paulorugeiro
Cissp | Information Security Officer
Certified Information Systems Security Professional (CISSP) certified with 5+ years of hands-on experience in security consulting and operations (spanning vulnerability management, SOC operations, cloud security, and governance), I bring both technical depth and adaptability that allow me to thrive in diverse and fast-paced environments.
I often describe myself as a “jack of all trades” in the field. My experience across multiple domains, from conducting penetration test audits and optimizing SIEM controls to leading PCI DSS certification efforts, has given me a holistic understanding of how technology, processes, and people intersect to shape an organization’s security posture.
Beyond technical expertise, I value collaboration and continuous learning. I’m a strong team player who thrives in enthusiastic, growth-oriented environments. I always seek a team that values curiosity, creativity, and hands-on problem-solving, where I can both contribute and continue to learn every day.
I often describe myself as a “jack of all trades” in the field. My experience across multiple domains, from conducting penetration test audits and optimizing SIEM controls to leading PCI DSS certification efforts, has given me a holistic understanding of how technology, processes, and people intersect to shape an organization’s security posture.
Beyond technical expertise, I value collaboration and continuous learning. I’m a strong team player who thrives in enthusiastic, growth-oriented environments. I always seek a team that values curiosity, creativity, and hands-on problem-solving, where I can both contribute and continue to learn every day.
Experience: 6 years
Yearly salary: $64,000
Hourly rate: $40
Nationality: 🇵🇹 Portugal
Residency: 🇵🇹 Portugal
Experience
Information Security Consultant
EY Portugal 2020 - 2023
• Spearheaded M365 security for a banking Cybersecurity as a Service project serving 5,000+ users, engineering mail flow rules, MFA, Conditional Access policies, and certificate/secret lifecycles. • Enhanced SOC efficiency by creating IRPs and playbooks for 100+ monthly incidents, delivering continuous risk posture and metric reporting directly to the Head of Information Security. • Managed the vulnerability lifecycle by conducting scans across 30+ business-critical applications and infrastructure components, driving cross-functional remediation initiatives. • Conducted BIA and DRP activities to establish MTD, RTO, and RPO metrics; created phishing/smishing simulation framework making use of PPSE to increase user security awareness by over 50%.
Skills
security
english
portuguese
spanish