Information Security professional and pragmatic problem-solver with a technical background, security engineering and incident management focus, compliance and governance knowledge and experience in managing cross-functional teams. CISSP, ISO27k1 LI, Security+, CIH and MCSA certified, if that’s what you're into.I also work as (SCUBA) Open Water Instructor, Freediving Instructor and boat skipper in my spare time.
-
Staff Security EngineerSinglestore Apr 2024 - PresentSan Francisco, California, Us -
Senior Security EngineerSinglestore Nov 2022 - Apr 2024San Francisco, California, UsImproving SingleStore's AppSec posture.▪ Implemented a security review process for new product features and changes, introduced threat modeling and pentests into those reviews, and currently leading the charge in conducting them, having reviewed all major features released by SingleStore in 2023 and 2024;▪ Carrying out the implementation of OWASP SAMM and promoting the development of a security-centric engineering culture;▪ Improved and redesigned product vulnerability management processes at SingleStore and currently enforcing those same processes. Moreover, I have developed an automation bot (python, AWS Lambda) to help tracking and managing vulnerabilities internally;▪ Implemented SingleStore's current Pentesting Program and responsible for conducting internal pentesting for new major features and coordinating yearly pentests with service providers;▪ Carrying out security IR activities and providing guidance on IR for product-related events when these arise;▪ Implemented Application Security training for 140+ engineers;▪ Implemented SingleStore's Responsible Disclosure Program (in partnership with HackerOne);▪ Kept supporting ISO27k1 and SOC2T2 audits, enabling consistently positive results.Most relevant technologies: Kubernetes, Containers, Golang, Python, Gitlab, AWS, GCP, Azure, multiple open-source SAST and SCA tools (e.g. grype, kics, semgrep, flawfinder, gosec), Kali, Burp Suite, Crowdstrike, Knowbe4, Tenable, Nessus, ELK, Grafana, HackerOne, automations and scripting. -
Security AnalystSinglestore Feb 2022 - Oct 2022San Francisco, California, UsProduct and Enterprise Security plus compliance management.▪ Created SingleStore's foundational framework for vulnerability management (policy dev+implementation, deployed scanning tools namely Tenable and open-source SAST, SCA, secrets and IaC scanning, implemented an annual pentesting program);▪ Successfully led SingleStore as interim GRC manager achieving positive results in the ISO27k1 2nd year surveillance audit and the SOC2 Type 2 and HIPAA 2022 audit;▪ Handled supplier security management, screening and risk assessments for over 200 vendors;▪ Supported Sales and PM wrt to Product Security matters, enabling positive relationships with at least 5 key customers for SingleStore.▪ Delivered Information Security awareness training (including running simulated phishing and smishing tests company wide) to over 400 employees. -
Open Water Instructor (Scuba) & Freediving InstructorSsi Scuba Schools International May 2022 - PresentWendelstein, Bavaria, DeI freelance as an instructor for SCUBA diving and freediving in the coast of continental Portugal. I'm also a certified gas blender (Nx and Tx), equipment service technician and hold a local skipper license. -
Security LeadUnbabel Dec 2020 - Feb 2022San Francisco, California, UsLed implementation of Information Security at Unbabel from both the enterprise and product areas:▪ Assumed the role of the ISMS Manager and led Information Security processes implementation, maintenance and improvement, in preparation for ISO27001 certification which was successful enabling Unbabel to get certified;▪ Provided guidance and aided in the implementation of security controls in corporate and product environments;▪ Managed vulnerability, bug bounty and pentesting programs liaising w/ SRE, TechOps and Engineering teams successfully enforcing a stable growing trend of vulnerability remediation;▪ Implemented Unbabel's SIRT, led the team and ran successful IR tests;▪ Coordinated with the DPO in privacy and data protection issues (GDPR, CCPA, others);▪ Jointly implemented supplier security management processes w/ Legal and conducted vendor screening for over 150 vendors;▪ Developed and provided security awareness training company-wide to 200 users;▪ Internal/external interface in all security aspects related to Unbabel, namely with customers;▪ Helped define the roadmap for the merger between Unbabel and Lingo24 wrt to Information Security.Most relevant technologies: Fortiguard, Gophish, Eramba, ELK, logz.io, strongDM, Dashlane, 1Password. -
Area Head For Portugal Cybersecurity ServicesGmv Jun 2019 - Dec 2020Tres Cantos, Madrid, EsLed the Cybersecurity team of the Secure E-Solutions department in Portugal. Stepped up to manage operations, people and commercial activities within this area. -
Security ConsultantGmv Mar 2018 - Dec 2020Tres Cantos, Madrid, EsProvided Information Security consultancy for national and European organizations in the space and aviation industries (ESA and EUROCONTROL), banking (IADB and BNI Europa) and IT companies, having performed various activities:▪ ISMS implementation and maintenance based on ISO27k1 and NIST;▪ Information security, business continuity, privacy and compliance assessments and mitigation plans;▪ Definition and guidance on information security requirements and controls;▪ Vulnerability management;▪ Technical security review of systems, networks and software architecture;▪ SecDevOps and Secure SDLC implementation and guidance;▪ Technology scouting and implementation of software-based security solutions.Most relevant technologies: Microsoft 365 security, Checkmarx, ArcSight, IBM QRadar, Kali, Burp, Fortinet, FireEye, PAM (Privileged Access Management) software, custom software. -
Project ManagerGmv Jan 2017 - Dec 2020Tres Cantos, Madrid, EsLed and supported multiple software engineering and cybersecurity small scale projects. -
Software EngineerGmv Nov 2015 - Dec 2017Tres Cantos, Madrid, EsDeveloped secure web and mobile applications for several public administration and banking projects, for national (Lisbon City Hall, AICEP) and international customers (ESA, IADB).Most relevant technologies: .NET/C#, Sharepoint, Cordova, PHP (LAMP stack), JS. -
Security Incident Handler (Through Gmv)Euspa - Eu Agency For The Space Programme Apr 2019 - Nov 2020Prague, CzSupported security monitoring and incident handling operations for the Galileo GNSS programme infrastructure as a contractor through GMV. -
TraineeNovabase Feb 2015 - Jul 2015Lisbon, Lisboa, PtCurricular internship program. Built a mobile cross-platform app meant to provide business intelligence to the energy sector in Cape Verde.Most relevant technologies: Cordova, Ionic, AngularJS, sqlite.
Francisco Godinho Skills
Francisco Godinho Education Details
-
Universidade Nova De LisboaComputer Science And Engineering
Frequently Asked Questions about Francisco Godinho
What company does Francisco Godinho work for?
Francisco Godinho works for Singlestore
What is Francisco Godinho's role at the current company?
Francisco Godinho's current role is Staff Security Engineer @ SingleStore.
What schools did Francisco Godinho attend?
Francisco Godinho attended Universidade Nova De Lisboa.
What skills is Francisco Godinho known for?
Francisco Godinho has skills like Java, Software Development, C#, Ruby On Rails, Sql, Databases, Javascript, Teamwork, Asp.net, Mobile Applications, C, Html.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial