Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Work Availability
Timeline
Cyber Security Conferences
Cyber Security Conferences
Generic

Rui Gonçalves

Prague,Prague

Summary

I am a dedicated, organized and methodical individual. I have good interpersonal skills, am an excellent team worker and am keen and very willing to learn and develop new skills. I am reliable and dependable and often seek new responsibilities within a wide range of employment areas. I have an active and dynamic approach to work and getting things done. I am determined and decisive. I identify and develop opportunities.

Overview

18
18
years of professional experience
6
6
years of post-secondary education
2
2
Certificates
5
5
Languages

Work History

Application Security Risks Analyst

European Space Agency (ESA) (6 Months contract)
Remote
06.2022 - Current
  • Undertaking low-complexity routine vulnerability assessments using automated and semiautomated tools and escalates issues where appropriate.
  • Contribute to documenting the scope and evaluating results of vulnerability assessments.
  • Performing vulnerability assessments and business impact analysis for medium complexity information systems.
  • Contribute to selection and deployment of vulnerability assessment tools and techniques.
  • Plan and manages vulnerability assessment activities within organisation.
  • Evaluate and select, reviews vulnerability assessment tools and techniques.
  • Obtain and act on vulnerability information and conducts security risk assessments, business impact analysis and accreditation on complex information systems.
  • Maintain a Risk Register - logging risks & vulnerabilities etc

Head of Security

Confidential (Stealth mode Start up wannabe)
Zurique
09.2021 - 05.2022
  • Overseeing security of development and operations of a prototype while integrating with Partners which includes but not only:
  • Oversee security of development and operations of the platform while integrating with Partners
  • Provide current best practice security measures for protection, intervention, and remediation of security events
  • Operational environment is in a cloud (Google Cloud Platform)
  • Meeting regulatory oversight and objectives yet to be set by Partners.

Technical Security Consultant

Huld
Prague
05.2021 - 11.2021
  • Security analysis of customer’s system environments and products
  • Execution of system-related attack surface mapping and technical testing against customer’s target systems.
  • Facilitating technical threat modelling workshops and risk assessment workshops
  • Planning blackbox or white box testing countermeasures and finding security vulnerabilities in customer systems.
  • Writing security assessment reports that include description of the tests and vulnerabilities and recommendations.
  • Identification and troubleshooting bugs in existing software/design;
  • Designing security features within the software based on requirements, standards and processes;
  • Technical security consultancy work with new and actual customers in the fields of Technical Testing, Security Management and/or Cloud Security

Ethical Hacker/Red Team

Trend Micro
09.2019 - 04.2021
  • Vulnerability/attack scenario reproduction to ensure the attack is well understood and well protected against
  • Carry out testing with exploit PoCs, viruses, Metasploit and other • exploit tools.
  • Review for flaws in the rule and relevant codes which have a tendency of being logical/state/detail oriented
  • Implement and design small-scale to medium-scale automation in order to simplify testing tasks, improve and assure the best quality using Perl, python, ruby etc.
  • Vulnerability scanner execution & results analysis

Cloud Security Engineer

Symantec
Prague
11.2016 - 08.2019
  • Creating cloud-based programs (implementing identity and access management and securely configuring cloud environments)
  • Detect possible risk through threat simulation and penetration tests
  • Managing encryption of data in the cloud
  • Logging, monitoring, and responding to detected incidents in the cloud environment
  • Provide security recommendation

Network IPT Engineer

AT&T
04.2011 - 10.2016
  • Cisco Voice troubleshooting, Remote Desktop connection Manager, Cisco Unified CM Administration.
  • Internetworking Devices – Routing, Switching, Sub Netting
  • Direct technical support for all products delivered in this 24/7 telephony and voice environment
  • Actively troubleshooting complex incidents and implementing break/fix changes on CUCM, Voicemail and Analog VG issues

Network Operations Team Leader

Portugal Telecom
08.2010 - 03.2011
  • Responsibility for direct supervision of NOC team members
  • Conduct Performance Appraisals, coaching, training and objective • settings.
  • Provide direction and leadership to build process-focused, cross-functional team.
  • Manage scheduling of shift coverage and operational work streams to optimize service delivery.
  • Address technical and non-technical escalations
  • Report on key metrics of availability, incident resolution and service delivery performance.
  • Manage and document Standards, Policies, and Processes for the NOC.
  • Perform regular process improvement reviews to ensure ongoing optimization

NOC Engineer

Portugal Telecom
07.2009 - 07.2010
  • Assemble project plans and budgets as well as teamwork assignments, directing and monitoring
  • Work efforts on a daily basis, identifying resource needs and performing quality review.
  • Direct management of technical projects, including new service deployment and existing network augmentations/upgrades.
  • Escalate functional, quality and timeline issues appropriately.
  • Technical customer service and consulting support

Penetration Tester (white Hat Hacker)

Freelancer
01.2004 - 06.2009

• Carry out application, network, systems and infrastructure penetration tests

• Review physical security and perform social engineering tests where appropriate

• Evaluate and select from a range of penetration testing tools

• Keep up to date with latest testing and ethical hacking methods

• Deploy the testing methodology and collect data

• Report on findings to a range of stakeholders

• Make suggestions for security improvements

• Enhance existing methodology material


*Collaboration with Companies mainly startups such as: Insighti (www.insighti.com); Spreenauten

(www.spreenauten.com); Ftmo (ftmo.com)

Education

Associate of Science - Informatics

COMENIUS UNVERSITY BRATISLAVA
Bratislava
09.2008 - 06.2009

Bachelor of Science - Engineering Technology

INSTITUTO POLITECNICO DE BRAGANZA
Braganza
09.2001 - 06.2007

Skills

    Penetration Testing

undefined

Accomplishments

    Project about Carbanak and FIN7 Attack Techniques published


Certification

Reverse Engineering U.S. Department of Homeland Security)

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Timeline

Reverse Engineering U.S. Department of Homeland Security)

10-2022

Application Security Risks Analyst

European Space Agency (ESA) (6 Months contract)
06.2022 - Current

Head of Security

Confidential (Stealth mode Start up wannabe)
09.2021 - 05.2022

Technical Security Consultant

Huld
05.2021 - 11.2021

Ethical Hacker/Red Team

Trend Micro
09.2019 - 04.2021

Certified Ethical Hacker (EC-Council) ECC0961372485

06-2019

Cloud Security Engineer

Symantec
11.2016 - 08.2019

Network IPT Engineer

AT&T
04.2011 - 10.2016

Network Operations Team Leader

Portugal Telecom
08.2010 - 03.2011

NOC Engineer

Portugal Telecom
07.2009 - 07.2010

Associate of Science - Informatics

COMENIUS UNVERSITY BRATISLAVA
09.2008 - 06.2009

Penetration Tester (white Hat Hacker)

Freelancer
01.2004 - 06.2009

Bachelor of Science - Engineering Technology

INSTITUTO POLITECNICO DE BRAGANZA
09.2001 - 06.2007

Cyber Security Conferences

2020-10 Grayhat Cyber Conference


2020-10 2020 Security Conference


2019-10 Hacker Halted

Cyber Security Conferences

2020-10 Grayhat Cyber Conference


2020-10 2020 Security Conference


2019-10 Hacker Halted

Rui Gonçalves