
Senior Information Security Specialist at CIBC
Toronto, Canada Area

Senior Information Security Specialist at CIBC
Toronto, Canada Area
Information Security Professional, Bsc in Computer Science, CISSP-ISSAP.
MCSE (Microsoft) and CCSE (Check Point) certified. PCI QSA.
Working knowledge on Security Policies, Security Awareness, PKI, Firewalls and VPNs, Advanced Windows Security, Unix Security and Web Application Security.
Currently working as Senior Information Security Specialist for the Canadian Imperial Bank of Commerce (CIBC). Also worked as a consultant for Deloitte Canada and Tempest Security Intelligence. I had also worked on security management positions, such as CSO of Fidelity Information Services and Information Security Knowledge & Policies (ISKP) Manager of BankBoston. I started my information security career as security analyst and project manager at Modulo Security Solutions.
Former president of the ISSA Brasil-SP Chapter.
Writer of Infosec papers published on specialized magazines and websites (see articles page), and speaker at Infosec events, like BlackHat Briefings, YSTS, CNASI and Modulo CSO Meeting.
Professor at IBTA's and at Faculdade Impacta de Tecnologia (FIT) Information Security post-graduation programs.
Information Security
(Public Company; 10,001 or more employees; CM; Banking industry)
October 2008 — Present (1 year 3 months)
(Privately Held; 10,001 or more employees; Accounting industry)
July 2008 — October 2008 (4 months)
Vulnerability assessments and penetration testing.
(Information Technology and Services industry)
July 2007 — May 2008 (11 months)
Providing security consulting to key customers, reviewing the company services portfolio and planning their evolution over the next years
(Non-Profit; 10,001 or more employees; Information Technology and Services industry)
July 2006 — July 2007 (1 year 1 month)
(Public Company; 1001-5000 employees; FIS; Banking industry)
March 2005 — July 2007 (2 years 5 months)
Chief Security Officer, in charge of all activities related to Information Security.
(Public Company; 10,001 or more employees; Information Technology and Services industry)
September 2002 — February 2005 (2 years 6 months)
Security Policy and Standards development and dissemination. Incident Response and Security Monitoring.
(Privately Held; 11-50 employees; Information Technology and Services industry)
August 2001 — September 2002 (1 year 2 months)
Information Security projects management. Risk & Vulnerability analysis. Penetration Testing.
(Privately Held; 201-500 employees; Information Technology and Services industry)
January 2000 — August 2001 (1 year 8 months)
Information Security projects. Vulnerability and Risk analysis, Security solutions design, penetration testing.
BsC , Computer Science , 1995 — 1998
Nata da Segurança da Informação 2006 (TI Intelligence)
SECMASTER 2005 - Top 3 - Melhor trabalho acadêmico
Nata da Segurança da Informação 2004 (TI Intelligence)