# Daniel Ferreira

Cybersecurity Operations Manager · Software Engineer · Architect · AI harness engineer

Agentic AI specialist focused on Cyber Security Operations and SOC automation. Hands-on, do-it-yourself manager, Software Engineer, and Architect. Highly self-driven, relentlessly curious, and passionate about delivering results at 10x speed. 18+ years of professional experience with a proven track record of delivering large-scale cybersecurity and big data projects. **Strong leadership**, coaching, and strategic communication skills. Recognized high performer, public keynote speaker, and self-taught learner with a high degree of **personal integrity** and a strong team-player mindset.
**Tech stack**: harness Agentic AI engineering and automation solutions, enterprise-ready. Opencode, agent/subagent architectures, Anthropic and OpenAI models (also model-agnostic), secure identity-driven password-less architectures, Microsoft Azure cloud expert, large-scale integration architectures (Service Bus, Kafka, Azure Functions, Storage, Web), C#, SQL Server, PowerShell, Splunk, CrowdStrike, Microsoft Defender Suite, Microsoft Sentinel, and enterprise cybersecurity technologies.

## Profile metrics

- **18+** — professional years
- **12+** — cybersecurity years
- **3** — FTE reports, +15 indirect
- **2** — Expert-level certifications

## Experience

### SKF AB group — The Hague, Netherlands
*Nov 2025 – present*

#### Head of Cyber Security Operations
*Nov 2025 – present*

Head of SOC for IT and OT across ~20 factories. Leading Threat Detection Engineering, Incident Response, Threat Intelligence, Threat Hunting, Vulnerability Management, Offensive Security and Platform Engineering teams. Owner of SIEM, XDR, EDR, CSPM, CASB and OT security platforms.

- Shipped the [Agentic SOC platform](https://cv-daniel.ferreira.fm/portfolio-agentic-SOC.html): identity-first, password-less, AI Agentic architecture.
- Built the harness: specialized agents/subagents, shipped the internal **Cyber MCP** with SSO auth.
- Security engineering and operational delivery increased by ~5x.

### Shell plc — The Hague, Netherlands
*Nov 2016 – May 2025*

#### Lead Cyber Security Architect
*Apr 2023 – May 2025*

Led SOC cyber architecture for group IRM and ERP, hands-on, focused on protecting 10+ cloud tenants, responsible for threat modeling, defining default security controls, contributing to vision and roadmap for global cyber team: SIEM, SOAR, EDR, Vulnerability, IAM, Cloud Posture.

- Delivered multiple six-figure savings through architecture changes.

#### Lead Cyber Security Vulnerability Analyst
*Apr 2020 – Apr 2023*

Led global SOC vulnerability management mission across discovery, analysis, prioritisation, remediation, mitigation and reporting.

- Automated end-to-end vulnerability management; reduced critical attack surface by 99%.
- Built an in-house [**Shodan-like** search engine](https://github.com/daniel0x00/splunk.conf-keynotes/blob/91b0886a7b179cf2d63827b7fa81ddb05ae5f237/Splunk%20.confGO%202022%20Hilversum%20-%20Your%20META(DATA)%20is%20QUEEN%20for%20Cyber-Security%20Vulnerability%20Management.pdf) for IT/OT devices at scale.
- Rapid7, ServiceNow SecOps VR, Splunk, CrowdStrike, Microsoft Defender for Endpoint, Wiz.

#### Senior Cyber Security Data Scientist
*Jun 2019 – Apr 2020*

Delivered ML, AI and NLP strategy for the global SOC Cyber Security team.

- Pitched first version of an AI chatbot for SOC Operations at Integrate 2019, London. Pre-ChatGPT moment!
- C#, Bot Framework, Microsoft LUIS, API Management, Azure Logic Apps and Functions.

#### Cyber Security Threat Hunter
*Nov 2016 – Jun 2019*

Found unknown threats and weaknesses in security controls using SIEM detections, threat intelligence and incident log evidence.

- Group CIO awarded; found two threats that prevented ransomware opportunities.
- Splunk, FireEye HX, CrowdStrike Falcon, Microsoft Defender for Endpoint

### SIA, Indra group — Madrid, Spain
*Apr 2016 – Jul 2016*

#### Senior Cyber Security Consultant · Pentester / Red Team
*Apr 2016 – Jul 2016*

Red-team and offensive security consultant for Active Directory, web applications and perimeter security.

- Obtained Domain Admin privileges in a large Spanish bank red-team assignment.

### Shell plc — Valencia, Venezuela
*Dec 2008 – Feb 2012*

#### Database Administrator / Software Developer
*Dec 2008 – Feb 2012*

Architected, developed and distributed Microsoft SQL Server and C# applications.

- Built a C# integration app and BI solution rolled out across northern Latin America.

## Skills

- **AI-first, agent-enabled SOCs** (opencode, Claude Code, Codex, MCP): Ability to create and maintain Enterprise-ready AI agents for SOC Operations to achieve ~5x delivery.
- **Offensive security** (Red team, C2, Reverse engineering): Red team / Pentest skills.
- **Windows & Linux security** (EDR, Forensics, Logging): Hands-on ops on both OSes: EDR, forensics, IoC hunting; Bash/PowerShell automation from exploit validation at scale to SIEM telemetry pipelines for tens of thousands of servers.
- **Programming & secure coding** (C#, PowerShell, MSSQL, SPL/KQL): Senior dev background: C#, PowerShell, SQL Server, PostgreSQL, SPL, KQL. Now shipping most code through agentic pipelines with review gates, tests and Human-in-the-Loop.
- **Threat modeling & detection** (STRIDE, ATT&CK, Detection-as-code): STRIDE on critical systems and APIs; pragmatic risk assessments; intel TTPs translated to SPL/KQL detections and IR playbooks.
- **Leadership & communication** (C-level comms, MSP management, Coaching): Leads FTEs, contractors, MSSPs and a fleet of AI agents; mentoring and comms up to CIO/CISO; public keynote speaker; yearly anonymous peer feedback.
- **Cloud expertise** (Azure certified, CSPM, Cloud hardening): Azure Expert-certified (Solutions Architect + Cybersecurity Architect). Wiz rollout for multi-cloud CSPM across AWS, Alibaba, Azure China and Azure; hardened PaaS with monitoring and response automation.

## Education

- **[Cybersecurity Master's Degree](https://github.com/daniel0x00/r2dr2-udp-drdos-tool)** — Universidad Europea, Madrid, Spain (Oct 2013 – Jul 2014)  
  1 year, published dissertation, grade 85.60/100.
- **Bachelor of Information Technology** — Universidad Tecnologica del Centro UNITEC, Valencia, Venezuela (Jan 2007 – Dec 2011)  
  5 years, Cum Laude, #1 Honour Roll, grade 87.17/100.
EU officially accredited.

## Certifications

- **[Microsoft Certified: Azure Solutions Architect Expert](https://learn.microsoft.com/api/credentials/share/en-gb/daniel0x00/AC29E0E751C6D24D?sharingId=AE96336F33648BCE)** — holder since 2017 · active
- **[Microsoft Certified: Cybersecurity Architect Expert](https://learn.microsoft.com/api/credentials/share/en-gb/daniel0x00/6E4E954136076FE?sharingId=AE96336F33648BCE)** — holder since 2022 · active

## Honours

- **[TUI CV](https://github.com/daniel0x00/tui-cv) (this project!)** — Terminal-based CV for agents to consume and interact via command-line.
- **[Agentic SOC platform](https://cv-daniel.ferreira.fm/portfolio-agentic-SOC.html)** — Designed and shipped an identity-first, fully audited agentic platform running 24/7 SOC operations.
- **Shell Group CIO Award winner, twice** — Recognized for detecting material cyber risk and preventing ransomware-like opportunities.
- **[Splunk .conf21 speaker](https://github.com/daniel0x00/splunk.conf-keynotes/blob/91b0886a7b179cf2d63827b7fa81ddb05ae5f237/Splunk%20.conf21%20-%20SEC1075A%20-%20Effective%20and%20affordable%20Cyber-Security%20Vulnerability%20Management.pdf)** — Vulnerability Management at scale. Advanced level.
- **[Splunk .confGO Netherlands speaker](https://github.com/daniel0x00/splunk.conf-keynotes/blob/91b0886a7b179cf2d63827b7fa81ddb05ae5f237/Splunk%20.confGO%202022%20Hilversum%20-%20Your%20META(DATA)%20is%20QUEEN%20for%20Cyber-Security%20Vulnerability%20Management.pdf)** — How to build an internal Shodan-like search engine. Advanced level.
- **[Published PowerShell packages and code](https://github.com/daniel0x00?tab=repositories)** — Infoblox Grid, Exchange permissions, Yahoo Finance, FireEyeHX and more.

## Compensation

### Compensation analysis

Lossdog.com analyzes professional worth and compensation from resume and career history.

[View Daniel's total compensation analysis](https://app.lossdog.com/share/profile-report/d2a26f68-00ec-40a2-8a42-f7d95d106201/)

## Contact

- Email: [gourd-farrier.6p@icloud.com](mailto:gourd-farrier.6p@icloud.com)
- LinkedIn: [https://www.linkedin.com/in/daferreira/](https://www.linkedin.com/in/daferreira/)
- GitHub: [https://github.com/daniel0x00](https://github.com/daniel0x00)
- Location: The Hague, Netherlands
- Citizenship: Spain / EU
- Languages: English, Spanish

For privacy reasons and to combat spam, the email shown is a disposable email address that changes over time. You can write there and I will receive it. Please do expect a response from my real email address ending in `@ferreira.fm`.
[PRIVACY.md](https://raw.githubusercontent.com/daniel0x00/tui-cv/refs/heads/main/PRIVACY.md).

## Appendix

### Cyber skills to experience match

| #   | Skills | Experience |
|-----|-------------------|------------------|
| 1   | Offensive security | Strong software engineering background, hence very aware of common developer pitfalls. Performed a red-team exercise in a large Spanish bank and obtained Domain Admin privileges in a 3-week black-box assignment using multiple techniques and custom tooling, including a custom C# C2 and an opsec-tuned Mimikatz build. Also found two major issues internally, one through reverse engineering, in scenarios that could have enabled ransomware on endpoints and highly confidential servers; the CIO individually awarded this work. Deep expertise in databases, JavaScript and web applications also gives me solid ground in SQLi, persistent XSS and [DDoS](https://github.com/daniel0x00/r2dr2-udp-drdos-tool) techniques. |
| 2   | Securing Windows and Linux systems | Daily hands-on experience across both Windows and Linux in cybersecurity operations, scripting, pentesting, EDR, forensics and IoC hunting. I automate most repetitive work in bash and PowerShell for both OS, from exploit validation at scale to remote collection of telemetry from tens of thousands of servers and automated ingestion into SIEM platforms. |
| 3   | Programming experience, secure coding practices, technical background in software development | Senior developer background in C#, [PowerShell](https://github.com/daniel0x00?tab=repositories), SQL Server, PostgreSQL, Splunk SPL and Microsoft KQL. Built and operated large-scale security data pipelines where cost, performance and availability had to be balanced carefully. Consistently applied sound engineering and security practices, from code quality and performance to SAST-driven secure coding awareness and OWASP pitfalls. Also evangelized Azure Logic Apps as a low-cost replacement for Splunk SOAR Phantom, shipping production workflows and apps that saved roughly 500k USD per year. |
| 4   | Threat modeling, Threat intel, Threat detection, risk assessment and mitigation  | Applied STRIDE to critical in-house systems and APIs, identifying realistic abuse cases such as API DoS, WAF bypass, data tampering, information disclosure, privilege escalation on database backends and persistent XSS. Produced pragmatic risk assessments based on likelihood and impact, together with preventive, detective and response recommendations. Worked closely with Threat Intel outputs and translated IoCs and TTPs into detection and response logic, including Incident Management playbooks, in Splunk SPL and Microsoft KQL. Also built an internal threat-intel dissemination tool that used AI to generate tailored executive summaries and personalized communications in Azure Logic Apps + JavaScript for less than 200 USD per year. |
| 5   | AI-first, agent-enabled SOC | Built an AI-first, **Agentic SOC** operating model, [Agentic SOC platform](https://cv-daniel.ferreira.fm/portfolio-agentic-SOC.html). Defined markdown-first SOPs with procedure, triage guidance, examples of true positives and false positives, automation accounts to use, who to contact, and approval-email flows. Created an internal **Cyber MCP**. Heavy use of `opencode` with Enterprise grade deployment, harness engineering, agent/subagent architectures, integrated with OpenAI / Claude LLMs (via Azure Foundry models and AI governance). |
| 6   | CI/CD & code security | Assessed internally developed APIs through both automated and manual DAST, while also reviewing likely attack paths such as DMZ-to-internal-network exposure. Pushed for SAST evidence as part of pre-deployment checks and promoted the use of OpenAPI definitions with predictable HTTP responses so credentialed DAST scans and alerting could be scheduled and scaled. Partnered with the Software Engineering CoE to institutionalize this approach using Invicti. |
| 7   | Cloud expertise | Microsoft Azure certified at Expert level in both [Solution Architecture](https://learn.microsoft.com/api/credentials/share/en-gb/daniel0x00/AC29E0E751C6D24D?sharingId=AE96336F33648BCE) and [Cybersecurity](https://learn.microsoft.com/api/credentials/share/en-gb/daniel0x00/6E4E954136076FE?sharingId=AE96336F33648BCE). Led cloud security capability improvements for multi-cloud environments, including vendor selection and rollout of Wiz to provide unified CSPM visibility across AWS, Alibaba Cloud, Azure China and Azure. Hands-on experience hardening Azure PaaS services with proper logging, monitoring, alerting, false-positive suppression and response automation. |
| 8   | Vendor security, third-party security assessments | Conducted third-party security reviews and tool evaluations, including comparisons across EDR vendors such as CrowdStrike, FireEye HX and Defender for Endpoint. Addressed supply-chain risk through pragmatic controls, for example advocating n-1 upgrade policy except for critical security releases, and asking vendors to separate content and agent releases. Also worked with consultancies to assess the attack surface of M&A companies before and after acquisition. |
| 9   | Vulnerability management, Incident Management, risk-based decision-making | Led vulnerability management for roughly 350,000 IT and OT devices. Reframed what should truly count as Critical by balancing exploitability, business impact and operational trade-offs, then drove prioritization and KPI definition accordingly. Selected and implemented ServiceNow SecOps VR for both Incident and Vulnerability Management, handled major cases such as WannaCry, log4j and ZeroLogon, and delivered a 99% reduction of the Critical attack surface. Also built a [Shodan-style](https://github.com/daniel0x00/splunk.conf-keynotes/blob/main/Splunk%20.confGO%202022%20Hilversum%20-%20Your%20META(DATA)%20is%20QUEEN%20for%20Cyber-Security%20Vulnerability%20Management.pdf) internal discovery and risk assessment platform, published the work, presented it publicly, and influenced a Splunk product feature through direct engineering engagement. |
| 10   | Management, Leadership, Communication | Experience leading direct reports, contractors and MSPs, with strong mentoring and stakeholder communication skills up to CIO and CISO level. Public keynote speaker, collaborative team player and pragmatic risk-based decision-maker. I work well within existing leadership structures, focus on common goals, and actively seek feedback through anonymous peer surveys every year. |
