Projects

Projects that I implemented and operate at AKAD Seguros, aligned with strategic security and IT infrastructure modernization.

🏗️ Information Security Area Construction — AKAD Seguros

FOUNDATIONAL PROJECT · 2024 – PRESENT

Complete structuring of the Information Security area at AKAD Seguros do nothing — from the absence of formal processes to a mature SOC operation with full visibility, automation, and established governance.

📈 What was built:

  • Operational SOC: Microsoft Sentinel implemented from scratch — analytical rules, automation playbooks, and daily L3 triage
  • Total visibility: Integration of Azure, AWS, Entra ID, Meraki, Cloudflare, and endpoint logs into a single dashboard
  • Zero Trust: Redesigned identity architecture — mandatory MFA, Conditional Access, Global Secure Access, and Identity Governance
  • Perimeter protection: Cloudflare Enterprise on 4 domains with WAF, DDoS, and custom rules
  • Automation: BUD Network with 60+ AI agents for SOC Autopilot, reports and automatic triage
  • Compliance: LGPD, CIS Controls, security policies, and company-wide awareness program
  • Governance: Vulnerability management processes, Shadow IT, EASM, and AWS exposure remediation

🛡️ SOC — Microsoft Sentinel

DETECTION & RESPONSE

Implementation and operation of a centralized SOC. Proactive detection, N3 analysis, playbook automation, and MTTR reduction. Daily triage of 13+ incidents with documented closure.

🔐 Zero Trust — Microsoft Entra ID

IDENTITY & ACCESS

Corporate identity redesign with Zero Trust architecture. Conditional Access policies, mandatory MFA, and continuous monitoring of privileged accounts.

🌐 Microsoft Global Secure Access (ZTNA)

ZTNA & SECURE ACCESS

Secure application access without traditional VPN, with granular control by identity, device, and location. Perimeter model replacement with context-based access.

Identity Governance — Microsoft Entra

Identity Governance

Access lifecycle, automated access reviews, secure onboarding/offboarding, and just-in-time access policies. Control who has access to what — and why.

Cloudflare Enterprise — WAF & DDoS

WEB PERIMETER PROTECTION

WAF on 4 AKAD domains, malicious scanner blocking, DDoS protection, and traffic analytics. Custom rules with bypass for legitimate partners.

☁️ Cloud Security Posture — AWS & Azure

CSPM & HARDENING

Continuous security posture management. Remediation of exposed Security Groups, Secure Score, GuardDuty, and compliance policies. Over 35 security groups remediated.

🤖 BUD Network — Corporate AI

AUTOMATION & AI

Architecture of 60+ specialized AI agents. Security task automation, email triage, Shadow IT reports, and SOC Autopilot integrated into Sentinel.

📊 Shadow IT & EASM

VISIBILITY & CONTROL

Discovery of Shadow IT via Microsoft Defender for Endpoint. Monthly reports by category (AI, cloud, webmail, BYOD) and external attack surface reconnaissance.