Skip to content
View RochaCrypt's full-sized avatar
πŸ’­
Let’s go!
πŸ’­
Let’s go!

Block or report RochaCrypt

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
RochaCrypt/README.md

Summary

Cybersecurity leader with over 14 years of IT experience, including 7+ years specialising in Information Security, Security Operations and Cybersecurity Consulting. I combine deep technical expertise with a strategic mindset to help organisations strengthen their security posture, reduce risk and protect business continuity.

Based in Dublin, Ireland, I lead cybersecurity initiatives across enterprise and multi-tenant environments, aligning security strategy with business objectives so that technical decisions translate into measurable value for clients and stakeholders. My expertise spans Security Operations, Incident Response, Vulnerability Management, Penetration Testing, Threat Detection & Response, Security Architecture, EDR/XDR and Cybersecurity Strategy β€” applied across Private, Public and Hybrid Cloud, with alignment to NIST CSF, ISO 27001 and MITRE ATT&CK.

Throughout my career I have led programmes spanning SOC development, EDR/XDR deployments, vulnerability remediation, offensive security engagements and cloud security initiatives, translating complex technical findings into clear, actionable insight for both engineering teams and executive stakeholders β€” ensuring security investments deliver tangible business outcomes.

Role Lead Cybersecurity Engineer
Focus Purple Team Β· Offensive Security Β· Detection & Response
Location Dublin, Ireland
Languages Portuguese (native) Β· English (professional) Β· Spanish (basic)
Frameworks MITRE ATT&CK Β· OWASP Β· NIST CSF Β· ISO 27001
Focus now LLM application security Β· offensive AI
Credentials CEH Β· CCFA Β· CLLMSP

Latest in Cybersecurity

Cyber Pulse

Cyber exec arrested in case allegedly tied to ShinyHunters hackers
Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple…
BleepingComputer

ARTEX AI, Claude agents used in cyberattacks on South Korean banks
The cyberattacks that shook the South Korean financial sector earlier this month were launched by a Chinese hacker using the ARTEX AI penetration…
BleepingComputer

Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP…
BleepingComputer

The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn't
In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind…
The Hacker News

Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison
The former core infrastructure engineer deleted admin accounts, reset hundreds of passwords, and demanded 20 bitcoin to spare the company’s servers…
SecurityWeek

Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws
Anthropic on Friday said it's cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its…
The Hacker News

FBI Arrests Executive at Ransomware Negotiation Firm
Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an…
Krebs on Security

OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks
The ChatGPT maker said the researchers "violated clear policies on handling sensitive information.” The post OpenAI Fires 3 Safety Researchers in…
SecurityWeek

Auto-updated every 6 hours from The Hacker News, BleepingComputer, Krebs on Security, Dark Reading, SecurityWeek, The Record and CISA advisories. Headlines link to the original source.


Core Expertise

Area Focus
Offensive Security & Pentest Web application, network and infrastructure penetration testing; manual exploitation; controlled threat simulation
Purple Teaming Bridging red and blue β€” validating detections and hardening defences against real attack techniques
Vulnerability & Risk Management Qualys VMDR/WAS, Nessus, OpenVAS; asset discovery, custom QQL, risk analysis and remediation planning
Threat Detection & Response SOC operations, threat hunting, incident response, EDR/XDR/MDR (CrowdStrike Falcon), threat intelligence
Security Operations SIEM engineering (FortiSIEM), log correlation, monitoring use cases, dashboards, SOC development
Network & Perimeter Firewalls (FortiGate), WAF, IPS/IDS, VPN, web filtering; FortiManager / FortiAnalyzer
Identity & Access IAM, access control, Active Directory, Windows Server
Cloud Security AWS, Azure and GCP across Private, Public and Hybrid Cloud
Governance & Compliance ISO 27001, ISO 27032, NIST CSF, MITRE ATT&CK, OWASP; audits and policy
Awareness & Reporting Security awareness (KnowBE4); technical, executive and analytical reporting

Engagement approach: Reconnaissance β†’ Assessment β†’ Exploitation β†’ Post-exploitation β†’ Detection review (purple-team) β†’ Technical & executive reporting


How I Deliver Value

I treat security as a business function: every technical decision is measured by the value it creates, the risk it removes and the efficiency it adds.

Business value

  • Translate complex technical findings into clear, executive-level insight that shows where security investment delivers the most return.
  • Build and mature Security Operations Centre (SOC) capability, giving the business continuous visibility and faster detection.
  • Lead offensive security engagements (penetration testing) that surface real weaknesses before attackers can exploit them.
  • Support pre-sales and customer workshops, positioning security as an enabler of new business rather than a blocker.
  • Mentor security teams, compounding capability across the whole organisation.

Risk management

  • Run risk-based vulnerability management β€” prioritising remediation by real exploitability and business impact, not raw scores.
  • Lead threat detection, incident response and threat-intelligence analysis to contain issues quickly and limit impact.
  • Review and approve security architectures before production, catching risk at design time.
  • Enforce identity and access controls and least-privilege access across environments.
  • Align delivery to NIST CSF and ISO 27001, sustaining certifications and audit readiness.

Operational efficiency

  • Engineer SIEM correlation rules, use cases and dashboards (FortiSIEM) that cut alert fatigue and speed up triage.
  • Standardise monitoring, detection and remediation into repeatable processes and playbooks.
  • Centralise and consolidate tooling (EDR/XDR, centralised firewall and log management) to reduce operational overhead.
  • Deliver technical, executive and analytical reporting that keeps stakeholders aligned and reduces rework.

Tip: add measurable outcomes as you quantify them β€” reduction in mean time to detect/respond, vulnerabilities remediated, audit findings closed. Real numbers make this section land hardest.


Experience

Claranet

March 2019 – Present Β· 7+ years Β· Managed security and cloud services provider

Lead Cybersecurity Engineer β€” March 2026 – Present Β· Dublin, Ireland (Remote)

  • Lead technical cybersecurity initiatives across managed security and cloud environments, supporting Private, Public and Hybrid Cloud customers
  • Lead penetration testing engagements across infrastructure, network and web application environments
  • Design, implement and manage EDR/XDR solutions, including CrowdStrike Falcon
  • Provide Level 3 technical support and escalation for security incidents and complex projects
  • Lead incident response investigations and threat analysis activities
  • Perform vulnerability assessments, risk analysis and remediation planning; support the design of SOC capabilities
  • Review and approve security architectures for customer projects
  • Deliver executive and technical security reports and provide technical mentoring to security teams
  • Ensure alignment with NIST CSF, MITRE ATT&CK, OWASP and ISO 27001

Senior Cybersecurity Analyst β€” September 2024 – March 2026 Β· SΓ£o Paulo, Brazil (Hybrid)

  • Led security operations, threat detection and vulnerability management across managed customer environments
  • Conducted Proof of Concepts and technical evaluations of cybersecurity solutions; managed EDR, MDR and XDR platforms
  • Designed and deployed firewalls, IDS/IPS, WAF and DDoS protection solutions
  • Built SIEM use cases, correlation rules and monitoring dashboards
  • Investigated security incidents, coordinated response actions and supported ISO 27001 governance initiatives

Cybersecurity Engineer β€” June 2021 – September 2024 Β· Brazil (Hybrid)

  • Designed and implemented secure network and cybersecurity architectures, from project initiation through production deployment
  • Deployed and managed firewalls, IDS/IPS, WAF, Web Filtering and Application Control solutions
  • Implemented centralised log management and SIEM integrations
  • Developed and enforced security policies using FortiManager
  • Supported pre-sales teams in customer workshops and technical demonstrations
Earlier roles at Claranet

Information Security Analyst β€” June 2020 – July 2021 Β· Brazil (On-site)

  • Supported cybersecurity operations, vulnerability management and customer security projects within managed service environments
  • Monitored and investigated security alerts; assisted with vulnerability assessments and remediation activities

Junior Information Security Analyst β€” March 2019 – June 2020 Β· Barueri, Brazil (On-site)

  • Monitored security events and alerts, supported vulnerability scanning and participated in incident response processes

Amistad Networks

July 2015 – March 2019 Β· 3 years 9 months

Network & Telecommunications Engineer Β· Technical Support Specialist

Network & Telecommunications Engineer β€” April 2017 – March 2019 Β· Brazil

  • Designed, deployed and supported telecommunications, networking and infrastructure solutions for enterprise customers
  • Installed, configured and managed enterprise network infrastructure including routers, switches and firewalls; supported VPN, VLAN, NAT and routing services
  • Supported the implementation of information security controls and secure network architectures; participated in network incident investigation and service restoration

Technical Support Specialist β€” July 2015 – April 2017 Β· Brazil

  • Provided first-line technical support for telecommunications and network services
  • Supported VoIP deployments and infrastructure troubleshooting

Technologies

Platforms and tools I operate in production and assessment environments.

Domain Technologies
Offensive & Assessment Nmap, Burp Suite, Metasploit, Kali Linux, Qualys VMDR / WAS, OWASP methodology
Detection & Response CrowdStrike Falcon (RTR), FortiEDR, FortiSIEM
Network & Perimeter FortiGate, FortiManager, IDS/IPS, Web Filtering, Application Control, Cloudflare (WAF/DDoS)
Identity & Cloud Keycloak, AWS, Private / Public / Hybrid Cloud
Automation & Scripting Python, PowerShell, Bash, Docker

Projects and Knowledge Base

Open resources I build and maintain.

Repository Description Stack
Cyber Pulse Auto-updating cybersecurity news portal, refreshed every 3 hours. Live. Python Β· HTML Β· Actions
Arsenal Interactive catalog of 366 security tools plus my own operational scripts. Live. Bash Β· Python Β· PowerShell Β· HTML
Security Knowledge Base 50 certification and framework references β€” what each is, what it validates, key concepts and a mind map. Docs Β· Mermaid

Certifications and Education

Certifications

Education

  • Postgraduate Degree, Cybersecurity β€” Instituto Daryus (2023 – 2024)
  • Bachelor's Degree, Information Security Management β€” UNINOVE (2018 – 2021)

Activity

Top languages Contribution streak



Contribution calendar Contribution graph

All techniques and tooling are used exclusively in authorised engagements.

Popular repositories Loading

  1. AD_Miner AD_Miner Public

    Forked from AD-Security/AD_Miner

    AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses

    JavaScript

  2. rengine rengine Public

    Forked from yogeshojha/rengine

    .

    Python

  3. lynis lynis Public

    Forked from CISOfy/lynis

    Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

    Shell

  4. faraday faraday Public

    Forked from infobyte/faraday

    Open Source Vulnerability Management Platform

    Python

  5. rapidscan rapidscan Public

    Forked from skavngr/rapidscan

    πŸ†• The Multi-Tool Web Vulnerability Scanner.

    Python

  6. kics kics Public

    Forked from Checkmarx/kics

    Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

    Open Policy Agent