Kelvin Sécolo

Business Analyst

London, England, United Kingdom9 yrs 1 mo experience
Highly Stable

Key Highlights

  • Reduced vulnerability backlog by 60% in 2022.
  • Increased compliance adherence through training for 600+ IT analysts.
  • Launched Nubank's public Bug Bounty Program, saving significant costs.
Stackforce AI infers this person is a Cybersecurity expert in Fintech with a strong focus on Vulnerability Management.

Contact

Skills

Core Skills

Vulnerability ManagementIncident Response

Other Skills

Risk ManagementCloud ComputingJiraSlackAutomationHackerOneBugcrowdJamfProMicrosoft OfficeCrisis ManagementIncident ManagementCybersecurity Incident ResponsePenetration TestingMalware AnalysisSecurity Operations Center

About

Hey there! 👋 I'm a CyberSecurity professional with 10+ years of career and still learning something new every day. Since 2015 I have been providing IT services to multinational companies such as Hewlett Packard and Nubank that have turned me into the professional that I proudly am today. ⚙️ My mission: I bring to the table a technical framework by blending the Secure Software Development, Vulnerability Management and Incident Response disciplines into a unified, practical method to solve real-world, business and engineering scenarios. This approach allows me to observe problems, understand pain points, transform them into clear, actionable steps, handle risks and vulnerabilities efficiently and also ensure that security incidents are properly contained, resolved, and learned from with minimal damage to a company's operation. I am passionate and inspired about using this approach to strengthen the security posture of organizations and contribute to a culture of continuous improvement in a friendly way. ⏰ The present moment: My day-to-day is all about showing potential vulnerabilities to everyone in their stack before they become a problem. I lead the lifecycle of a vulnerability backlog of different severities and sources from the very beginning, until their closure by collaborating with external security researchers while orchestrating internal teams and dealing with realistic deadlines and roadmaps. 🏆 Achievements that I'm proud of: (scroll to the Honor & Awards section for more) • Increased compliance adherence and customer satisfaction applying recurring training to 600+ IT analysts from Europe, US and Mexico about Security Awareness, Incident Response, and Problem Management. • Identified and mitigated 8.000+ vulnerabilities through JamfPro optimizing Patch Management policies. • Reduced a company's backlog of vulnerabilities by 60% in 2022, dealing with at least 5 different sources of discovery, Low to Critical severities, more than 50 teams, their roadmaps, Risk Acceptance exceptions, and auditing routines. • Implemented an in-house Jira–Slack automation that now handles follow-ups for 80%+ of all vulnerability tickets, eliminating hundreds of manual check-ins per month and boosting team productivity by ~30–40%. 📚 Currently studying: CompTIA CySA + 💻 Platforms and Tools: HackerOne | Bugcrowd | Jira | ServiceNow | Tenable | Nessus | Splunk | Looker | Python | Burp Suite 💬 Feel free to DM! I would love to talk about interests in common and collab.

Experience

Nubank

2 roles

Senior Vulnerability Management Analyst

Promoted

Jan 2024Present · 2 yrs 3 mos

  • Nubank is one of the largest digital banks in the world and a leading fintech in Latin America with over 10 years of operations, serving more than 90 million customers across Brazil, Mexico, Colombia and United States. In 2025, Nubank was ranked as the most valuable company in Brazil and the second one in Latin America.
  • 🎯 Main Projects
  • Implemented an in-house Jira–Slack automation that now handles follow-ups for 80%+ of all vulnerability tickets, eliminating hundreds of manual check-ins per month and boosting team productivity by ~30–40%.
  • Achieved a 60% backlog reduction of vulnerabilities (Scanners, GitHub, Ethical Hacking Tests and External Consulting) through process automation;
  • Launched, led, and still act as full owner of Nubank’s public Bug Bounty Program from the ground up, driving partnerships with HackerOne and Bugcrowd, managing scope, triage, and orchestration between internal teams and external researchers saving an estimated US$ 25k–45k/year in direct testing costs, plus additional six-figure risk reduction from early discovery of high-impact vulnerabilities.
  • Published more than 200 weekly editions of a company’s Infosec HUB, curating the latest cybersecurity threats out there and cross-checking them against Nubank’s tech stack; analyzing exploited vulnerabilities in the market to proactively mitigate risk and exposure;
  • Authored a Patch Management initiative, enabling automation with Jamf that fixed over 20.000 workstation vulnerabilities and supported the revocation of 8.000 exposed secrets.
  • 💼 Responsibilities
  • Review findings from tools that identify security vulnerabilities; verify accuracy, identify and validate false positives, and identify systemic patterns;
  • Coordinate remediation deadlines across multiple teams, ensuring timely closure of high-risk vulnerabilities within SLA, and operating with Risk Management & Governance maintaining focus on Threat Intelligence and measurable progress.
Risk ManagementCloud ComputingVulnerability ManagementIncident Response

Vulnerability Management Analyst II

Sep 2021Dec 2023 · 2 yrs 3 mos

Hp

3 roles

Senior Incident Response, Problem and Crisis Manager

Promoted

Jan 2019Sep 2021 · 2 yrs 8 mos

  • Hewlett-Packard is a large-scale IT Service Delivery Outsourcing enterprise with approximately 125,000 employees and high-end customers like Braskem, Coca-Cola, BMW, Ferrari, Heineken and others, operating in more than 70 countries. HP merged its IT Services with Computer Sciences Corporation (CSC) and is now called DXC Technology.
  • 🎯 Main Projects
  • Led the end-to-end service restoration for a high-profile client after a global ransomware incident in 2019, coordinating incident response, security teams, and backup & recovery processes ensuring business continuity and minimizing financial and operational damage by approximately 70–80%;
  • Led the development and in-person presentation of 20+ monthly incident reports, translating technical data into strategic recommendations that reduced incident volume, decreased risk exposure, and improved operational efficiency with measurable cost savings.'
  • Orchestrated crisis rooms reducing escalation noise by ensuring only ~20% of critical incidents required crisis response, with ~2% impacting the business.
  • 💼 Responsibilities
  • Delivered recurrent training to a staff group of +600 engineers on incident response and crisis management processes, ensuring alignment with organizational procedures;
  • Coordinated the response to incidents from initial detection and triage through to resolution, closely with the follow-the-sun international teams, ensuring continuity and effective handovers where required, and that the customer service was delivered in line with agreed quality;
  • Acted as the central lead for security incident communications, meetings, action tracking, and stakeholder updates maintaining clear incident reports, documentation, and post-incident reviews (including lessons learned and post mortems);
  • Managed and matured the operational relationship, face to face, with high-end customer such as Braskem, Coca-Cola, Ferrari, and Mercedes-Benz ensuring effective detection, escalation and response;
Risk ManagementMicrosoft OfficeIncident Response

Storage & Backup Analyst II

Promoted

Jan 2017Dec 2018 · 1 yr 11 mos

  • 💼 Responsibilities
  • Managed Backup Policies and Routines (end to end configuration, rerunning failed backups) supporting NetWorker Legato (EMC), ARCserve, and Data Protector (HP) as main tools;
  • Acted as a L3 escalation for critical storage & backup incidents and collaborated with international teams to support and oversee lower-level activities;
  • Managed SAN fabrics (Brocade/Cisco), zoning, switch upgrades, and fabric health. Performed storage provisioning, zoning, replication, firmware upgrades, and performance tuning.
Microsoft OfficeCloud Computing

IT Incident Response Program

Jan 2015Dec 2016 · 1 yr 11 mos

  • Hewlett Packard Enterprise is a major global IT company with around 67,000 employees worldwide and annual revenue of about $34.3 billion, serving enterprises across cloud, networking, storage, and edge computing markets.
  • 🎯 Main Projects
  • Completed a 2 year Job Rotation program across all IT departments, gaining end-to-end visibility of the IT outsourcing demand flow, since the client request until the final delivery of the service contract;
  • Used the 360 degree perspective to develop process improvements, individually to each department I interned in.
  • The Rotation was structured in three main tracks:
  • 1. Process areas (ITIL-based): Change, Incident, Problem, and Service Level Management (SLM);
  • 2. Technical operations: Network, Security, Database, Web, Storage, Backup, Intel, and Unix;
  • 3. Project Management & Customer Facing;
  • After the rotation I have been selected amongst 20 other interns to a permanent role in the Storage & Backup department.
Microsoft OfficeCloud Computing

Education

Universidade Metodista de São Paulo

Associate degree — Information Technology

Jan 2014Dec 2018

Impacta Tecnologia

Professional Development Course — Computer Programming

Jan 2012Present

Stackforce found 100+ more professionals with Vulnerability Management & Incident Response

Explore similar profiles based on matching skills and experience