Full curriculum
Complete record. For a summary, see LinkedIn.
Now
GRC Consultant
- Third-party risk assessment for a major financial institution, 260+ vendors, with consolidated risk reporting and remediation plans
- AI governance assessment against ISO/IEC 42001 and OT/IT risk assessment for an industrial client, with prioritized remediation for executive leadership
- Built TPRM forms, assessment templates and delivery workflows, including supplier risk criteria for an aerospace manufacturer
Previously
Information Security & Privacy Consultant, Founding Team
- Built an information security and privacy practice from zero with a senior DPO, delivering through an alliance with BeCompliance, one of the leading compliance platforms in Brazil
- Structured the service offering, assessment methodologies and delivery workflows
- ISMS and ISO/IEC 27001 alignment, with security documentation end to end
Information Security Analyst
- Security product development and client delivery, working directly with the CEO
- Led content development for Phishing Plus: 40+ enterprise security awareness products focused on human risk
- ISO/IEC 27001 and 27002 assessment support for a pharmaceutical company
Information Security & Privacy Analyst
- Trained by multiple senior DPOs in a multi-client privacy practice, executing client deliverables independently within months
- Data mapping, DPIAs and RoPA for multi-site organizations across agribusiness, insurance, automotive retail and manufacturing, including a group with 50+ locations
Post-Production & Live Streaming Infrastructure
- Delivery on projects for Google, Porsche Cup, Tommy Hilfiger and Mondelez
- Custom Twitch chatbots, stream automation and OBS architecture for high-availability live streaming, a go-to specialist for top Brazilian streamers
- Art direction and content production for Pernod Ricard, Philips, Royal Canin and Forno de Minas
Education
Instituto Daryus
- Operational technology security for critical infrastructure, the sector focus of the current consulting work
FIAP
- Technical foundation, built alongside the first security roles rather than before them
- Capstone project: SIEM development for Trustly
ESPM
- Left to apply the craft in practice: freelance delivery, agency work and founding a venture, the period recorded above under self-employment
FECAP
- Business, accounting and quantitative grounding, the basis for the later work in risk quantification
Publications
- RISK · book, 2026
Recognition
- Young Governance Transformer · Latin American Institute of Public Governance and Compliance (IGCP) and Rede Governança Brasil, 2026
Training
- Business and financial modeling: quantitative modeling, spreadsheets and models, modeling risks and realities, and decision-making and scenarios; managing social and human capital · Wharton Online, 2026
- FAIR cyber risk series: foundations, practical application, risk reporting, executive communication and governance, and advancing FAIR within risk management programs · FAIR Institute, 2025
- Introduction to Probability Management · Stanford Online, 2025
- Corporate intelligence (VI CEIAMC): intelligence doctrine, collection and sources, strategic intelligence and applied risk management, 67 hours · ADESG, 2026
- Platform training and certifications across privacy automation, consent, data discovery, third-party risk, IT risk and AI governance, 60+ modules · OneTrust, 2025
- OpenPages Essentials · IBM, 2025
- GRC on S/4HANA Public Cloud · SAP, 2025
- Running the Internal Audit Function · Wolters Kluwer, 2025
- AI Security & Governance, DSPM Fundamentals and PrivacyOps · Securiti, 2025
- Privacy deployment · Privacy Tools, 2025
- Falcon Identity Protection and Falcon Cloud Security fundamentals · CrowdStrike University, 2026
- Digital forensics: MITRE ATT&CK, OWASP Top 10, Cellebrite, Autopsy and the digital forensic expert track · Academia de Forense Digital, 2024
- Information Security Officer, Cybersecurity Professional and Penetration Testing · FIAP, 2024–2025
- COBIT, ITIL, HIPAA compliance and PCI DSS · LinkedIn Learning, 2025
- Cybersecurity Fundamentals · IBM, 2024
- Anti-corruption and antitrust compliance · ENAP, 2025
- Project management and people management · FGV, 2024–2025
- Information security for healthcare · ABCIS, 2026
- AI Governance Strategies virtual summit · ISACA, 2025
- McKinsey Forward · McKinsey & Company, 2026
Languages
- Portuguese · native
- English · fluent