{"id":32,"date":"2026-08-04T01:59:51","date_gmt":"2026-08-04T01:59:51","guid":{"rendered":"https:\/\/douglasrossetto.com.br\/projetos\/"},"modified":"2026-08-04T04:18:00","modified_gmt":"2026-08-04T04:18:00","slug":"projetos","status":"publish","type":"page","link":"https:\/\/douglasrossetto.com.br\/en\/projetos\/","title":{"rendered":"Projects"},"content":{"rendered":"<div style=\"padding:30px 40px;max-width:900px;margin:0 auto\">\n<p style=\"color:#718096;font-size:15px;line-height:1.6;margin:0 0 25px 0\">Projects that I implemented and operate at AKAD Seguros, aligned with strategic security and IT infrastructure modernization.<\/p>\n<div style=\"background:#1a202c;border:2px solid #63b3ed;border-radius:12px;padding:25px;margin-bottom:20px\">\n<h3 style=\"color:#63b3ed;font-size:20px;font-weight:700;margin:0 0 8px 0\">\ud83c\udfd7\ufe0f Information Security Area Construction \u2014 AKAD Seguros<\/h3>\n<p style=\"color:#a0aec0;font-size:11px;font-weight:700;letter-spacing:2px;margin:0 0 15px 0\">FOUNDATIONAL PROJECT \u00b7 2024 \u2013 PRESENT<\/p>\n<p style=\"color:#e2e8f0;font-size:15px;line-height:1.7;margin:0 0 18px 0\">Complete structuring of the Information Security area at AKAD Seguros <strong style=\"color:#ffffff\">do nothing<\/strong> \u2014 from the absence of formal processes to a mature SOC operation with full visibility, automation, and established governance.<\/p>\n<div style=\"padding-top:18px\">\n<p style=\"color:#63b3ed;font-size:13px;font-weight:700;margin:0 0 12px 0\">\ud83d\udcc8 What was built:<\/p>\n<ul style=\"font-size:14px;color:#cbd5e0;line-height:1.9;margin:0;padding-left:20px\">\n<li><strong style=\"color:#ffffff\">Operational SOC:<\/strong> Microsoft Sentinel implemented from scratch \u2014 analytical rules, automation playbooks, and daily L3 triage<\/li>\n<li><strong style=\"color:#ffffff\">Total visibility:<\/strong> Integration of Azure, AWS, Entra ID, Meraki, Cloudflare, and endpoint logs into a single dashboard<\/li>\n<li><strong style=\"color:#ffffff\">Zero Trust:<\/strong> Redesigned identity architecture \u2014 mandatory MFA, Conditional Access, Global Secure Access, and Identity Governance<\/li>\n<li><strong style=\"color:#ffffff\">Perimeter protection:<\/strong> Cloudflare Enterprise on 4 domains with WAF, DDoS, and custom rules<\/li>\n<li><strong style=\"color:#ffffff\">Automation:<\/strong> BUD Network with 60+ AI agents for SOC Autopilot, reports and automatic triage<\/li>\n<li><strong style=\"color:#ffffff\">Compliance:<\/strong> LGPD, CIS Controls, security policies, and company-wide awareness program<\/li>\n<li><strong style=\"color:#ffffff\">Governance:<\/strong> Vulnerability management processes, Shadow IT, EASM, and AWS exposure remediation<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div style=\"background-color:#ffffff;border:2px solid #2b6cb0;border-radius:12px;padding:22px 25px;margin-bottom:16px\">\n<h3 style=\"color:#2b6cb0;font-size:18px;font-weight:700;margin:0 0 4px 0\">\ud83d\udee1\ufe0f SOC \u2014 Microsoft Sentinel<\/h3>\n<p style=\"color:#a0aec0;font-size:11px;font-weight:700;letter-spacing:2px;margin:0 0 10px 0\">DETECTION &amp; RESPONSE<\/p>\n<p style=\"color:#4a5568;font-size:15px;line-height:1.6;margin:0\">Implementation and operation of a centralized SOC. Proactive detection, N3 analysis, playbook automation, and MTTR reduction. Daily triage of 13+ incidents with documented closure.<\/p>\n<\/div>\n<div style=\"background-color:#ffffff;border:2px solid #2b6cb0;border-radius:12px;padding:22px 25px;margin-bottom:16px\">\n<h3 style=\"color:#2b6cb0;font-size:18px;font-weight:700;margin:0 0 4px 0\">\ud83d\udd10 Zero Trust \u2014 Microsoft Entra ID<\/h3>\n<p style=\"color:#a0aec0;font-size:11px;font-weight:700;letter-spacing:2px;margin:0 0 10px 0\">IDENTITY &amp; ACCESS<\/p>\n<p style=\"color:#4a5568;font-size:15px;line-height:1.6;margin:0\">Corporate identity redesign with Zero Trust architecture. Conditional Access policies, mandatory MFA, and continuous monitoring of privileged accounts.<\/p>\n<\/div>\n<div style=\"background-color:#ffffff;border:2px solid #2b6cb0;border-radius:12px;padding:22px 25px;margin-bottom:16px\">\n<h3 style=\"color:#2b6cb0;font-size:18px;font-weight:700;margin:0 0 4px 0\">\ud83c\udf10 Microsoft Global Secure Access (ZTNA)<\/h3>\n<p style=\"color:#a0aec0;font-size:11px;font-weight:700;letter-spacing:2px;margin:0 0 10px 0\">ZTNA &amp; SECURE ACCESS<\/p>\n<p style=\"color:#4a5568;font-size:15px;line-height:1.6;margin:0\">Secure application access without traditional VPN, with granular control by identity, device, and location. Perimeter model replacement with context-based access.<\/p>\n<\/div>\n<div style=\"background-color:#ffffff;border:2px solid #2b6cb0;border-radius:12px;padding:22px 25px;margin-bottom:16px\">\n<h3 style=\"color:#2b6cb0;font-size:18px;font-weight:700;margin:0 0 4px 0\">Identity Governance \u2014 Microsoft Entra<\/h3>\n<p style=\"color:#a0aec0;font-size:11px;font-weight:700;letter-spacing:2px;margin:0 0 10px 0\">Identity Governance<\/p>\n<p style=\"color:#4a5568;font-size:15px;line-height:1.6;margin:0\">Access lifecycle, automated access reviews, secure onboarding\/offboarding, and just-in-time access policies. Control who has access to what \u2014 and why.<\/p>\n<\/div>\n<div style=\"background-color:#ffffff;border:2px solid #2b6cb0;border-radius:12px;padding:22px 25px;margin-bottom:16px\">\n<h3 style=\"color:#2b6cb0;font-size:18px;font-weight:700;margin:0 0 4px 0\">Cloudflare Enterprise \u2014 WAF &amp; DDoS<\/h3>\n<p style=\"color:#a0aec0;font-size:11px;font-weight:700;letter-spacing:2px;margin:0 0 10px 0\">WEB PERIMETER PROTECTION<\/p>\n<p style=\"color:#4a5568;font-size:15px;line-height:1.6;margin:0\">WAF on 4 AKAD domains, malicious scanner blocking, DDoS protection, and traffic analytics. Custom rules with bypass for legitimate partners.<\/p>\n<\/div>\n<div style=\"background-color:#ffffff;border:2px solid #2b6cb0;border-radius:12px;padding:22px 25px;margin-bottom:16px\">\n<h3 style=\"color:#2b6cb0;font-size:18px;font-weight:700;margin:0 0 4px 0\">\u2601\ufe0f Cloud Security Posture \u2014 AWS &amp; Azure<\/h3>\n<p style=\"color:#a0aec0;font-size:11px;font-weight:700;letter-spacing:2px;margin:0 0 10px 0\">CSPM &amp; HARDENING<\/p>\n<p style=\"color:#4a5568;font-size:15px;line-height:1.6;margin:0\">Continuous security posture management. Remediation of exposed Security Groups, Secure Score, GuardDuty, and compliance policies. Over 35 security groups remediated.<\/p>\n<\/div>\n<div style=\"background-color:#ffffff;border:2px solid #2b6cb0;border-radius:12px;padding:22px 25px;margin-bottom:16px\">\n<h3 style=\"color:#2b6cb0;font-size:18px;font-weight:700;margin:0 0 4px 0\">\ud83e\udd16 BUD Network \u2014 Corporate AI<\/h3>\n<p style=\"color:#a0aec0;font-size:11px;font-weight:700;letter-spacing:2px;margin:0 0 10px 0\">AUTOMATION &amp; AI<\/p>\n<p style=\"color:#4a5568;font-size:15px;line-height:1.6;margin:0\">Architecture of 60+ specialized AI agents. Security task automation, email triage, Shadow IT reports, and SOC Autopilot integrated into Sentinel.<\/p>\n<\/div>\n<div style=\"background-color:#ffffff;border:2px solid #2b6cb0;border-radius:12px;padding:22px 25px;margin-bottom:16px\">\n<h3 style=\"color:#2b6cb0;font-size:18px;font-weight:700;margin:0 0 4px 0\">\ud83d\udcca Shadow IT &amp; EASM<\/h3>\n<p style=\"color:#a0aec0;font-size:11px;font-weight:700;letter-spacing:2px;margin:0 0 10px 0\">VISIBILITY &amp; CONTROL<\/p>\n<p style=\"color:#4a5568;font-size:15px;line-height:1.6;margin:0\">Discovery of Shadow IT via Microsoft Defender for Endpoint. Monthly reports by category (AI, cloud, webmail, BYOD) and external attack surface reconnaissance.<\/p>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Projetos que implementei e opero na AKAD Seguros, alinhados com seguran\u00e7a estrat\u00e9gica e moderniza\u00e7\u00e3o da infraestrutura de TI. \ud83c\udfd7\ufe0f Constru\u00e7\u00e3o da \u00c1rea de Seguran\u00e7a da Informa\u00e7\u00e3o \u2014 AKAD Seguros PROJETO FUNDACIONAL \u00b7 2024 \u2013 PRESENTE Estrutura\u00e7\u00e3o completa da \u00e1rea de Seguran\u00e7a da Informa\u00e7\u00e3o da AKAD Seguros do zero \u2014 desde a aus\u00eancia de processos formais&#8230;<\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"pagelayer_contact_templates":[],"_pagelayer_content":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"class_list":["post-32","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/douglasrossetto.com.br\/en\/wp-json\/wp\/v2\/pages\/32","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/douglasrossetto.com.br\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/douglasrossetto.com.br\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/douglasrossetto.com.br\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/douglasrossetto.com.br\/en\/wp-json\/wp\/v2\/comments?post=32"}],"version-history":[{"count":4,"href":"https:\/\/douglasrossetto.com.br\/en\/wp-json\/wp\/v2\/pages\/32\/revisions"}],"predecessor-version":[{"id":77,"href":"https:\/\/douglasrossetto.com.br\/en\/wp-json\/wp\/v2\/pages\/32\/revisions\/77"}],"wp:attachment":[{"href":"https:\/\/douglasrossetto.com.br\/en\/wp-json\/wp\/v2\/media?parent=32"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}