Customise Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.

No cookies to display.

Clisnmamm Herbete

Versatile information security analyst professional, based in Fortaleza, Brazil, with 8 years of extensive experience working across multiple domains of IT infrastructure and cybersecurity.

What I Do

Audit

Information security audits using best know frameworks like ISO 27001, CIS Controls, NIST CSF, PCI-DSS.

Security awareness

Provide training for work force on how to interact with enterprise assets and data in a secure manner.

Cybersec

Implementing and monitoring security tools; handle cyber security incidents.

Management

Management InfoSec teams.

Testimonials

Resume

Education

2021 - 2022
Universidade Descomplica

MBA in Information Security

2015 - 2020
Federal Institute of Education, Science and Technology of Ceará

Telematics Technology

IFCE Fortaleza

Key Words

  • Governance, Risk & Compliance
  • Awareness Training
  • Cybersecurity
  • Data Privacy
  • Communication
  • BPMN
  • PCI-DSS
  • ISO 27001
  • CIS Controls
  • NIST CSF

Experience

MAR 2025 - Current
Insight Assurance

IT Auditor (ISO 27001)

Perform the day-to-day activities of IT audit engagements based on ISO27001, and readiness assessments.
Evaluate the design and effectiveness of technology controls
Identifies and communicates IT audit findings.

2022 JAN - 2025 FEB
Compass UOL

Senior Information Security Analyst

GRC leader, responsible for maintenance of ISO 27001 certification; performing internal information security auditing using ISO 27001, CIS Controls and NIST frameworks; third-party risk assessment; development and review of policies, processes and procedures; review and respond to RFIs/RFPs and contracts; training on the governance, risks and compliance path for cybersecurity interns; incident handling; security awareness and skills training.

2021 JULY - 2021 DEC
Hapvida

Senior Information Security Analyst

Responsible for developing and reviewing information security standards, policies and procedures; evaluate and validate action plans for information security; defining and monitoring information security requirements with the business areas; performing audits on information systems; assessing and monitoring the maturity level of information security processes; awareness training for employees regarding information security; managing and monitoring activities related to privacy, security and governance via OneTrust platform; maintenance of the cybersecurity program through third-party risk assessment and creation of a mitigation plan against cyber-attacks using the MITRE ATT&CK framework.

2020 JUN - 2021 MAR
Wirelink Telecom

System Supervisor

Responsible for supervising the Systems and Development teams. Conducted the feasibility study, integration and implementation of systems and services; creation, review and application of information security policies based on ISO 27001; configuration and maintenance of on-premises servers (Windows and Linux) and routers/switches (Mikrotik, Huawei, Cisco); training employees; assisting in the analysis and implementation of processes.

Some of my Certifications

Contact