Dennis Silva

Dennis Silva Email and Phone Number

Cloud Security Consultant at Amazon Web Services (AWS) @ Amazon Web Services (AWS)
seattle, washington, united states
Dennis Silva's Location
Campinas, São Paulo, Brazil, Brazil
About Dennis Silva

12+ years of experience in IT Audit and General Controls, IT Governance, Network and Security Architecture, Penetration Tests in Cloud, Infrastructure, ERP, Database and Web Application. Strong expertise working with Industry Standards such as COBIT, ISO/EIC 27001:2013, Cloud Security Alliance (CSA), NIST, CVSS and Open Web Application Project (OWASP).My personal experience includes several companies in the financial, automotive, energy, steel, pulp and paper and telecommunications. One of the my biggest challenge in my career was obtain the ISO/EIC 27001:2013 certification to the Cloud Computing operations (including Data center) in a major LATAM software development company, including 3 sites, 5 third parties, 350 employees and 50 business process.

Dennis Silva's Current Company Details
Amazon Web Services (AWS)

Amazon Web Services (Aws)

View
Cloud Security Consultant at Amazon Web Services (AWS)
seattle, washington, united states
Employees:
72973
Dennis Silva Work Experience Details
  • Amazon Web Services (Aws)
    Cloud Security Consultant
    Amazon Web Services (Aws) Jan 2022 - Present
    São Paulo, Brazil
  • Rd Station
    Cyber Security Tech Lead
    Rd Station May 2021 - Jan 2022
    Campinas, São Paulo, Brazil
    As a Cyber Security Tech Leader I was in charge to understand the possible security risks related to business to implement (and support the internal teams) security measures to keep data secure.Here is the majority of my responsabilities:- Define the security frameworks to use as a guide for software development process, security baseline, information system management system and risk assessment.- Establish the technical security requirements for several security areas (e.g. software development, IAM - authentication and authorization, vulnerability management, network protection and inspection, cryptograhy (in-transit and at-rest) and incident response.- Execute security assessment to validate which security controls are in place to minimize security risks. Create a security report either executive report and technical report with details about the main findings, recommendations and action plan prioritized by risk level.- Provide technical guidance and mentoring to security staff according to their career aspirations and support them to understand how important is the core security controls for the business.
  • Daitan Group
    Cloud Security Architect
    Daitan Group Jan 2019 - Apr 2021
    Campinas Area, Brazil
    I came to Daitan company with one big challange: elaborate and implement the strategic, tactical and operational Information Security Plan to mitigate business risks through the effective controls, keeping the Security Information KPIs and KGIs and providing customers satisfaction.The key activities that I'm development is:- Build the Cyber Security Strategic plan, including the risk assessment methodology, controls practices and audit guidelines;- Help the Executive Team to ensure the Information Security directives are established and published to all company;- Awareness all Daitan's Employees about the Information Security best practices, avoiding sensitive data leakage;- Supporting the Information Security questions sent by external customers about the Daitan's security information controls implemented in current IT Environment;- Proof of Concept/Value (PoC/PoV) in an IT or IS technology solutions.
  • Totvs
    Information Security Coordinator And Team Leader
    Totvs Nov 2017 - Dec 2018
    São Paulo E Região, Brasil
    In addition to the activities listed below, I am also responsible for:- Support the cloud customer to understand and clarify Information Security questions. Also, I'm helping them with other cloud subjects in terms of Infrastructure, Database, DevOps, Network, Storage and Backup, etc.- Elaboration the public security documentation (Ex: Security White Paper) that describes the technologies and internal process that we use for deliver the IT environment in a security manner.- Information Security Awareness Training to cloud staff to ensure knowledge about phishing, malwares and security procedures / incidents.
  • Totvs
    Information Security Specialist
    Totvs Apr 2015 - Nov 2017
    São Paulo E Região, Brasil
    Professional in charge for achieve the ISO27K1 certification and implement the Information Security Management System (ISMS) on TOTVS Cloud Computing Business Unit. The TOTVS cloud is managed by the IT orchestration platform (softwares developed to create and support TOTVS ERPs infrastructure and databases and public cloud approved by TOTVS).The following activities were developed for our team:• Security Information Risk methodology and procedures: - Business and Security Information impacts (e.g. Confidentiality, Integrity and Availability) - Mapping security information risk with internal control considering which kind of control (e.g. manual or automated) and frequency (e.g. quarter, monthly, etc) - Association of internal control with the control of Annex A of ISO27K1• Risk Treatment Plan (RTP) - Development a strategic plan to implement the new controls - Walkthrough to understand the control activities and, sometimes, collecting evidence. • Statement of Applicability (SOA) - Mapping of internal controls applicable to Annex A of ISO2701 based on business justification.• Development the policies, normative and procedures about information Security including: - Information Security - Physical and Logical Access - Remote Access - Clean Desk - Cryptography - Backup and Restore - IT Asset Disposal - Disaster Recovery
  • Icts Protiviti
    Senior Information Security Consultant
    Icts Protiviti Apr 2012 - Apr 2015
    São Paulo E Região, Brasil
    • Performing internal and external penetration test in infrastructure, web applications and ERP's (SAP).• Development of executive presentation considering key risks identified, preparation of technical reports describing the identified vulnerabilities and recommendations.• Analysis and implementation of firewall rules on devices such as CheckPoint and Cisco ASA.• Management and segregation of physical and virtual networks of corporate network devices, combined with the implementation of access rules at Layer 2 (Access Control List) and analysis of assets included in the demilitarized zone (DMZ).• Response to security incidents.• Vulnerability Management.• Hardening in operating systems such as Windows and Linux.• Configuration and managing SIEM (Splunk) tool for correlation of logs and notification of security events.• Forensic analysis for Windows / Linux servers and mobile devices.• Business impact analysis (BIA) / Disaster recovery plan (DRP).
  • Kpmg Advisory
    It Auditor/Consultant
    Kpmg Advisory Oct 2009 - Apr 2012
    São Paulo E Região, Brasil
    • Perform activities related to IT external Audit in support to financial audit and execution test of design and effectiveness IT general controls, acting in three areas:• Access and Program and Data - Security Police and user awareness, access control and sanitization users on network and corporate systems, password police, logs and user accounts administrative.• Program Change - request, authorization and transport changes, segregation of type of changes (Normal and Emergency) and environment (DEV, HMG and PRD).• Computer Operations - jobs and backup scheduled, storage of backup media and monitoring computing resources for critical servers.• Development ISAE3402 Type I or II report considering the entity level and internal controls.In addition to the above activities, participated in projects of IT governance, assessing the maturity level of the controls based on COBIT framework

Dennis Silva Education Details

Frequently Asked Questions about Dennis Silva

What company does Dennis Silva work for?

Dennis Silva works for Amazon Web Services (Aws)

What is Dennis Silva's role at the current company?

Dennis Silva's current role is Cloud Security Consultant at Amazon Web Services (AWS).

What schools did Dennis Silva attend?

Dennis Silva attended Fundação Getulio Vargas, Kaplan International, Universidade Bandeirante De São Paulo, Sap Ag Brazil, 4linux.

Not the Dennis Silva you were looking for?

  • Dênnis Silva

    São Paulo, Sp
  • Dennis Silva

    Devops Analyst At Accenture Brasil
    São Paulo, Sp
    3
    concrete.com.br, hotmail.com, locaweb.com.br

    1 (113)-5XXXXXXX

  • Dennis Silva

    Analista De Observabilidade | Zcs/Zcp - Zabbix Certified Professional | Sysadmin Linux
    Mauá, Sp
  • Dennis Silva

    Data Analyst | Business Analyst | Business Intelligence | Power Bi | Sql
    Sumaré, Sp

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.