Clisnmamm Herbete

Versatile information security analyst professional, based in Fortaleza, Brazil, with 8 years of extensive experience working across multiple domains of IT infrastructure and cybersecurity.

What I Do

Audit

Information security audits using best know frameworks like ISO 27001, CIS Controls, NIST CSF, PCI-DSS.

Security awareness

Provide training for work force on how to interact with enterprise assets and data in a secure manner.

Cybersec

Implementing and monitoring security tools; handle cyber security incidents.

Management

Management InfoSec teams.

Testimonials

Resume

Education

2021 - 2022
Universidade Descomplica

MBA in Information Security

2015 - 2020
Federal Institute of Education, Science and Technology of Ceará

Telematics Technology

IFCE Fortaleza

Knowledges

  • Governance, Risk & Compliance
  • Awareness Training
  • Cybersecurity
  • Data Privacy
  • Communication
  • BPMN
  • PCI-DSS
  • ISO 27001
  • IT Audit
  • CIS Controls
  • NIST CSF

Experience

MAR 2025 - Current
Insight Assurance

IT Auditor (ISO 27001)

Perform the day-to-day activities of IT audit engagements based on ISO27001, and readiness assessments.
Evaluate the design and effectiveness of technology controls
Identifies and communicates IT audit findings.

2022 JAN - 2025 FEB
Compass UOL

Senior Information Security Analyst

GRC leader, responsible for maintenance of ISO 27001 certification; performing internal information security auditing using ISO 27001, CIS Controls and NIST frameworks; third-party risk assessment; development and review of policies, processes and procedures; review and respond to RFIs/RFPs and contracts; training on the governance, risks and compliance path for cybersecurity interns; incident handling; security awareness and skills training.

2021 JULY - 2021 DEC
Hapvida

Senior Information Security Analyst

Responsible for developing and reviewing information security standards, policies and procedures; evaluate and validate action plans for information security; defining and monitoring information security requirements with the business areas; performing audits on information systems; assessing and monitoring the maturity level of information security processes; awareness training for employees regarding information security; managing and monitoring activities related to privacy, security and governance via OneTrust platform; maintenance of the cybersecurity program through third-party risk assessment and creation of a mitigation plan against cyber-attacks using the MITRE ATT&CK framework.

2020 JUN - 2021 MAR
Wirelink Telecom

System Supervisor

Responsible for supervising the Systems and Development teams. Conducted the feasibility study, integration and implementation of systems and services; creation, review and application of information security policies based on ISO 27001; configuration and maintenance of on-premises servers (Windows and Linux) and routers/switches (Mikrotik, Huawei, Cisco); training employees; assisting in the analysis and implementation of processes.

Some of my Certifications

CSA Certificate of Competence in Zero Trust (CCZT)

27 Jan 2026

CSA Certificate of Cloud Security Knowledge v.5

22 Dec 2025

AWS Certified Cloud Practitioner

28 Jun 2023

Contact