Projects that I implemented and operate at AKAD Seguros, aligned with strategic security and IT infrastructure modernization.
🏗️ Information Security Area Construction — AKAD Seguros
FOUNDATIONAL PROJECT · 2024 – PRESENT
Complete structuring of the Information Security area at AKAD Seguros do nothing — from the absence of formal processes to a mature SOC operation with full visibility, automation, and established governance.
📈 What was built:
- Operational SOC: Microsoft Sentinel implemented from scratch — analytical rules, automation playbooks, and daily L3 triage
- Total visibility: Integration of Azure, AWS, Entra ID, Meraki, Cloudflare, and endpoint logs into a single dashboard
- Zero Trust: Redesigned identity architecture — mandatory MFA, Conditional Access, Global Secure Access, and Identity Governance
- Perimeter protection: Cloudflare Enterprise on 4 domains with WAF, DDoS, and custom rules
- Automation: BUD Network with 60+ AI agents for SOC Autopilot, reports and automatic triage
- Compliance: LGPD, CIS Controls, security policies, and company-wide awareness program
- Governance: Vulnerability management processes, Shadow IT, EASM, and AWS exposure remediation
🛡️ SOC — Microsoft Sentinel
DETECTION & RESPONSE
Implementation and operation of a centralized SOC. Proactive detection, N3 analysis, playbook automation, and MTTR reduction. Daily triage of 13+ incidents with documented closure.
🔐 Zero Trust — Microsoft Entra ID
IDENTITY & ACCESS
Corporate identity redesign with Zero Trust architecture. Conditional Access policies, mandatory MFA, and continuous monitoring of privileged accounts.
🌐 Microsoft Global Secure Access (ZTNA)
ZTNA & SECURE ACCESS
Secure application access without traditional VPN, with granular control by identity, device, and location. Perimeter model replacement with context-based access.
Identity Governance — Microsoft Entra
Identity Governance
Access lifecycle, automated access reviews, secure onboarding/offboarding, and just-in-time access policies. Control who has access to what — and why.
Cloudflare Enterprise — WAF & DDoS
WEB PERIMETER PROTECTION
WAF on 4 AKAD domains, malicious scanner blocking, DDoS protection, and traffic analytics. Custom rules with bypass for legitimate partners.
☁️ Cloud Security Posture — AWS & Azure
CSPM & HARDENING
Continuous security posture management. Remediation of exposed Security Groups, Secure Score, GuardDuty, and compliance policies. Over 35 security groups remediated.
🤖 BUD Network — Corporate AI
AUTOMATION & AI
Architecture of 60+ specialized AI agents. Security task automation, email triage, Shadow IT reports, and SOC Autopilot integrated into Sentinel.
📊 Shadow IT & EASM
VISIBILITY & CONTROL
Discovery of Shadow IT via Microsoft Defender for Endpoint. Monthly reports by category (AI, cloud, webmail, BYOD) and external attack surface reconnaissance.