https://thiago.limaesilvatecnologia.com.br/en/perfil/


- [Home](https://thiago.limaesilvatecnologia.com.br/en/)
-  Profile 

Cybersecurity architecture

# Thiago Silva. 

Cyber Architect · Security Lead

Security from the first design decision. Bringing cloud, engineering and business together to build more secure systems.

[Connect on LinkedIn  ↗ ](https://www.linkedin.com/in/tlimasilva)

 PROFESSIONAL PROFILE  BR / GLOBAL 

TS

 FOCUS Security by design

 CLOUD AWS · GCP · Azure

 SCOPE Architecture & leadership

 25+ years  of experience in technology 

 AWS · GCP · Azure  security, governance and cloud 

 Brazil & LATAM  experience with global teams 

01 / ABOUT

## Technology with a business perspective.

My career brings together infrastructure, leadership and cybersecurity. As a Cybersecurity Architect at LTIMindtree on the Equifax project, I support the migration of on-premises environments to GCP and application modernization.

I combine technical experience in cloud, identity and secure development with service management, innovation and customer relationships. At Globant and Unisys, my work covered security architecture, testing leadership, mentoring and helping international teams adopt Secure SDLC practices.

02 / EXPERTISE

## Security at every layer.

From architecture to operations: technical controls, processes and collaboration to protect applications, identities and data.

 01 — CLOUD SECURITY 

### Secure cloud architecture

AWS architecture, security for GCP migrations, KMS encryption, private connectivity, multi-account governance and organization-wide controls.

 AWS  GCP  IAM · KMS · SCPs 

 Related reading 

- [Cloud SQL: database location does not finish the security review](https://thiago.limaesilvatecnologia.com.br/en/artigos/cloud-sql-regional-control-plane/)
- [Containers: follow the review into runtime](https://thiago.limaesilvatecnologia.com.br/en/artigos/container-runtime/)
- [Kubernetes: namespaces do not finish isolation analysis](https://thiago.limaesilvatecnologia.com.br/en/artigos/kubernetes-tenancy/) 02 — DEVSECOPS 

### Security in software delivery

CI/CD security gates, SAST, DAST, SCA, secret detection and manual security code reviews for sensitive components.

 Secure SDLC  SAST · DAST · SCA  API Security 

 Related reading 

- [CI/CD: every stage carries a trust boundary](https://thiago.limaesilvatecnologia.com.br/en/artigos/pipeline-trust/)
- [SBOM: from component list to response decision](https://thiago.limaesilvatecnologia.com.br/en/artigos/sbom-operational/)
- [GitHub Actions: who can change the build tool?](https://thiago.limaesilvatecnologia.com.br/en/artigos/actions-third-party/) 03 — IDENTITY & GOVERNANCE 

### Access, risk and compliance

Least privilege, MFA, Zero Trust, control assessments and alignment with PCI DSS, LGPD and security best practices.

 IAM  Zero Trust  PCI DSS · LGPD 

 Related reading 

- [Access control: who decides and who executes?](https://thiago.limaesilvatecnologia.com.br/en/artigos/access-control/)
- [Authentication: design beyond login](https://thiago.limaesilvatecnologia.com.br/en/artigos/authentication-journeys/)
- [Authorization: turn business rules into testable decisions](https://thiago.limaesilvatecnologia.com.br/en/artigos/authorization-decisions/) 04 — DETECTION & RESPONSE 

### Visibility and investigation

Security findings and telemetry integration, vulnerability management and support for incident analysis using AWS services and SIEM platforms.

 GuardDuty · Inspector  Security Hub · Security Lake  SIEM 

 Related reading 

- [Logs: start with the incident question](https://thiago.limaesilvatecnologia.com.br/en/artigos/logging-evidence/) 05 — INNOVATION & AI 

### Automation for security

Vulnerability lifecycle automation with Power Automate, generative AI initiatives and security controls for RAG solutions.

 Power Automate  Generative AI  RAG Security 

 Related reading 

- [Prompt injection: keep authority outside retrieved text](https://thiago.limaesilvatecnologia.com.br/en/artigos/prompt-injection-boundary/)
- [MCP: tool changes are trust changes](https://thiago.limaesilvatecnologia.com.br/en/artigos/mcp-tool-change/)
- [RAG: revocation must reach retrievable content](https://thiago.limaesilvatecnologia.com.br/en/artigos/rag-revocation/) 06 — LEADERSHIP & FINOPS 

### Strategy, people and services

Mentoring, global training, service management and customer relationships, focused on cloud adoption, costs and continuous improvement.

 FinOps  Customer Success  Team leadership 

 Related reading 

- [Attack surface: include the forgotten paths](https://thiago.limaesilvatecnologia.com.br/en/artigos/attack-surface/)
- [Availability: budget expensive operations](https://thiago.limaesilvatecnologia.com.br/en/artigos/availability-budgets/)
- [Microservices: preserve decision context when delegating](https://thiago.limaesilvatecnologia.com.br/en/artigos/microservice-delegation/)

03 / EXPERIENCE

## Experience across disciplines.

LTIMindtree 2026 — present 

### Cybersecurity Architect

- Equifax project: supporting architecture, implementation and operations for an on-premises-to-GCP migration involving Brazilian financial scoring data and application modernization.

Globant 2024 — 2026 

### Cybersecurity Architect & Security Testing Lead

- Led the implementation of AWS security architecture for the Red Sea project, covering workload protection, identity, encryption and private connectivity.
- Implemented Secure SDLC controls in pipelines, security testing and code reviews, aligned with PCI DSS and privacy requirements.
- Integrated services including WAF, GuardDuty, Config, CloudTrail, Security Hub, Inspector and Security Lake; also served as a cybersecurity career mentor.

Unisys 2022 — 2024 

### Cybersecurity Architect & Security Testing Lead

- Delivered global training and secure development content to strengthen security culture and team maturity.
- Reviewed Zero Trust across eight layers, automated vulnerability management with Power Automate and Tenable data, and used Wiz for security assessments.
- Contributed to OWASP-based minimum security requirements, threat intelligence, MITRE ATT&CK, cyber risk quantification and innovation initiatives.

SoftwareOne 2020 — 2022 

### Service Success Manager — LATAM

- Managed customer cloud journeys across Azure, AWS and Google Cloud, including business reviews, onboarding, SLA monitoring and sales support.
- Worked with FinOps and PyraCloud, created a FinOps Foundation community for LATAM and used Power BI for performance reporting.
- Conducted cloud security research and vulnerability assessments, and established a Blue Team to support remediation and DevSecOps improvements.

Cleartech 2019 — 2020 

### IT / Business Consultant

- Managed requirements and solution development for indices used by Anatel, alongside automation and digital transformation initiatives.
- Participated in the LGPD committee, implemented AWS WAF and IAM, conducted security testing and centralized logs and alerts with Splunk.
- Administered AWS environments and assessed digital experience, performance and capacity.

MiX Telematics 2018 — 2019 

### Service Manager IoT — LATAM

- Established service governance, ITIL processes and a lifecycle management approach for telemetry and IoT solutions.
- Developed the partner network, security policies and oversight of web and embedded software releases.

Claro Brasil 2015 — 2018 

### Mobility / Security / Innovation Consultant

- Worked in América Móvil Group’s MDM tower, which the résumé reports reached more than 4,000 customers or 70,000 devices in its first year.
- Deployed and supported mobility solutions, integrated SIEM, NAC and ISE, managed vendors and developed executive performance indicators.
- Served on Embratel’s innovation committee, contributing to IoT, automation, chatbots, information security and new products.

VITAIT Technology Services 2011 — 2015 

### Operations Consultant & Co-founder

- Managed national and international teams, Service Desk, a 24×7 NOC, infrastructure and cloud solutions.
- Implemented ITIL processes, BIA-based business continuity, security policies, a service catalog and executive reporting.
- Planned IT budgets, managed vendors and strategic projects, and supported team development.

04 / EDUCATION & QUALIFICATIONS

## Learning throughout a career.

### Education

-  MBA in Business Management  IBTA · 2011 
-  Postgraduate qualification in Technology Management  IBTA · 2011 
-  Extension courses in Project Management and IT Management  Fundação Getulio Vargas · 2010 
-  Bachelor’s degree in Information Systems  Universidade Anhembi Morumbi · 2008 
-  Database Development program  Universidade Anhembi Morumbi · 2006 
-  Technical qualification in Data Processing  Colégio Técnico Módulo · 2000 

### Selected certifications and qualifications

-  Cloud  AWS Certified Cloud Practitioner · Azure Fundamentals · Microsoft 365 Fundamentals · Azure Security and Compliance 
-  Security and privacy  Fortinet NSE 1 · OneTrust · Qualys · Tenable · LGPD Foundations · Centrify IAM 
-  Management and quality  ITIL Foundations 2, 3 and 4 · COBIT · ISO 20k · ISO 27k · CTFL · IREB 
-  Infrastructure and mobility  VMware VCP · Citrix CCA · Cisco Jasper · MobileIron · Check Point CCSBMSE 

Selected certifications and qualifications listed in the April 2026 résumé; issue dates and current validity were not specified.

### Languages

  English  · Advanced   Spanish  · Basic 

Publication

### Nove passos para construir um Data Warehouse

Authored book listed in the résumé, published in Portuguese.

[View publication on Amazon ↗](https://www.amazon.com.br/dp/B00DAGDSH8)

PROFESSIONAL CONTACT

## Let’s talk about security.

[LinkedIn ↗](https://www.linkedin.com/in/tlimasilva)[Send an email](mailto:tlimasilva@uol.com.br)
