Skip to content
View a-bonfim-tech's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report a-bonfim-tech

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
a-bonfim-tech/README.md

André Bonfim — Cybersecurity, Cloud Security, IAM and Governance

André Luiz Vieira Bonfim

Junior Cybersecurity Analyst · Cloud Security · IAM · Security Governance
Berlin, Germany

LinkedIn · TryHackMe · Coursera

Professional Profile

Cybersecurity professional based in Berlin with a completed 2,720-hour Cybersecurity Bootcamp specialized in Security Operations Center Analysis and practical internship experience assessing cloud security controls.

During a 320-hour internship at Panos.AI, I supported evidence-based reviews of TLS 1.3, HTTPS/HSTS, Azure Storage encryption, IAM, privileged access, logging, monitoring, backup and recovery controls in the context of GDPR and ISO/IEC 27001-oriented compliance work.

My portfolio focuses on a clear principle: security claims should be supported by reproducible technical evidence, explicit scope, documented limitations and human-reviewed decisions.

Core Focus

Domain Current focus
Cloud Security Azure and Google Cloud security controls, IAM, network exposure, encryption, logging and monitoring
Identity & Access MFA, privileged access, least privilege, RBAC/ABAC and Zero Trust concepts
Security Operations Network traffic analysis, IOC extraction, log analysis and incident-response fundamentals
Security Governance Control assessment, evidence management, audit readiness, risk communication and technical documentation
DevSecOps GitHub Actions, CodeQL, SBOM, vulnerability scanning, secrets detection and policy-as-code

Featured Portfolio

Project Evidence demonstrated
GCP Security Study Cases Five evidence-based cloud security cases covering Cloud Armor, Cloud NGFW, BeyondCorp, CMEK/KMS, Cloud Logging, Monitoring and VPC Flow Logs
TShark SOC Case Study PCAP analysis, phishing detection, HTTP POST inspection, IOC extraction and threat-intelligence correlation
DevSecOps Baseline GitHub Actions security gates with SBOM generation, vulnerability scanning, secrets detection and OPA policy-as-code
Guided Web Pentest Authorized web assessment covering reconnaissance, IDOR, weak password-reset logic, administrative access, RCE and vulnerability chaining
Human SIEM Cybersecurity Synthetic governance and decision-documentation framework for SOC, audit and risk-review scenarios
Cloud Risk Decision Framework Documentation-first cloud risk case studies focused on decisions, trade-offs and audit traceability

For role-specific navigation, see PORTFOLIO_INDEX.md.

Internship Experience

Cybersecurity Intern — Panos.AI, Berlin
08 June 2026 – 02 August 2026 · 320 hours

  • Assessed and documented security controls for cloud environments, focusing on encryption, IAM, logging, backup and recovery.
  • Supported GDPR and ISO/IEC 27001-oriented compliance activities through evidence collection and technical control validation.
  • Reviewed TLS 1.3, HTTPS, HSTS and Microsoft Azure Storage encryption configurations.
  • Evaluated MFA, privileged access, audit trails and monitoring controls.
  • Contributed to audit-ready documentation using GitHub, pull requests, GitHub Actions, CodeQL, Linear, Markdown and JSON.

Selected Technical Skills

Microsoft Azure · Google Cloud · IAM · MFA · TLS 1.3 · HTTPS · HSTS · GitHub Actions · CodeQL · TShark · Wireshark · Nmap · Linux · Markdown · JSON

Frameworks and Methods

GDPR · ISO/IEC 27001 fundamentals · NIST Cybersecurity Framework 2.0 · OWASP WSTG · OWASP Top 10 · PTES

Selected Credentials

  • Google Cybersecurity Professional Certificate
  • Security in Google Cloud coursework and specialization certificates
  • Google Cloud networking and Cloud NGFW training
  • Generative AI: Governance, Policy, and Emerging Regulation — University of Michigan
  • TryHackMe cybersecurity labs and learning paths

Portfolio Evidence Standard

Every anchor project should make the following clear:

  1. Scope and authorization
  2. My individual contribution
  3. Methodology and tools
  4. Reproducible execution steps
  5. Technical evidence and findings
  6. Risk interpretation and limitations
  7. Security and privacy safeguards

Current Development Priorities

  • Publish a sanitized security-controls evidence portfolio derived from internship competencies without exposing proprietary information.
  • Strengthen cloud IAM and security-control labs with reproducible scripts and sanitized evidence.
  • Expand SOC case studies with detection logic, timelines and mapped response decisions.
  • Maintain a clear separation between verified evidence, assumptions, recommendations and future work.

Languages

Portuguese — native · German — professional working proficiency · English — working proficiency

Security and Responsible Disclosure

Public repositories use authorized labs, synthetic data or sanitized examples. No active credentials, customer data, internal company identifiers or production secrets should be published.

Security concerns related to this profile repository can be reported according to SECURITY.md.

Pinned Loading

  1. bonfim-security-constitution bonfim-security-constitution Public

    Fundamental governance framework for information security, oriented towards SecOps, GDPR, and Cybersicherheit, with versioned, auditable, and traceable decisions.

  2. human-siem-cybersecurity human-siem-cybersecurity Public template

    Audit-ready cybersecurity operating model for SIEM, SOC, governance, decision records, validation, and security leadership review.

  3. aws-ec2-ebs-snapshot-check-bash aws-ec2-ebs-snapshot-check-bash Public

    Forked from CaseyLabs/aws-ec2-ebs-snapshot-check-bash

    AWS EBS snapshot verification Bash reference; third-party learning material kept for backup, cloud operations, and security study context.

    Shell

  4. thm-guided-pentest-web thm-guided-pentest-web Public

    Authorized TryHackMe web pentest case study with OWASP/PTES methodology, evidence handling, vulnerability chain analysis, and professional report structure.

    1

  5. cloud-risk-decision-framework cloud-risk-decision-framework Public

    Cloud security risk decision framework for audit-ready reasoning, trade-off analysis, governance, GRC, and architecture review.