Carlos Carvalho
@decarvalhocarlos
Cybersecurity advisor specializing in GRC, security-by-design, and audit-ready control programs.
What I'm looking for
I am a cybersecurity and information security professional with 15+ years delivering governance, risk management, and audit-ready control programs across banking, telecom, and insurance sectors.
I translate frameworks such as ISO/IEC 27001, NIST, CIS and SOC 2 into pragmatic, evidence-based security requirements and act as a trusted advisor to project teams and enterprise architecture.
I lead threat and risk assessments, design security patterns for cloud and hybrid environments, and build repeatable artifacts and evidence libraries to streamline audit and compliance engagements.
I drive stakeholder alignment through concise risk narratives, executive dashboards, and prioritized remediation backlogs, and I have a track record of maturing SOC governance, detection tuning, and cross-functional delivery enablement.
Experience
Work history, roles, and key accomplishments
Senior Information Security Analyst
BOX Technology
Jul 2022 - Present (3 years 7 months)
Lead cyber risk and compliance for strategic initiatives, translating governance into project controls and architecture guardrails; conducted risk assessments and drove remediation to closure while delivering executive risk reporting.
Cyber Security Analyst
Intact
May 2021 - Jul 2022 (1 year 2 months)
Performed Tier 2 SOC incident triage and investigations across hybrid and cloud workloads; produced evidence packages, tuned detections to reduce false positives, and advised IAM/DLP stakeholders on control improvements.
Senior Information Security Analyst
BOX Technology
Jun 2019 - May 2021 (1 year 11 months)
Authored and operationalized InfoSec policies and SOC governance, onboarding 40+ log sources and improving detection and playbook consistency; embedded security-by-design in BRDs and HLAs for strategic projects.
Network Security Analyst
SecureOps Inc.
Feb 2019 - Jun 2019 (4 months)
Delivered multi-tenant SOC monitoring and investigations for MSSP clients, supporting telemetry onboarding, detection tuning, and incident response coordination with clear remediation guidance.
Cyber Security Analyst
Bell Canada
Dec 2017 - Feb 2019 (1 year 2 months)
Managed and audited 100+ firewall instances, enforced segmentation and access-control governance, and provided risk-based recommendations to reduce attack surface and support compliance checks.
IT Infrastructure Security Team Leader
HSBC Global Technology Center
Nov 2012 - Jul 2015 (2 years 8 months)
Led multi-region security operations and governance across Brazil, India, Malaysia, and China; standardized processes, coordinated vendor assessments and penetration testing, and built team capacity through hiring and mentoring.
Senior IT Security Analyst
HSBC Global Technology Center
Oct 2010 - Nov 2012 (2 years 1 month)
Operated core security controls including firewall, proxy and VPN governance; performed control reviews and coordinated remediation to maintain policy compliance and service resilience.
Education
Degrees, certifications, and relevant coursework
McGill University
Undergraduate Certificate, Applied Cybersecurity
Undergraduate certificate in Applied Cybersecurity currently in progress at McGill University.
Montreal College of IT
ACS Diploma, Networking and Technical Support
ACS Diploma in Networking and Technical Support completed in 2018.
AIPE
Advanced Diploma, IT Project Management
Advanced Diploma in IT Project Management completed in 2016.
Pontifical Catholic University of Paraná
Postgraduate Certificate, Network and Systems Security
Postgraduate certificate in Network and Systems Security completed in 2011.
FARESC
Graduate Diploma, Computer Networks
Graduate Diploma in Computer Networks completed in 2009.
Faculdades FaCiencia
Post-graduate (lato sensu), MBA in Artificial Intelligence Management and Governance
Faculdades FaCiencia
Post-graduate (lato sensu), MBA in Information Security Management
Faculdades FaCiencia
Post-graduate (lato sensu), MBA in Governance, Risk, and Compliance
Availability
Location
Salary expectations
Social media
Job categories
Skills
Interested in hiring Carlos?
You can contact Carlos and 90k+ other talented remote workers on Himalayas.
Message CarlosFind your dream job
Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
