Skip to content
View a-bonfim-tech's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report a-bonfim-tech

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
a-bonfim-tech/README.md

André Bonfim — Cybersecurity, Secure AI, Cloud Security, IAM, Security Automation and Governance

André Luiz Vieira Bonfim

Security Engineering · Detection Engineering · Secure AI · Security Automation
Berlin, Germany · Evidence-driven engineering with explicit claim boundaries

LinkedIn · TryHackMe · Coursera

Professional Profile

Cybersecurity professional based in Berlin focused on security engineering, detection engineering, Secure AI and security automation.

I build security work around a consistent engineering principle: claims should be supported by reproducible technical evidence, explicit scope, documented limitations, traceable decisions and human accountability. My portfolio therefore emphasizes not only what a system can do, but also who is authorized to act, under which boundaries, how the action is verified and what evidence remains afterward.

My practical work includes a tested segmented private-cloud homelab, officer-bound AI-agent authorization architecture, governed Python SDK engineering, security/compliance automation and SOC-oriented network analysis.

Professional Cybersecurity Training — Completion Certificate

MSIT GmbH — Master School Institute of Technology

Certificate field Official information
Course Cybersecurity Bootcamp
Duration 2,720 instructional hours · June 3, 2025 – August 3, 2026
Specialization Security Operations Center Analysis
Internship 8 weeks · 320 hours
Credential ID 43529502854875
Issue Date July 28, 2026

The course title Cybersecurity Bootcamp and specialization Security Operations Center Analysis are preserved exactly as stated on the completion certificate; descriptive German labels from the certificate are rendered here in English for consistency across the profile.

Selected curriculum documented on the certificate
  • IT Support Fundamentals: Hardware, Software, Networking Troubleshooting
  • Operating Systems: Windows & Linux Administration
  • Network Architecture & Security: Firewalls, VPNs and Segmentation
  • Cyber Threats Vulnerabilities & Mitigation Strategies
  • Security Tools: SIEM, EDR, Packet Analysis, Forensics Basics
  • Risk Management Governance & Compliance: NIST, ISO, GDPR, HIPAA
  • Identity & Access Management (IAM): MFA and Authentication Protocols
  • Data Security: Encryption, PKI and Secure Disposal Practices
  • System Hardening, Patch Management and Secure Configurations
  • Intro to SQL, Bash, Python Scripting and Automation
  • Incident Response, Business Continuity and Disaster Recovery
  • Virtualization & Cloud Fundamentals: IaaS, SaaS, VMs and Containers
  • Advanced Network Design and Troubleshooting
  • Network Defense and Secure Architecture
  • Solo Project: Secure Network Implementation and Monitoring
  • Internship: 8 weeks, 320 hours

Flagship Portfolio — Recruiter Fast Path

These are the six repositories I recommend reviewing first. They are deliberately ordered to demonstrate complementary evidence across security infrastructure, Secure AI, software engineering, GRC and detection work.

Priority Project Primary hiring signal
#1 Cybersecurity Private Cloud Homelab Native FreeBSD PF segmentation evidence, Suricata and Wazuh detection tests, IaC, threat modeling, evidence integrity and explicit deployment limits.
#2 Officer-Bound Digital Investigation Agent Secure AI authorization, human accountability, IAM boundaries, threat modeling, tested Go reference implementation and governed evidence.
#3 Bonfim SDK Governed Python SDK with strict typing, tests, SAST, SBOM, secret scanning, packaging and build provenance.
#4 AI SaaS Security & Compliance Fit-Gap TypeScript security/compliance automation spanning NIST CSF, ISO 27001, SOC 2, GDPR, EU AI Act and OWASP-oriented evidence assessment.
#5 Gemini Security Engineering Study Lab Tested synthetic event correlation with human validation, AI-risk controls and explicit separation between learned, demonstrated and unproven claims.
#6 TShark SOC Case Study Authorized network-forensics study covering phishing, HTTP analysis, IOC extraction and threat-intelligence correlation.

For role-specific navigation and the wider repository classification, see PORTFOLIO_INDEX.md.

Recruiter Snapshot — Evidence I Can Show

Domain Evidence represented in the portfolio
Secure AI & Agent Security Human-bound authorization, default-deny execution, agent governance, secure automation and explicit authority boundaries
Cloud Security Azure and Google Cloud controls, IAM, network exposure, encryption, logging, monitoring and risk decisions
Identity & Access Management MFA, privileged access, least privilege, RBAC/ABAC, Zero Trust and identity-first security models
Security Operations Network traffic analysis, IOC extraction, investigation structure, SIEM concepts and incident-response fundamentals
Security Governance / GRC Control assessment, evidence management, audit readiness, risk communication, GDPR, ISO 27001 and NIST-aligned reasoning
DevSecOps / Supply Chain GitHub Actions, CodeQL, SAST, SBOM, vulnerability scanning, secret detection, branch protection and provenance
Security Automation Python, TypeScript, Bash and deterministic evidence/report generation

Practical Experience — Panos.AI

Cybersecurity Intern — Berlin
8 weeks · 320 hours

  • Assessed and documented cloud-security controls focused on encryption, IAM, logging, monitoring, backup and recovery.
  • Supported GDPR and ISO/IEC 27001-oriented compliance activities through evidence collection and technical control validation.
  • Reviewed TLS 1.3, HTTPS/HSTS and Microsoft Azure Storage encryption controls.
  • Evaluated MFA, privileged access, audit trails and monitoring controls.
  • Contributed to audit-ready technical documentation and Git-based review workflows.

Selected Technical Skills

Python · Go · TypeScript · Bash · Microsoft Azure · Google Cloud · IAM · MFA · Zero Trust · TLS 1.3 · PKI · GitHub Actions · CodeQL · SBOM · SAST · TShark · Wireshark · Nmap · Linux · Security Automation · Threat Modeling

Frameworks and Methods

GDPR · ISO/IEC 27001 fundamentals · NIST Cybersecurity Framework 2.0 · SOC 2 concepts · EU AI Act · OWASP · OWASP WSTG · OWASP Top 10 · PTES

Selected Credentials and Learning Evidence

  • MSIT — Cybersecurity Bootcamp — 2,720 instructional hours — Security Operations Center Analysis
  • Google Cybersecurity Professional Certificate
  • Security in Google Cloud coursework and specialization certificates
  • Google Cloud networking and Cloud NGFW training
  • Generative AI: Governance, Policy, and Emerging Regulation — University of Michigan
  • TryHackMe cybersecurity labs and learning paths

Portfolio Evidence Standard

Every anchor project should make the following clear:

  1. Scope and authorization
  2. Individual contribution
  3. Methodology and tools
  4. Reproducible execution or validation steps
  5. Technical evidence and findings
  6. Risk interpretation and limitations
  7. Security and privacy safeguards
  8. Human decision boundaries where automation or AI is involved

Current Engineering Priorities

  1. Extend the private-cloud homelab only through bounded, reproducible integration tests while keeping unproven deployment claims explicit.
  2. Preserve the OBDIA v0.1.x bounded reference slice as the stable security baseline and evolve productionization separately.
  3. Elevate Bonfim SDK through release hardening and later isolated-execution research.
  4. Harden the AI SaaS Security & Compliance Fit-Gap project as the primary GRC and AI-governance anchor.
  5. Expand SOC evidence with detection logic, investigation timelines and mapped response decisions.

Languages

Portuguese — native · German — professional working proficiency · English — working proficiency

Security and Responsible Disclosure

Public repositories use authorized labs, synthetic data or sanitized examples. No active credentials, customer data, employer-owned internal identifiers or production secrets should be published.

Security concerns related to this profile repository can be reported according to SECURITY.md.

Pinned Loading

  1. cybersecurity-private-cloud-homelab cybersecurity-private-cloud-homelab Public

    Evidence-oriented cybersecurity homelab with native FreeBSD PF segmentation, Suricata, Wazuh, IaC and reproducible security validation.

    Shell

  2. officer-bound-digital-investigation-agent officer-bound-digital-investigation-agent Public

    Human-accountable security architecture for officer-bound AI agents supporting authorized digital investigations.

    Go

  3. bonfim-sdk bonfim-sdk Public

    Governed Python SDK for auditable security skills, AI agents and automations with fail-closed validation, traceability and human review.

    Python

  4. ai-saas-security-compliance-fit-gap-public ai-saas-security-compliance-fit-gap-public Public

    TypeScript-based security, compliance and AI governance fit-gap analysis for AI-enabled B2B SaaS environments.

    TypeScript

  5. gemini-security-engineering-study-lab gemini-security-engineering-study-lab Public

    Evidence-first Python study lab for AI-assisted security analysis using synthetic events, tests, human validation and explicit claim boundaries.

    Python

  6. tshark-teamwork-soc-case-study tshark-teamwork-soc-case-study Public

    SOC network forensics case study using TShark: phishing detection, IOC extraction, HTTP POST analysis, and VirusTotal correlation.