Skip to content
View Alisson-P's full-sized avatar

Block or report Alisson-P

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Alisson-P/README.md
GitHub Panel

Alisson Pereira

Cyber Security Engineer | Senior Cybersecurity Consultant | Tech Lead

Vulnerability Management · Cloud Security · Security Automation

LinkedIn Portfolio Gmail


About

Vulnerability Management and Cloud Security leader with 15+ years of professional experience, delivering for large enterprises across North America, EMEA and LATAM in English speaking, multicultural teams.

What I do

  • Run vulnerability management as a full cycle, not a scan report: intake, deduplication, risk based prioritization, owner assignment, remediation roadmap and verification
  • Assess cloud security posture at enterprise scale and turn findings into a plan, with severity, effort, affected resources and an owner for every item
  • Lead and mentor consultants and architects, raising delivery quality and shortening ramp up time for new team members
  • Build the automation behind all of it, which is how high assessment volume gets delivered consistently instead of one report at a time

How I work

I turn scan output into decisions someone can own. The pipelines I build ingest cloud posture and benchmark exports, then produce a prioritized remediation roadmap, an executive readout, dashboards and a client ready package, with every recommendation traced back to its evidence.

I also build the tooling behind the delivery. Internal automation agents I designed cut assessment delivery time by roughly 80% and reduced onboarding time for new team members by about 25%, which made the practice measurably more scalable and consistent.

My early career includes national level leadership in a regulated, audit driven environment, which still shapes how I report and document.

Based in Brazil. I work in Portuguese and English.


What I work with

Domain Tools and practices
🤖 AI Agents & Skills Agent and skill design, orchestration, prompt engineering, typed and auditable decisions, Microsoft Copilot
☁️ Cloud Security & CSPM Microsoft Defender for Cloud, Secure Score, Microsoft Cloud Security Benchmark, Azure Policy
🛡️ Threat Detection & Response Microsoft Sentinel, Defender XDR, KQL, MITRE ATT&CK
🔍 Vulnerability Management Qualys VMDR and CSAM, Tenable Nessus, Defender Vulnerability Management
🦅 Endpoint & EDR CrowdStrike Falcon, Microsoft Defender for Endpoint
🔐 Identity & Data Microsoft Entra ID, Conditional Access, Microsoft Purview
📋 Governance & Compliance CIS Controls, NIST SP 800-53, ISO 27001, PCI DSS, LGPD
⚙️ Automation & Reporting Python, PowerShell, KQL, Power BI, Git, GitHub Actions

Certifications


Highlights

  • 🚀 ~80% faster security assessment delivery, through automation agents I designed and built
  • 📉 ~25% shorter onboarding for new consultants, from standardized runbooks and documentation
  • 🌎 Delivering to large enterprise customers across North America, remote from Brazil
  • 🎓 Mentoring and enabling other consultants on assessment quality and delivery
  • 🗂️ 108 badges and 21 trophies on Microsoft Learn, plus 77+ hours of tracked learning

Featured

End to end vulnerability management built with open source tooling: internal scanning, external attack surface, threat intelligence enrichment and redundant validation.

Python MIT

Typed decision variant: same base, triage with calibrated confidence and a comparative benchmark against the base program.

Python MIT

Unified platform for indicators of compromise, potentially unwanted applications and automated threat hunting, built with open source tooling.

Python YARA MIT

Typed decision variant: indicator triage decided in code, with an auditable trail and a blocking layer veto.

Python MIT

🤖 YSAT

An AI agent skill that disagrees with you, on purpose, with evidence. Risk first, pre mortem always, verdict changes only on new evidence.

Agent skill MIT

⚖️ YSAT-JEV

Typed judgment variant: the verdict is composed in code from atomic typed questions, with an auditable trail and a state hash.

Python MIT

Interactive single page portfolio: 140 certifications, instant search, filters by vendor and area, dark mode and shareable filtered links.

HTML Live

Source repository behind the portfolio, with every certificate, badge and course syllabus under version control.

140 certifications


animated panel

Open your mind!

Security is not a product you buy, it is a posture you keep measuring. Bora.

@Alisson-P's activity is private