Caio Henrique
I'm Caio Henrique, a Cybersecurity Analyst with 6+ years of experience protecting corporate environments through a blend of offensive (Red Team) and defensive (Blue Team) strategies.
I specialize in Vulnerability Management, DevSecOps, and Security Automation, with proven expertise in deploying and managing SIEM, EDR, and XDR solutions. By leveraging frameworks such as MITRE ATT&CK, CIS Controls, and ISO 27001, I help organizations strengthen their detection, response, and overall security posture.
Currently, I focus on:
- Automating and orchestrating security processes to scale efficiency.
- Identifying, prioritizing, and remediating vulnerabilities across environments.
- Continuous monitoring and incident response to reduce risk exposure.
- Hardening infrastructure and applying best practices for resilience.
My mission is simple: to anticipate threats, reduce risks, and deliver security-driven solutions that enable organizations to grow with confidence.
Experience
Cybersecurity Analyst • DevSecOps
Design and optimize DevSecOps pipelines, seamlessly integrating security into CI/CD workflows.
Automate security operations and proactively manage vulnerabilities across complex environments.
Detect, analyze, and respond to threats using advanced SIEM, EDR, and XDR platforms.
Implement offensive and defensive strategies, hardening Windows/Linux servers using CIS Controls, MITRE
ATT&CK, and ISO 27001 frameworks.
Cybersecurity Engineer
With extensive experience in network and system administration and security, my focus is on protecting physical and virtual servers with robust cybersecurity practices. I specialize in virtualization platforms like VMware, Hyper-V, and VirtualBox, and in penetration testing and security audits to mitigate vulnerabilities. I have expertise in Identity and Access Management (IAM), ensuring effective access controls. I use tools such as Zabbix, Grafana, Wireshark, and Wazuh for continuous monitoring and incident response, always seeking to implement best practices and enhance infrastructure protection.
Junior Infrastructure Analyst
I managed and maintained networks and systems to ensure efficiency and security. I gained experience in configuring and supporting network devices and servers, monitoring performance for quick problem resolution. I implemented security practices using tools such as Zabbix, Grafana, Dnsenum, Nessus, Wireshark, and Wazuh. I administered Windows and Linux servers, applied security patches, and monitored logs for suspicious activities. I also contributed to cybersecurity awareness by developing and conducting training on best practices. I consistently sought to expand my skills and face new challenges to enhance system security and performance.
Information Security Analyst
In my role, I managed and configured tools like Zabbix and Grafana for network monitoring and real-time security alerts. I deployed and monitored firewalls and VPNs to protect corporate networks from threats. I handled Identity and Access Management (IAM), ensuring effective access controls. I identified and addressed vulnerabilities using tools like Dnsenum, Nessus, Wireshark, and Wazuh. I managed Windows and Linux servers, applied patches, and monitored logs for suspicious activities. Additionally, I developed and conducted cybersecurity training, creating materials to educate the team on best practices.
Junior Support Analyst
As a Support Technician, I specialized in computer assembly and maintenance. I assembled and configured hardware like motherboards, processors, memory, and hard drives for optimal performance. I installed and configured operating systems and software, adjusting settings for security and user needs. I diagnosed and resolved hardware and software issues, from system failures to compatibility problems. I provided technical support, performed maintenance, updated components, and optimized system performance. I also conducted tests to ensure proper system functionality.
Projects
Note: These projects are complete and currently undergoing restructuring. I’m enhancing documentation and case studies to better showcase the scope and impact of each initiative.
Snyk Golang Scanner
Custom vulnerability scanner for Golang applications with Snyk integration and reporting.
View Project
Infrastructure Vulnerability Dashboard
An automated system for continuous infrastructure vulnerability scanning, reporting, and remediation orchestration.
View Project
Linux Hardening
System hardening for Linux servers aligned with CIS Benchmarks and MITRE ATT&CK, featuring automated auditing and remediation.
View Project
Vulnerability Management
An integrated platform for identifying, prioritizing, and remediating security vulnerabilities in real-time.
View Project
EDR/XDR Endpoint
Advanced endpoint detection and response system with extended detection capabilities for comprehensive threat hunting.
View Project
SIEM
Advanced cybersecurity monitoring and analysis system with real-time threat detection capabilities.
View Project
Network Monitoring
A scalable solution for real-time network monitoring, featuring automated alerts and performance dashboards.
View ProjectVulnerability Management Forum
Collaborative platform for vulnerability tracking, discussion, and remediation coordination.
View ProjectCloud Vulnerabilities
Cloud pentesting leveraging a custom-built tool and AWS Inspector to map findings and prioritize remediation.
View ProjectInfrastructure Tools
A collection of automation tools for infrastructure provisioning, compliance, and observability.
View ProjectPhishing Campaign
Planning and execution of simulated phishing campaigns to assess and strengthen employee security awareness.
View ProjectSecurity Page
Comprehensive security dashboard with threat intelligence and compliance monitoring.
View ProjectVulnerability Reduction Process
Linux kernel-focused vulnerability reduction process with SentinelOne integration and cyber vulnerability dashboard.
View Project
SIEM Implementation & Optimization
Design, deployment, and fine-tuning of a SIEM solution for centralized log management and real-time threat detection.
View Project
EDR/XDR Deployment & Threat Hunting
Implementation and management of EDR/XDR solutions for advanced endpoint protection and proactive threat hunting.
View ProjectCoding Skills
85%
Python
80%
Golang
85%
Shell Script
65%
Ruby
75%
PowerShell
70%
C++
75%
C#
85%
HTML5
85%
CSS
70%
Javascript
70%
MySQL
60%
PHP
Education
loading
BACHELOR'S DEGREE - SOFTWARE ENGINEERING.
Software Engineering is a course that combines computer science and engineering principles to develop, test, and maintain high-quality software systems. Students learn to design efficient solutions, create robust and scalable software, and develop skills in areas such as algorithms, information security, and project management. The program prepares professionals to work in various industries and provides a solid foundation for careers in software development and information technology.
Completed Successfullyd
Systems Development Analyst - Technologist
The Systems Analysis and Development program taught me how to develop and maintain software systems, from analysis and design to implementation. I learned programming, working with databases, and using agile methodologies, which prepared me to create technological solutions that meet real business needs. With this education, I am ready to work in various IT fields, whether in software development, consulting, or project management.
Completed Successfullyd
Computer Networks Technician - Technologist
The Technical Course in Computer Networks offers comprehensive training in network architecture, with a focus on IoT, programming, and information security. It covers requirement gathering, agile methodologies, as well as the configuration and maintenance of network infrastructures. Operating systems, network services, monitoring techniques, and automation are addressed to ensure efficient and secure network management.
Certifications
CRTA - Certified Red Team Analyst
Jul 2024Validates advanced skills in Red Team operations, focusing on simulating real-world attacks to test and improve organizational security posture.
Cisco - Ethical Hacking
Aug 2024Provides expertise in offensive security methodologies within enterprise network environments, focusing on identifying vulnerabilities in Cisco devices.
EC-Council - CERTIFIED ETHICAL HACKER (CEH)
In ProgressDemonstrates expertise in identifying and fixing security vulnerabilities in systems and networks, using the same techniques as malicious hackers.
CompTIA Security+ (SY0-701)
In ProgressA globally recognized certification validating essential knowledge for threat identification, risk management, and incident response.
Cisco - (CCST) Certified Support Technician Cybersecurity
In ProgressValidates foundational knowledge in cybersecurity, covering basic security concepts, threat management, and technical support.
Cisco - (CCST) Certified Support Technician Networking
In ProgressDesigned for professionals who want to validate their fundamental networking skills, including OSI/TCP-IP models and IP addressing.
LPIC-1 Certification
In ProgressValidates fundamental knowledge in Linux system administration, covering installation, configuration, and package management.
EC-Council - Ethical Hacking Essentials (EHE)
Jan 2024Certifies foundational knowledge in ethical hacking, focusing on threat identification and secure practices.
CISCO - Introduction to Cybersecurity
Feb 2024Provides a foundational understanding of cybersecurity, covering essential topics such as common cyber threats and basic protective measures.
Solyd - Introduction to Hacking and Pentest 2.0
May 2024Offers a comprehensive introduction to ethical hacking and penetration testing methodologies and tools.
Udemy - Certified Ethical Hacker (CEH)
Apr 2024In-depth knowledge of ethical hacking techniques, focusing on identifying and mitigating security threats.
Udemy - SOC - Threat Hunting
Apr 2024Focuses on techniques and methodologies for proactive threat detection and response within a Security Operations Center (SOC).
Udemy - SIEM - EDR e XDR
Jun 2024Comprehensive understanding of SIEM, EDR, and XDR, covering deployment, configuration, and management of these critical security tools.
SkillFront - ISO/IEC 27001
Feb 2023Covers the principles and practices of implementing and maintaining an Information Security Management System (ISMS).
Udemy - Wireshark Analyzing Network Attacks
Jun 2024Hands-on training in using Wireshark for network analysis and attack detection, covering how to capture, analyze, and interpret network traffic.
Get in Touch
I'm always open to discussing new projects, creative ideas, or opportunities to be part of your vision. Feel free to reach out.
caiohenriquesinger@gmail.com
Click to copyPhone
+55 (47) 99665-1207
Click to copyLocation
Joinville, SC - Brazil