https://thiago.limaesilvatecnologia.com.br/en/profile/


- [Home](https://thiago.limaesilvatecnologia.com.br/en/)
-  Profile

Cybersecurity architecture

# Thiago Silva.

 Thiago Lima Soneti da Silva (Thiago Silva)  — Cyber Architect and technical lead at [Lima e Silva Tecnologia](https://www.limaesilvatecnologia.com.br/en/).

Cyber Architect · Security Lead

Security from the first design decision. Bringing cloud, engineering and business together to build more secure systems.

[Connect on LinkedIn  ↗ ](https://www.linkedin.com/in/tlimasilva)

 PROFESSIONAL PROFILE  BR / GLOBAL

TS

 FOCUS Security by design

 CLOUD AWS · GCP · Azure

 SCOPE Architecture & leadership

 25+ years  of experience in technology

 AWS · GCP · Azure  security, governance and cloud

 Brazil & LATAM  experience with global teams

01 / ABOUT

## Technology with a business perspective.

My career brings together infrastructure, leadership and cybersecurity. As a Cybersecurity Architect at LTIMindtree on the Equifax project, I support the migration of on-premises environments to GCP and application modernization.

I combine technical experience in cloud, identity and secure development with service management, innovation and customer relationships. At Globant and Unisys, my work covered security architecture, testing leadership, mentoring and helping international teams adopt Secure SDLC practices.

02 / EXPERTISE

## Security at every layer.

From architecture to operations: technical controls, processes and collaboration to protect applications, identities and data.

 01 — CLOUD SECURITY

### Secure cloud architecture

AWS architecture, security for GCP migrations, KMS encryption, private connectivity, multi-account governance and organization-wide controls.

 AWS  GCP  IAM · KMS · SCPs

[Related consulting · Lima e Silva Tecnologia](https://www.limaesilvatecnologia.com.br/en/servicos/cloud-security/)

 Related reading

- [Managed mTLS on GCP: workload identity becomes an architecture boundary](https://thiago.limaesilvatecnologia.com.br/en/articles/cloud-security/gcp-managed-backend-mtls/)
- [API Gateway: 1 MB logs need a new evidence contract](https://thiago.limaesilvatecnologia.com.br/en/articles/cloud-security/api-gateway-log-delivery-budget/)
- [Cloud SQL: database location does not finish the security review](https://thiago.limaesilvatecnologia.com.br/en/articles/cloud-security/cloud-sql-regional-control-plane/) 02 — DEVSECOPS

### Security in software delivery

CI/CD security gates, SAST, DAST, SCA, secret detection and manual security code reviews for sensitive components.

 Secure SDLC  SAST · DAST · SCA  API Security

[Related consulting · Lima e Silva Tecnologia](https://www.limaesilvatecnologia.com.br/en/servicos/devsecops/)

 Related reading

- [GitHub credential inventory: turn the CSV into an exposure graph](https://thiago.limaesilvatecnologia.com.br/en/articles/identity-access/github-enterprise-credential-inventory/)
- [CI/CD: every stage carries a trust boundary](https://thiago.limaesilvatecnologia.com.br/en/articles/devsecops/pipeline-trust/)
- [SBOM: from component list to response decision](https://thiago.limaesilvatecnologia.com.br/en/articles/devsecops/sbom-operational/) 03 — IDENTITY & GOVERNANCE

### Access, risk and compliance

Least privilege, MFA, Zero Trust, control assessments and alignment with PCI DSS, LGPD and security best practices.

 IAM  Zero Trust  PCI DSS · LGPD

[Related consulting · Lima e Silva Tecnologia](https://www.limaesilvatecnologia.com.br/en/servicos/identity-access/)

 Related reading

- [GitHub credential inventory: turn the CSV into an exposure graph](https://thiago.limaesilvatecnologia.com.br/en/articles/identity-access/github-enterprise-credential-inventory/)
- [Managed mTLS on GCP: workload identity becomes an architecture boundary](https://thiago.limaesilvatecnologia.com.br/en/articles/cloud-security/gcp-managed-backend-mtls/)
- [Access control: who decides and who executes?](https://thiago.limaesilvatecnologia.com.br/en/articles/identity-access/access-control/) 04 — DETECTION & RESPONSE

### Visibility and investigation

Security findings and telemetry integration, vulnerability management and support for incident analysis using AWS services and SIEM platforms.

 GuardDuty · Inspector  Security Hub · Security Lake  SIEM

[Related consulting · Lima e Silva Tecnologia](https://www.limaesilvatecnologia.com.br/en/servicos/security-roadmap/)

 Related reading

- [API Gateway: 1 MB logs need a new evidence contract](https://thiago.limaesilvatecnologia.com.br/en/articles/cloud-security/api-gateway-log-delivery-budget/)
- [Logs: start with the incident question](https://thiago.limaesilvatecnologia.com.br/en/articles/security-operations/logging-evidence/) 05 — INNOVATION & AI

### Automation for security

Vulnerability lifecycle automation with Power Automate, generative AI initiatives and security controls for RAG solutions.

 Power Automate  Generative AI  RAG Security

[Related consulting · Lima e Silva Tecnologia](https://www.limaesilvatecnologia.com.br/en/servicos/ai-security/)

 Related reading

- [Prompt injection: keep authority outside retrieved text](https://thiago.limaesilvatecnologia.com.br/en/articles/ai-security/prompt-injection-boundary/)
- [MCP: tool changes are trust changes](https://thiago.limaesilvatecnologia.com.br/en/articles/ai-security/mcp-tool-change/)
- [RAG: revocation must reach retrievable content](https://thiago.limaesilvatecnologia.com.br/en/articles/ai-security/rag-revocation/) 06 — LEADERSHIP & FINOPS

### Strategy, people and services

Mentoring, global training, service management and customer relationships, focused on cloud adoption, costs and continuous improvement.

 FinOps  Customer Success  Team leadership

[Related consulting · Lima e Silva Tecnologia](https://www.limaesilvatecnologia.com.br/en/servicos/security-architecture/)

 Related reading

- [Attack surface: include the forgotten paths](https://thiago.limaesilvatecnologia.com.br/en/articles/security-architecture/attack-surface/)
- [Availability: budget expensive operations](https://thiago.limaesilvatecnologia.com.br/en/articles/security-architecture/availability-budgets/)
- [Microservices: preserve decision context when delegating](https://thiago.limaesilvatecnologia.com.br/en/articles/security-architecture/microservice-delegation/)

03 / EXPERIENCE

## Experience across disciplines.

LTIMindtree 2026 — present

### Cybersecurity Architect

- Equifax project: supporting architecture, implementation and operations for an on-premises-to-GCP migration involving Brazilian financial scoring data and application modernization.

Globant 2024 — 2026

### Cybersecurity Architect & Security Testing Lead

- Led the implementation of AWS security architecture for the Red Sea project, covering workload protection, identity, encryption and private connectivity.
- Implemented Secure SDLC controls in pipelines, security testing and code reviews, aligned with PCI DSS and privacy requirements.
- Integrated services including WAF, GuardDuty, Config, CloudTrail, Security Hub, Inspector and Security Lake; also served as a cybersecurity career mentor.

Unisys 2022 — 2024

### Cybersecurity Architect & Security Testing Lead

- Delivered global training and secure development content to strengthen security culture and team maturity.
- Reviewed Zero Trust across eight layers, automated vulnerability management with Power Automate and Tenable data, and used Wiz for security assessments.
- Contributed to OWASP-based minimum security requirements, threat intelligence, MITRE ATT&CK, cyber risk quantification and innovation initiatives.

SoftwareOne 2020 — 2022

### Service Success Manager — LATAM

- Managed customer cloud journeys across Azure, AWS and Google Cloud, including business reviews, onboarding, SLA monitoring and sales support.
- Worked with FinOps and PyraCloud, created a FinOps Foundation community for LATAM and used Power BI for performance reporting.
- Conducted cloud security research and vulnerability assessments, and established a Blue Team to support remediation and DevSecOps improvements.

Cleartech 2019 — 2020

### IT / Business Consultant

- Managed requirements and solution development for indices used by Anatel, alongside automation and digital transformation initiatives.
- Participated in the LGPD committee, implemented AWS WAF and IAM, conducted security testing and centralized logs and alerts with Splunk.
- Administered AWS environments and assessed digital experience, performance and capacity.

MiX Telematics 2018 — 2019

### Service Manager IoT — LATAM

- Established service governance, ITIL processes and a lifecycle management approach for telemetry and IoT solutions.
- Developed the partner network, security policies and oversight of web and embedded software releases.

Claro Brasil 2015 — 2018

### Mobility / Security / Innovation Consultant

- Worked in América Móvil Group’s MDM tower, which the résumé reports reached more than 4,000 customers or 70,000 devices in its first year.
- Deployed and supported mobility solutions, integrated SIEM, NAC and ISE, managed vendors and developed executive performance indicators.
- Served on Embratel’s innovation committee, contributing to IoT, automation, chatbots, information security and new products.

VITAIT Technology Services 2011 — 2015

### Operations Consultant & Co-founder

- Managed national and international teams, Service Desk, a 24×7 NOC, infrastructure and cloud solutions.
- Implemented ITIL processes, BIA-based business continuity, security policies, a service catalog and executive reporting.
- Planned IT budgets, managed vendors and strategic projects, and supported team development.

04 / EDUCATION & QUALIFICATIONS

## Learning throughout a career.

### Education

-  MBA in Business Management  IBTA · 2011
-  Postgraduate qualification in Technology Management  IBTA · 2011
-  Extension courses in Project Management and IT Management  Fundação Getulio Vargas · 2010
-  Bachelor’s degree in Information Systems  Universidade Anhembi Morumbi · 2008
-  Database Development program  Universidade Anhembi Morumbi · 2006
-  Technical qualification in Data Processing  Colégio Técnico Módulo · 2000

### Selected certifications and qualifications

-  Cloud  AWS Certified Cloud Practitioner · Azure Fundamentals · Microsoft 365 Fundamentals · Azure Security and Compliance
-  Security and privacy  Fortinet NSE 1 · OneTrust · Qualys · Tenable · LGPD Foundations · Centrify IAM
-  Management and quality  ITIL Foundations 2, 3 and 4 · COBIT · ISO 20k · ISO 27k · CTFL · IREB
-  Infrastructure and mobility  VMware VCP · Citrix CCA · Cisco Jasper · MobileIron · Check Point CCSBMSE

Selected certifications and qualifications listed in the April 2026 résumé; issue dates and current validity were not specified.

### Languages

  English  · Advanced   Spanish  · Basic

Publication

### Nove passos para construir um Data Warehouse

Authored book listed in the résumé, published in Portuguese.

[View publication on Amazon ↗](https://www.amazon.com.br/dp/B00DAGDSH8)

PROFESSIONAL CONTACT

## Let’s talk about security.

[LinkedIn ↗](https://www.linkedin.com/in/tlimasilva)[Send an email](mailto:contato@limaesilvatecnologia.com.br)
