Jose Vanderlei Nunes Moreira

Since 1989 working in many IT areas like software development, support, service desk, network, architecture, security and team management, since 2004 dedicated to IT security. Advanced knowledge in ITIL, Cobit, standards and frameworks for Information Security. Experience in ISO 27K, PCI / DSS and SOX implementation and auditing process and risk management assessment as well. Large experience in corporate security policies design and implementation and IT governance. Experience in Business Continuity and Disaster Recovery Plans (BCP/DRP). Development of IS campaign for non-IT people. Vulnerabilities analysis, risks and intrusion tests. Auditing IT infrastructure, systems, web applications and processes. Experience in complex IT environments. CISSP, ISO27K and CSO certifications.

Informações coletadas do Lattes em 30/10/2024

Acadêmico

Formação acadêmica

Especialização em MBA - Gestão da Tecnologia da Informação

2011 - 2013

Universidade do Vale do Rio dos Sinos
Título: Pesquisa de Campo

Graduação em Gestão da Tecnologia da Informação

2006 - 2008

Universidade do Sul de Santa Catarina
Título: Estudo de Caso

Formação complementar

2015 - 2015

CISSP Certification. (Carga horária: 40h). , International Information System Security Certification Consortium, ISC2, Estados Unidos.

2013 - 2013

ISO 27K LEAD IMPLEMENTER CERTIFICATION. (Carga horária: 40h). , Professional Evaluation and Certification Board, PECB, Inglaterra.

Idiomas

Bandeira representando o idioma Inglês

Compreende Bem, Fala Bem, Lê Bem, Escreve Bem.

Bandeira representando o idioma Espanhol

Compreende Bem, Fala Pouco, Lê Bem, Escreve Pouco.

Bandeira representando o idioma Português

Compreende Bem, Fala Bem, Lê Bem, Escreve Bem.

Histórico profissional

Endereço profissional

  • Metalurgica Gerdau - Matriz, Metalurgica Gerdau - Matriz - RS - Brasil. , Avenida Borges de Medeiros, 650, Colonial, 93212110 - Sapucaia do Sul, RS - Brasil, Telefone: (51) 34507771, Ramal: 7771

Experiência profissional

2007 - 2010

Televisão Gaúcha

Vínculo: Colaborador, Enquadramento Funcional: Coordenador de Segurança da Informação, Carga horária: 40, Regime: Dedicação exclusiva.

Outras informações:
GRUPO RBS (National media company (TV,Radio,Online Content and News) Address: Av. Erico Verissimo, 400 ? 4º andar, Azenha, CEP: 90160-180, Porto Alegre/RS ? Brazil Phone : +55-51-3218-6309 Manager: Regis Zanini (regis.zanini@gruporbs.com.br: +55-51-3218-6309) Position 1: Security Information and Network Coordinator; Position 2: Security Analyst Main Responsibilities: ? IS and Network team management; ? Define technologies, methodologies and Capex/Opex plans; ? Negotiation with supplier?s solutions to meet the business needs. Negotiating, quotations, RFPs and preparing proofs of concept; ? Preparation, execution and IS project management involving multidisciplinary teams; ? Development of the Corporate Information Security Policy; ? Creation of the Business Continuity Plan(creation, testing and review); ? Creation and coordination of the Executive Committee of Information Security; ? Compliance audits (PCI / DSS), vulnerability assessment and risk analysis on IT Environments based on ISO 27K; ? SLA´s management for sourcing and internal team to maintain the quality of IT services and KPI´s definition for critical processes and services; ? Member of team that implemented the ITIL on IT environment; ? Firewall administration; ? IPS administration; ? Endpoint protection administration; ? Certificate authority administration; ? Perimeter protection administration; ? DNS administration and monitoring; ? Network protection (segmentation and policies); ? Three years working as a contractor providing and managing IT as a service (sourcing).

2010 - 2010

Usefashion

Vínculo: Colaborador, Enquadramento Funcional: Gerente de Tecnologia da Informação, Carga horária: 40, Regime: Dedicação exclusiva.

Outras informações:
Position : IT Manager (Infrastructure, Security, Telecom and Applications Team) Main Responsibilities: In this company, the IT area is the core for the business where all business initiatives are supported 100% by the IT. This is a small company with agile methodologies in place and simplicity as rule. ? IT team management; ? Capex/Opex plans; ? Define and implement the Cloud Strategy ? Team development; ? Lead agile projects; ? Define and implement the roadmap for web applications; ? Manage the infrastructure, datacenter and all aspects of IT as a core for the business success.

2010 - Atual

Metalurgica Gerdau - Matriz

Vínculo: Colaborador, Enquadramento Funcional: Information Security Advisor, Regime: Dedicação exclusiva.

Outras informações:
Position: Information Security Advisor Main Responsibilities: ? Coordinating local and global projects with multidisciplinary teams from all regions (North America, Latin America, Europe and India) in IS areas such perimeter security and infrastructure security; ? RFP / RFI for IS vendors; ? Lead Sarbanes-Oxley (SOX), ISO 27001 audits and compliance process, vulnerability and risk assessments. Action plan for deviations correction and control improvements; ? Manage IS sourcing (suppliers, contractors and partners for IS solutions and management) to meet the SLA requirements and KPI analysis; ? Define and manage Information Security Architecture (Network Security, Infrastructure Security and Perimeter Security); ? IS incidents response management; ? Accountable for Audit, Compliance and risk management for Gerdau in Brazil; ? To design and review the controls matrix to address the risks in process for IT and non-IT areas; ? Accountable for certificates management; ? Accountable for endpoint security (antimalware, encryption, DLP, HIPS, HFW); ? Change Advisory Board member (CAB); ? Application Development vulnerability assessment and best practices evaluations; ? Evaluate and validate Cloud and SaaS vendors according security requirements for business needs and risk mitigation; ? Coordinate a task force to reduce and control vulnerability on IT environment; ? Accountable to lead MSSP contractor to protect the perimeter against APT attacks, DDoS, and monitoring and report malicious activities, also accountable for SIEM implementation. ? Management of SOC team and lead SOC implementation and MSS service.