Skip to content
View a-bonfim-tech's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report a-bonfim-tech

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
a-bonfim-tech/README.md

Cloud Security Banner

André Luiz Vieira Bonfim

Cloud Security and Cybersecurity professional in training in Germany, focused on GCP, IAM, Zero Trust, DevSecOps, SOC workflows, GRC, and responsible AI governance.

I am building a recruiter-ready cybersecurity portfolio around one question: how can security decisions be made, implemented, documented, and defended under real audit or incident pressure?

Current Positioning

Area Focus
Target role Cloud Security, Security Architecture, GRC, SOC / Blue Team, DevSecOps
Primary cloud Google Cloud Platform
Security themes IAM, Zero Trust, network security, logging, risk decisions, auditability
Practical labs TryHackMe, TShark, Kali Linux, GCP security labs
Governance themes Decision records, evidence handling, compliance-safe documentation
AI security Responsible AI, RAG risk, inference/privacy concerns, human validation

Portfolio Projects

Project What it demonstrates
TryHackMe Guided Web Pentest Authorized web application pentest workflow with OWASP/PTES methodology, evidence handling, vulnerability chain analysis, and professional reporting.
Human SIEM Cybersecurity Governance-driven cybersecurity operating model for SOC, SIEM, risk decisions, audit readiness, and security leadership review.
Cloud Risk Decision Framework Audit-ready cloud risk reasoning, decision options, trade-offs, and architecture review documentation.
TShark SOC Case Study Network forensics investigation using TShark: phishing detection, IOC extraction, HTTP POST analysis, and threat intelligence correlation.
GCP Security Study Cases Google Cloud security cases covering Cloud Armor, NGFW, BeyondCorp, KMS, logging, monitoring, and evidence-based review.
DevSecOps Baseline GitHub Actions baseline with SBOM generation, vulnerability scanning, secrets detection, and OPA policy-as-code gates.

Evidence I Care About

  • Clear scope: authorized labs, sanitized examples, and no live third-party targets.
  • Repeatable structure: README, methodology, evidence, findings, and conclusions.
  • Audit readiness: decisions are explicit, versioned, and explainable.
  • Security judgment: trade-offs and risk reasoning matter as much as tools.
  • Human validation: AI-assisted work must remain accountable and reviewable.

Technical Skills

Domain Tools and concepts
Google Cloud VPC, Cloud Armor, Cloud NGFW, Cloud Logging, Cloud Monitoring, KMS, Cloud Run
Identity and access IAM, RBAC/ABAC, BeyondCorp, Zero Trust, least privilege
DevSecOps GitHub Actions, SBOM, OPA/Rego, secrets detection, vulnerability scanning
Security operations TShark, Wireshark, Linux, Kali, log analysis, incident response
Governance GRC, decision records, audit evidence, risk communication
AI governance Responsible AI, RAG security, privacy, inference risk, policy documentation

Selected Credentials

  • Google Cybersecurity Professional Certificate
  • Security in Google Cloud Specialization
  • Google Cloud networking and Cloud NGFW certificates
  • TryHackMe Jr Penetration Tester Path
  • TryHackMe Cyber Defense / Blue Team Labs
  • Generative AI governance and policy coursework

Full certificate evidence and verification links are maintained in the profile repository and related portfolio projects.

Background

  • Cybersecurity student at Masterschool Institute of Technology, Berlin.
  • Bachelor degree in Portuguese Language and Literature.
  • Languages: Portuguese, German, and English.
  • Professional strength: structured thinking, documentation quality, and security reasoning across technical and governance contexts.

Links

Platform Profile
LinkedIn André Bonfim
Coursera Coursera profile
TryHackMe a.bonfim.tech
GitHub a-bonfim-tech

GitHub Activity

GitHub Stats

Top Languages

TryHackMe Badge

Pinned Loading

  1. bonfim-security-constitution bonfim-security-constitution Public

    Fundamental governance framework for information security, oriented towards SecOps, GDPR, and Cybersicherheit, with versioned, auditable, and traceable decisions.

  2. human-siem-cybersecurity human-siem-cybersecurity Public template

    Audit-ready cybersecurity operating model for SIEM, SOC, governance, decision records, validation, and security leadership review.

  3. aws-ec2-ebs-snapshot-check-bash aws-ec2-ebs-snapshot-check-bash Public

    Forked from CaseyLabs/aws-ec2-ebs-snapshot-check-bash

    AWS EBS snapshot verification Bash reference; third-party learning material kept for backup, cloud operations, and security study context.

    Shell

  4. thm-guided-pentest-web thm-guided-pentest-web Public

    Authorized TryHackMe web pentest case study with OWASP/PTES methodology, evidence handling, vulnerability chain analysis, and professional report structure.

    1

  5. cloud-risk-decision-framework cloud-risk-decision-framework Public

    Cloud security risk decision framework for audit-ready reasoning, trade-off analysis, governance, GRC, and architecture review.