I am Gilson, a cybersecurity professional with over 8 years of experience specializing in critical areas such as penetration testing (pentest), Application Security (AppSec), DevSecOps, and cloud security. My career is defined by delivering robust projects focused on identifying and mitigating vulnerabilities, safeguarding systems and data, and fostering a security-driven organizational culture.Key Skills:Vulnerability Management: Strategic planning and execution of vulnerability detection tests.Incident Response: Rapid and effective reaction to emerging threats.Threat Intelligence: Proficiency in frameworks such as NIST, MITRE ATT&CK, ISO/IEC 27001, ISO 27005, ITIL, and OWASP.Cloud Security: Hands-on experience with Azure and AWS, including mainframe-to-cloud transitions.Regulatory Compliance: Ensuring adherence to standards such as LGPD, GDPR, and other relevant regulations.Achievements:I have led security projects for prominent organizations, including Coopersystem, Trinca, and act digital, where I implemented innovative solutions that enhanced cybersecurity resilience. My certifications, including GDPR Foundation, LPIC-1, and CompTIA Linux+, reinforce my technical expertise and strategic insight.Current Objective:I am seeking opportunities to contribute to organizations that prioritize cybersecurity as a strategic pillar. I am ready to take on challenging projects in dynamic environments, delivering innovative and integrated solutions.If you’re looking for a dedicated expert to strengthen your organization's digital security and resilience, let’s connect!Email: gilsonojr@gmail.com
Framework Digital
View- Website:
- frameworksystem.com
- Employees:
- 415
-
DevsecopsFramework DigitalFederal District, Brazil -
Information Security Analyst - Red TeamCoopersystem Mar 2024 - PresentBrasília, Distrito Federal, BrasilFunctions and Responsibilities:Strategic Penetration Testing Planning:- Developing customized approaches to simulate realistic cyber attacks, aligned with the specific objectives and requirements of each client.- Identifying and prioritizing potential targets, considering the criticality of the assets and systems involved.Advanced Penetration Testing Execution:- Conducting penetration tests on network infrastructure, operating systems, web, and mobile applications using current and sophisticated attack techniques.- Utilizing specialized tools and recognized methodologies for vulnerability discovery and exploitation.Risk and Vulnerability Analysis:- Detailed assessment of discovered vulnerabilities, including their severity and potential impact on the client's environment.- Recommending countermeasures and solutions to mitigate security risks and strengthen the organization's defensive posture.Comprehensive Security Reporting:- Creating detailed technical reports documenting test results, including evidence of exploitation and clear recommendations for remediation.- Effective communication with technical and non-technical stakeholders to ensure a comprehensive understanding of findings and necessary actions.Team Empowerment and Development:- Mentoring and training team members in advanced penetration testing techniques, security methodologies, and industry best practices.- Promoting a proactive security culture and raising awareness of emerging cyber threats.- Continuous Research and Development:- Monitoring trends and developments in the field of cybersecurity by participating in security communities, conferences, and workshops.- Actively contributing to internal research and development projects related to security and technological innovation. -
SecopsTrinca Jan 2023 - Mar 2024Porto Alegre, Rio Grande Do Sul, BrasilFunctions and Responsibilities:Vulnerability Assessment.Penetration Testing (Pentest).Risk Analysis.Development of Mitigation Strategies.Security Monitoring.Security Incident Response.Development and Implementation of Security Policies.Security Training and Awareness.Digital Forensic Analysis.Security Architecture Assessment.Introduction of policies and best practices based on LGPD and GDPR.Mapping and design of processes based on ISO27001 and ISO27002. -
Information Security SpecialistAct Digital Jun 2022 - Jan 2023São Paulo, BrasilFunctions and Responsibilities:Vulnerability Analysis:- Identification and analysis of vulnerabilities in systems, networks, and applications.- Conducting penetration tests (pentests) to assess the security of systems and networks.- Implementation of Security Measures:- Development and implementation of information security policies.- Configuration and management of firewalls, IDS/IPS, and other security tools.Security Auditing:- Conducting security audits to ensure compliance with standards and regulations.- Analysis of logs and security records to identify suspicious activities.Incident Response:- Development of incident response plans.- Coordination and execution of investigations in cases of security breaches.Training and Awareness:- Conducting information security awareness training for employees.- Preparation of educational materials on cybersecurity best practices.- Participation in Mainframe to Cloud Digital Transition (Azure and AWS):- Assessment of mainframe system security during the transition to cloud environments, using Azure and AWS services.- Implementation of specific security controls for cloud environments such as AWS, Azure, or Google Cloud Platform.- Collaboration with development and operations teams to ensure data integrity and security during the migration process.Risk Analysis:- Identification and evaluation of security risks associated with the mainframe to cloud transition, with a focus on Azure and AWS services.- Recommendation of mitigation measures to reduce identified risks.Identity and Access Management:- Implementation of access control policies and identity management.- Configuration and administration of multi-factor authentication systems and identity management solutions. -
Security Engineer - N3Nuveo Dec 2021 - Jul 2022Ão Paulo, São Paulo, BrasilFunctions and Responsibilities:- Port Analysis and System Identification- Wireless System Weakness Testing- Service Verification (Website, Email, Name Server, Visible Documents, Viruses, and Trojans)- Vulnerability Determination and Exploit Identification- Password Strength Analysis and Denial of Service- Cookie and Site Bug Analysis- Manual Vulnerability Checking- Firewall and ACL Review and Information Security Policy Review- Intrusion Detection Systems Review and Monitoring- Information Gathering (news services, press releases, company-provided information), job offers, newsgroups, xracks, serial numbers, and "underground" information, FTP, Website, P2P- Introduction of Policies and Best Practices based on LGPD and GDPR- Mapping and Process Design based on ISO27001 and ISO27002- Creating Training to Share the Information Security Culture- Bug Bounty Analysis- Design of Technology Area Services and Processes using frameworks (ITIL, Scrum, Green IT...) -
Head Of Cyber SecurityConta Zap May 2021 - Nov 2021São Paulo, São Paulo, BrasilFunctions and Responsibilities:- Analysis of ports and System Identification- Testing weaknesses in wireless systems- Verification of services (Website, email, name server, visible documents, viruses, and trojans)- Determination of vulnerabilities and Exploit Identification- Password strength analysis and Denial of Service- Cookie analysis and Website bugs- Manual vulnerability checks- Firewall and ACL review and information security policies- Review of intrusion detection systems / intrusion prevention systems- Information gathering (news services, press releases, company-provided information), job offers, newsgroups, xracks, serial numbers, and "underground" resources, FTP, Website, P2P- Introduction of policies and best practices based on LGPD and GDPR- Mapping and process design based on ISO27001 and ISO27002- Designing Technology area services and processes using frameworks (ITIL, Scrum, Green IT...) -
Bank Automation AnalystEngesoftware Tecnologia S.A Dec 2020 - May 2021Brasília, Distrito Federal, BrasilFunctions and Responsibilities:Monitoring activities and analysis of error logs, receiving demands through the HP tool, and preparing reports for data conferences and audits.Maintenance and management of systems and services on Windows and Linux platforms.Administration and Operation of application server, Weblogic, APACHE, Jboss, WebSphere, Docker.Creation of automation scripts and queries.Mapping and Automation of processes.Management and execution of ETL maps.Messaging management in MQ channels. -
Information Security CoordinatorGlobal Hitss Mar 2016 - Apr 2018Rio De Janeiro E Região, BrasilFunctions and Responsibilities:- Responsible for supervising the support activities for users in the IT and Information Security areas, carrying out the development of implementation, development, and integration projects with the use of high technology.- Preparation of technical documentation, data dictionary, and system manuals, conducting technology research in informatics, guiding support areas, and engaging third-party support.- Coordination of activities within the high, intermediate, and low platform teams, aiming to evaluate and identify technological solutions.- Planning activities to meet customer and business needs.- Monitoring activities and analyzing error logs, receiving demands through the BMC Remedy tool, and preparing reports for conferences and data audits.- Execution of commands and procedures in z/OS partitions managing users, groups, and high platform systems using the RACF tool.- Creation of Dataset, profiles, and system protections, managing identity with SGR, Logical Access, and Control-AS tools. -
Mainframe OperatorCapgemini Sep 2010 - Nov 2013Brasília, Distrito Federal, BrasilFunctions and Responsibilities:- Execution of commands and procedures in ZOS/JES2 environments, file restoration using TSM tools.- Management of incidents using HP Service Manager 7.11.- Responsible for monitoring and operating the entire mainframe platform (consoles) and low platform (CCSBATCH, BACENJUD, and Scripts).- Access to sysouts through Control-M Enterprise Manager, creation of tables for job scheduling using Control-M Desktop.- Maintenance and creation of JCLs using TSO tool for editing and Control-M for execution.
Gilson Oliveira Skills
Gilson Oliveira Education Details
-
Computer Technology/Computer Systems Technology
Frequently Asked Questions about Gilson Oliveira
What company does Gilson Oliveira work for?
Gilson Oliveira works for Framework Digital
What is Gilson Oliveira's role at the current company?
Gilson Oliveira's current role is DevSecOps.
What schools did Gilson Oliveira attend?
Gilson Oliveira attended Esab - Escola Superior Aberta Do Brasil, Senac Df.
What skills is Gilson Oliveira known for?
Gilson Oliveira has skills like Redes De Computadores, Iso 27002, Etl, Git, Linux, Rede De Computadores, Green It, Microsoft Windows, Itil, Servidor Linux, Microsoft Sql Server, Json.
Not the Gilson Oliveira you were looking for?
-
-
Gilson Oliveira
Full Stack Developer | Javascript | React.Js | Node | React-Native | TypescriptJuiz De Fora, Mg -
Gilson Oliveira
São Paulo, Sp -
Gilson Oliveira
Santos, Sp2gmail.com, pepsico.com
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial