Head of Engineering
This is a summary of the computer security engagements only. To access the full resume, including all non-security related engagements, please access the complete version at: go.lunenetworks.com/nelson/resume
For all the technologies listed below, I have first-hand experience with them. It means I used them thoroughly and achieved considerable proficiency, many used for years on these long-term projects.
20+ years of experience in security
Responsible for CIS 20, JSOX, ISO, SOC 2, and regulatory compliance.
Led security programs and initiatives at multiple Fortune 500 companies:
| Company | Group | Responsibilities |
|---|---|---|
![]() |
All Engineering | SOC2, cross-cloud security, bug bounty |
![]() |
Infrastructure Team | SOC2 |
![]() |
Security & Compliance Team | CIS20, Policy, Audits, Security Software |
![]() |
Security & Compliance Council | ISO 27001, PCI, Policy, Enforcement |
![]() |
Cloud Platform Security Group | Security Software |
![]() |
Security Business Unit | CISSP, Security Software |
![]() |
Brazil Presidential Elections | ISO 9001, Security Software |
Special security projects for the Brazilian government, financial sector, and military, including the application and network security of the Presidental Elections of Brazil.
15 patents filed, 4 in the security space
union.ai
sourcegraph.com
indeed.com
grab.com
google.com
microsoft.com
modulo.comArchitect and developer manager of Brazilian Presidential Elections security system, used in every voting booth, every district network computer and every processing hub across the country. Largest synchronized deployed system ever built at the time.
Featured case study by Microsoft, as the largest deployed network system to enforce security nationwide at technet.microsoft.com/en-us/library/cc750080.aspx
Participated in the design of ICP Brasil, the Brazilian government national official digital identity system based on X.509 certificates.
Threat analysis and mitigation of the heterogeneous government network that runs nationwide to support the elections
System level protection by interception of system calls using device drivers and other hooking mechanisms, file system, network, process and thread management, USB and modem protection and control.
Development of large deployment systems based on Windows technology to roll many of company products throughout the enterprise, supporting roll back and forward, lab and staged deployment, security and authentication for software authenticity and authorization
Cryptography: Developed transport level network encryption system for military and top-secret government purposes (agency is similar to USA’s NSA/CIA)
Financial System security: Designed the SPB (Brazilian Payment System) to Brazilian Central Bank, a system designed to secure, certified and undisputable cross-bank transactions. Thanks to this system in place, a TED from a bank to another in Brazil takes a couple of seconds to a couple of minutes max.
Designed and implemented various projects involving X.509, symmetric and asymmetric encryption, elliptic curves, El Gamal
Kernel <=> User mode fast communication & synchronization, ring 0-3 data/process synchronization
Architecture and lead development of He@tSeeker distributed firewall, used as a key security component during Brazilian Presidential Elections
Leader of company ISO 9001 certification focused on security lifecycle management by DNV. First certification of the kind awarded to a security company
Hardware cryptography: worked with various cryptography devices and HSM (hardware security module), from well-known vendors such as Aladdin crypto tokens, Gemplus smartcards and CryptoSystems HSM.
Worked with eTrust PKI product line, helping customers design, plan and roll installations and integrating with other Modulo’s security products and services
Worked with Verisign & Certisign to develop PKI solutions to customers
Developed early architecture and framework of award winning Modulo Risk Management software
Lune Networks (Owned Startup Company) lunenetworks.com iamazingapps.comMain architect of security developer products:
Head of NOC (Network Operating Center) for enterprise customers
Security consultant
Implementation of security solutions based on OpenVPN, OpenSSH, OpenSSL
Linux based hard disk software encryption solutions
infolink.com.br
(Owned Startup Company) obaweb.com.br
(National Research Center) cetem.gov.br
(Federal University of Rio de Janeiro) ufrj.br