David Cardoso
@davidcardoso
Cybersecurity Incident Response & SOC operations leader, reducing downtime and building AI-augmented, proactive cyber defense programs.
What I'm looking for
I’m a CISSP-certified cybersecurity professional with 6+ years in Incident Response, Cyber Defense Operations, and SOC operations. I’ve built hands-on, operational defenses that focus on rapid containment, eradication, and recovery—especially when the business can’t afford delays.
At Amgen (Tier 3 Incident Response), I led critical work that drastically reduced production downtime from 6 months to 1 day. I served as a key IR liaison during a global Swimlane to Turbine SOAR migration, automating playbooks for Cyber Defense Operations, and I led post-incident reviews and forensic analysis to drive vulnerability remediation.
I bring measurable outcomes to detection quality and threat discovery. My work reduced false-positive events from 40% to 10%, and I spearheaded threat hunting using Microsoft Copilot to uncover and remediate internal credential exposures, while also creating internal phishing campaigns to strengthen email security and employee awareness.
Earlier, I supported SOC teams at OutSystems and Multicert by implementing AWS security controls, building Splunk dashboards and metrics (improving detection by 33%), and using Microsoft Defender 365 for forensic investigations and email security enhancements. I also leveraged MISP threat intelligence, developed automation scripts and a vulnerability scraper for early warning, and supported security monitoring architecture with ArcSight and FortiSIEM—plus I founded CyberPlay to develop the D.A.V.I.D Engine, an AI system for adaptive incident response simulations in healthcare.
Experience
Work history, roles, and key accomplishments
Led Tier 3 incident response at Amgen, reducing manufacturing downtime from 6 months to 1 day. Served as an IR liaison during a Swimlane-to-Turbine SOAR migration, automating playbooks and cutting false-positive events from 40% to 10%.
Implemented AWS security controls and leveraged cyber threat intelligence to mitigate cloud risks. Built Splunk dashboards improving detection by 33% and used Microsoft Defender 365 for forensic investigations and email security enhancements.
SOC Analyst (Tier 1)
Multicert
Mar 2020 - Jul 2021 (1 year 4 months)
Used MISP threat intelligence to correlate threats and support Tier 1 SOC operations. Developed automation scripts and a vulnerability scraper for early warning and managed ArcSight and FortiSIEM to enhance security monitoring architecture.
Education
Degrees, certifications, and relevant coursework
North American University
Master of Business Administration, Business Administration
Pursuing an MBA at North American University, expected to complete in May 2026.
Universidade de Lisboa
Master of Science in Cybersecurity, Cybersecurity
2019 -
Studying Cybersecurity at Universidade de Lisboa, starting in November 2019.
Availability
Location
Authorized to work in
Portfolio
github.com/davidanil/publicJob categories
Interested in hiring David?
You can contact David and 90k+ other talented remote workers on Himalayas.
Message DavidFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
