment and correlation
  • Incident summaries for technical and executive audiences
  • Suggested response actions with human validation
  • MITRE ATT&CK context and investigation support

03 — PROJECTS

Applied security work

Technical initiatives centered on authorized environments, reviewable automation and human decision-making.

CURRENT TECHNICAL DIRECTION

01

SIEM engineering

Telemetry onboarding, detection tuning and alert investigation across Wazuh and Microsoft Sentinel.

02

Defensive automation

Repeatable n8n workflows for enrichment, routing, reporting and analyst-reviewed response guidance.

03

LLM-assisted analysis

Structured risk assessment, incident summarization and MITRE ATT&CK context with human validation.

04 — EXPERIENCE

Leadership grounded in engineering

More than two decades across software architecture, research and development, cloud platforms, infrastructure and technology leadership. At Estratosfera, I lead technology and cybersecurity initiatives, including monitoring, automation, identity, resilience and secure modernization.

Selected career path

Estratosfera

Director of Technology & Cybersecurity

Turbi

CTO

Justto

CTO

Navita

Technical Lead & Architect

TOTVS

Research & Development Engineer

Enterprise technology

Architecture and senior software engineering roles

05 — CREDENTIALS

Credentials & education

Public, independently verifiable credentials are linked below.

06 — CONTACT

Let’s build safer systems

Available for conversations about AI-assisted SOC, Microsoft security, SIEM/SOAR architecture, cloud security and defensive automation.[email protected]