Himalayas logo
Carlos CarvalhoCC
Looking for a job

Carlos Carvalho

@decarvalhocarlos

Cybersecurity advisor specializing in GRC, security-by-design, and audit-ready control programs.

Canada
Message

What I'm looking for

I seek roles where I can embed GRC into delivery, design scalable security patterns, lead risk assessments, and produce audit-ready evidence while partnering with architecture and executive stakeholders.

I am a cybersecurity and information security professional with 15+ years delivering governance, risk management, and audit-ready control programs across banking, telecom, and insurance sectors.

I translate frameworks such as ISO/IEC 27001, NIST, CIS and SOC 2 into pragmatic, evidence-based security requirements and act as a trusted advisor to project teams and enterprise architecture.

I lead threat and risk assessments, design security patterns for cloud and hybrid environments, and build repeatable artifacts and evidence libraries to streamline audit and compliance engagements.

I drive stakeholder alignment through concise risk narratives, executive dashboards, and prioritized remediation backlogs, and I have a track record of maturing SOC governance, detection tuning, and cross-functional delivery enablement.

Experience

Work history, roles, and key accomplishments

BT
Current

Senior Information Security Analyst

BOX Technology

Jul 2022 - Present (3 years 7 months)

Lead cyber risk and compliance for strategic initiatives, translating governance into project controls and architecture guardrails; conducted risk assessments and drove remediation to closure while delivering executive risk reporting.

IN

Cyber Security Analyst

Intact

May 2021 - Jul 2022 (1 year 2 months)

Performed Tier 2 SOC incident triage and investigations across hybrid and cloud workloads; produced evidence packages, tuned detections to reduce false positives, and advised IAM/DLP stakeholders on control improvements.

SI

Network Security Analyst

SecureOps Inc.

Feb 2019 - Jun 2019 (4 months)

Delivered multi-tenant SOC monitoring and investigations for MSSP clients, supporting telemetry onboarding, detection tuning, and incident response coordination with clear remediation guidance.

HC

Senior IT Security Analyst

HSBC Global Technology Center

Oct 2010 - Nov 2012 (2 years 1 month)

Operated core security controls including firewall, proxy and VPN governance; performed control reviews and coordinated remediation to maintain policy compliance and service resilience.

Education

Degrees, certifications, and relevant coursework

McGill University logoMU

McGill University

Undergraduate Certificate, Applied Cybersecurity

Undergraduate certificate in Applied Cybersecurity currently in progress at McGill University.

MI

Montreal College of IT

ACS Diploma, Networking and Technical Support

ACS Diploma in Networking and Technical Support completed in 2018.

AI

AIPE

Advanced Diploma, IT Project Management

Advanced Diploma in IT Project Management completed in 2016.

Pontifical Catholic University of Paraná logoPP

Pontifical Catholic University of Paraná

Postgraduate Certificate, Network and Systems Security

Postgraduate certificate in Network and Systems Security completed in 2011.

FA

FARESC

Graduate Diploma, Computer Networks

Graduate Diploma in Computer Networks completed in 2009.

Faculdades FaCiencia logoFF

Faculdades FaCiencia

Post-graduate (lato sensu), MBA in Artificial Intelligence Management and Governance

Faculdades FaCiencia logoFF

Faculdades FaCiencia

Post-graduate (lato sensu), MBA in Information Security Management

Faculdades FaCiencia logoFF

Faculdades FaCiencia

Post-graduate (lato sensu), MBA in Governance, Risk, and Compliance

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Carlos Carvalho - Senior Information Security Analyst - BOX Technology | Himalayas