My Timeline

1983 to 1991: The beginning

My story with computers began around 1983, when I was eleven and living in France. A family friend let my brother and me play an asteroids game in the computing lab where he worked. Soon came our first home computers: a Commodore 64, a TK 3000, and then a PC. With each machine, we went a little deeper—from games and BASIC to floppy-disk structures, binary and hexadecimal, sector editors, computer viruses, and our first experiments with reverse engineering. I also completed a technical high-school program in electronics and, at seventeen, earned an internship at IBM as a computer maintenance technician. There I encountered mainframes, data centers, IBM’s worldwide private network, early antivirus research, and Token Ring. It was my first glimpse of computing at a global and professional scale.

1992 to 1996: UFMG, the early internet, and cryptography

At UFMG, where I studied Computer Science, I gained access to the internet before the Web became widely available. We used email, FTP, Telnet, Gopher, mailing lists, BBSs, and text-based online games. Later, we experimented with HTML and Java while the Web was still taking shape. The university laboratories were also a breeding ground for computer viruses. My brother and I identified previously unknown malware, sent samples to antivirus researchers, and followed international discussions through the Virus-L mailing list. An assignment on RSA and my discovery of PGP opened the door to cryptography, which became the focus of my undergraduate research and final project. I also spent a semester at Concordia University in Montreal. After returning to UFMG, I helped run the university’s junior enterprise and co-founded Expert Solutions. The company never became a successful business, but it gave me an early education in entrepreneurship, commitment, timing, and risk.

1996 to 1998: Unicamp, a master’s degree, and teaching

After graduation, I moved to Campinas for a master’s degree at Unicamp. I joined the cryptography group and focused on electronic payment systems, studying eCash, SET, micropayments, formal methods, and pay-per-use software at a time when online commerce was still searching for practical and secure payment models. During this period, I married, became a father, and completed much of the thesis away from Campinas. Seeking a stable job, I applied for a faculty position at the Federal University of Lavras and placed first. At UFLA, I helped build a young Computer Science program, design its courses, introduce object-oriented programming with Eiffel from the first semester, and modernize the university’s infrastructure. Along with other new faculty members, I helped turn an unfinished fiber-optic project into a functioning campus network. After two years, I returned to Unicamp for a PhD.

1999 to 2006: Research, industry, and corporate security

My PhD research explored blinded-key signatures and their possible use in protecting mobile agents. I published papers and developed the protocol, but struggled to produce the formal security proof later required for the thesis. Having my defense canceled after years of work was devastating. I had reached the point at which the end seemed close, only to see it suddenly taken away. The disappointment drained much of the energy I still had for the project, and I gradually abandoned the PhD. While studying, I joined Intelligenesis, an American startup attempting to build artificial general intelligence for financial applications. After the dot-com crash ended that job, I moved to BMS, the IT company of the Belgo-Mineira group, where I worked with corporate networks, firewalls, antivirus, high availability, traffic management, virtualization, and information security policy. In 2003, my family and I moved to Brasília, where I worked at BRB and later as a security consultant. Those roles taught me that security in large organizations involves governance, budgets, client relationships, corporate politics, and ethical judgment as much as technology.

2006 to 2012: The public sector and the security community

In 2006, I joined the Central Bank of Brazil after placing first for an IT infrastructure position. I worked with firewalls, application security, data protection, secure development, and the Brazilian Payment System. One of the most important projects was modernizing the cryptographic mechanisms used in communications between the Central Bank and financial institutions. In 2008, I moved to the Chamber of Deputies, where I created an internal secure-development course, built an open-source web application firewall using ModSecurity, proposed the creation of the .leg.br domain, and helped establish the Chamber’s incident response group. In parallel, my involvement with the security community grew. I became active in OWASP, helped organize AppSec Brasil 2009 and later editions, led the Brasília chapter, and joined OWASP’s international Conferences Committee. After years of applying for positions abroad, I was selected for a network-security role at the United Nations in New York and moved there in February 2012.

2012 to 2015: The United Nations in New York

I arrived at the UN to take care of the firewalls, but the scope of the job expanded quickly. I inherited environments weakened by years of technical debt and worked to introduce default-deny policies, modernize equipment, automate DNS and NTP administration, reorganize network architecture, and improve remote access, proxies, authentication tokens, and security monitoring. I also became responsible for a large and fragile Active Directory environment and helped respond to signs that an attacker had obtained domain-administrator privileges. Log analysis uncovered malware, compromised servers, and targeted attacks, leading to incident-response work and cooperation with the FBI. Hurricane Sandy combined the professional and personal sides of that period in a single crisis: my family had to evacuate our apartment while, at work, we coordinated the shutdown and restoration of the UN’s main data center as floodwater approached. Over time, I became responsible for much of the UN campus network in New York, working under operational pressure in a complex global organization.

2015 onward: Vienna and international technical leadership

After about three years in New York, the pace and stress of the city began to wear us down. I was selected to lead the Linux administration unit at the CTBTO in Vienna. The move, in August 2015, was a promotion within the United Nations common system and marked a new stage of my career: international technical leadership in a new organization, city, and country. This book ends at that transition.

The connecting thread

Looking back, I do not see a carefully planned or linear career. I see layers accumulating over time: electronics, programming, viruses, networks, cryptography, academic research, teaching, infrastructure, corporate security, governance, public service, technical communities, incident response, and leadership. At different moments, I was a student, researcher, professor, entrepreneur, systems administrator, consultant, security specialist, community organizer, public servant, and manager. Some projects succeeded; others failed. Bad bosses, generous colleagues, family choices, professional communities, unexpected crises, and simple luck all influenced the direction of the journey. The strongest connection between these experiences is curiosity: the desire to understand how complex systems work. Over time, that curiosity was joined by humility, ethics, accountability, and the responsibility to make systems not only function, but function more securely and reliably for the people who depend on them.