nasgoncalbes
Dev Sec Ops
I'm an information security professional with more than 10 years in the industry. My expertise spans various environments and architectures, including critical infrastructures, network/systems security, security analytics, security controls, datacentre/cloud security, incident response, security administration, software security, development, and automation.
Experience: 11 years
Yearly salary: $140,000
Hourly rate: $65
Nationality: šµš¹ Portugal
Residency: šµš¹ Portugal
Experience
Security & Supply Chain Tech Lead
Morgan Stanley 2022 - 2025
Lead Security SDLC modernization effort: SBOM and providence attestation for each step of the SDLC process and support systems (following SLSA + in-toto attestations). Standardization SDLC controls and policies across firmwide + entities. SAST pipeline integration for Software Security Assurance (SSA) controls. Expansion and standardization of the SAST offering. Security Scan Results Attestation. Migration Security Pipelines to new standard Security pipelines. Vulnerability management. Data feed and APIs to determine the security posture of a production deployment (Software and/or Services).
Security Engineer
Morgan Stanley 2018 - 2023
Development of reusable/repeatable architectural pattern around all aspects of software deployment and infrastructure provision (DevSecOps). Guide, support and upskill other squads in the development of automation projects and agile adoption. Reusable architectural patterns for Software and Infrastructure deployments (DevSecOps, CI/CD, Automation, BDD); Automation and pipeline architecture and development; Process simplification and optimisation (Value Stream Mapping). Stateless and Stateful applications strategies. Configuration-as-code, Infrastructure-as-code, configuration modelling. Knowledge Sharing Sessions, High-Level Design and Low-Level Design documentation. Automation and component Development, 3 service integrations 'glue' (Ansible, Python). Definition SLI, SLO and Error Budget Dashboards. Agile metrics, Business KPIāS, Value Stream Mapping. Aligned with SDLC.
Information Security Specialist
BBC 2017 - 2018
Development of automation workflow to deploy fully functional Hadoop environment. Hadoop for Splunk integration, Hadoop data roll, unified search, archived indexes. On prem and Cloud compatible solution implementation. Tech stack, (Ambari, YARN, HDFS and Zookeeper).
Security Operations Centre Specialist
BBC 2014 - 2017
Design and development of an organization Security Operation Centre: Hardware procurement and installation (e.g., Switches, Storage, Blade server, etc.). Architecture and Implementation multisite (private), terabyte Splunk environment: More than one thousand data sources. Data Lifecycle ā retention & destruction policies. Data onboarding (parsing and field extraction) and validation. Design and develop an automated backup solution for Splunk operational data: Implementation based on the best security practices (Public key encryption) data at rest and in transit. On prem and cloud storage platforms.
Information Security Consultant
CGI 2012 - 2014
Design and development of an organization Security Operation Centre [Energy - Portugal]. Deployment and configure ArcSight SIEM. Deployment and tuning of IT Governance (ISO 27001) and NERC CIP packages and use cases. Tunning rules for vulnerability Identification. Integration of multiple data sources.
Skills
ansible
golang
infrastructure
python
security
devops
english