Cyber Security Consultant & Advisor · Intelligence-to-Operations bridging
Portugal
I help technology teams prepare the evidence that regulators, auditors, and investors require — without slowing down delivery.
My work sits at the intersection of security governance, GRC, and engineering. I build systems that connect detection output, compliance controls, and release gates into audit trails that are ready when the regulator asks.
Everything I produce is grounded in the EU Cyber Resilience Act (CRA), ISO 27001, NIS2, and DORA.
Knowing a CVE exists in the NVD is not the same as knowing it is being actively exploited. Without correlation against CISA KEV, the CRA Article 14 notification clock starts running without the organisation knowing.
Regulators do not ask for the patch — they ask for the record of who assessed the risk, when, with what criteria, and what was decided. A Jira ticket and a git commit are not that record.
An organisation can have solid internal processes and still fail CRA compliance — because it did not produce the artifacts the regulation requires as proof. Annex VII must exist on paper.
Risk-driven release gate engine. CRA Art. 14 notification artifacts, KEV correlation, and HMAC-chained audit trail.
3CP reference implementation — tokenless, VRF-verified post-quantum provenance anchoring for chain of custody.
Practical lab bridging CTI and operations — evolving from misp-playground into a full intelligence-to-operations workflow environment.