Network Security Engineering • Operations • Cloud Architecture • Automation & AI
Hi, I'm Caio! Building secure, reliable and automated hybrid infrastructure.
Network & Security engineer with hands-on experience in NOC operations, security labs, and cloud infrastructure. This portfolio presents practical projects and documented learning, not just certifications.
Current Focus
- AWS SAA-C03: architecture labs (IAM, VPC, HA/DR, serverless, monitoring)
- Multi-vendor networking: Cisco, Juniper, EVE-NG
- Python & AI for security and network automation
About me
I’m an IT professional with 10+ years of experience across network operations, infrastructure delivery, and enterprise support, working in large-scale, mission-critical environments where reliability and operational discipline are essential. Now advancing toward a cloud/hybrid security engineering focus, combining strong network fundamentals with defensive security skills and automation to build and support systems that are secure, resilient, and designed for modern operational demands.
Highlights
- AWS Solutions Architect – Associate (SAA-C03) learning track
- CompTIA Security+ certified
- Multi-vendor network simulations (EVE-NG)
- Python automation & scripting
- Hands-on SOC & blue team labs
AWS SAA-C03 | Architecture in Progress
I’m building AWS architecture fundamentals as part of the SAA-C03 learning path. The focus is on understanding how core AWS services work together, how security boundaries are designed, and how to make sound architectural decisions, not on producing fully polished production systems.
Current learning focus
- IAM design with users, groups, roles, and least-privilege access
- Using IAM roles for workloads instead of long-lived access keys
- Secure EC2 setups and basic access control patterns
- Storage choices and trade-offs between EBS, EFS, and instance store
- Security-first thinking and common AWS design mistakes
EC2 Storage Decision Lab
Hands-on lab exploring EC2 storage options and architectural trade-offs. Covers EBS, EFS, and instance store behavior, including persistence, snapshotting, AMI creation, and immutable infrastructure patterns. Focuses on choosing the right storage model based on cost, performance, and durability requirements.
View repository on GitHub →EC2 Secure Compute Baseline
Design and implementation of a secure EC2 baseline architecture demonstrating practical understanding of compute, networking, and access control. The lab covers instance provisioning with user data, security group design and behavior, SSH access models, and IAM role usage to enable secure service access without static credentials.
View repository on GitHub →AWS IAM Foundations
Hands-on exploration of AWS IAM concepts, including users, roles, policies, permission boundaries, and service role usage. The repository documents learning notes, practical examples, and security pitfalls encountered while building least-privilege access models.
View repository on GitHub →Focus areas
Cloud & Infrastructure
Cloud security concepts, IAM, network segmentation, zero trust patterns, and infrastructure-as-code experiments.
View cloud projects →Networking
BGP & routing labs, network design, Wireshark captures, Juniper & Cisco configurations, and performance tuning.
View networking labs →Cybersecurity
SOC investigations, SIEM use cases, Suricata, malware traffic analysis, vulnerability management, and GRC labs.
View cybersecurity projects →AI & Automation
Python tools, AI-assisted analysis, log parsing, and proof-of-concept projects using LLMs for security workflows.
View AI & automation →Featured projects
A small selection of projects that represent how I think about security, reliability and automation.
Network Threat Detection with Suricata
Built and tuned Suricata rules to detect malicious traffic, analysed alerts and documented incident response steps.
Multi-vendor BGP Lab on EVE-NG
Designed a service-provider style topology with Cisco & Juniper routers to explore routing policies and resilience.
AI-Assisted Log Analysis Prototype
Prototype pipeline where Python and an LLM help triage noisy logs, surface anomalies and support SOC investigations.
Contact
The best way to reach me is via email or LinkedIn. I'm happy to walk through any of the labs or projects you see here.