Solutions Architecture • Security Engineering & Cloud

RESILIENT ARCHITECTURE.
PROVEN DEFENSE.

I operate where identity, cloud platforms, operational resilience, data protection, and AI agents intersect — transforming ambiguous enterprise risk into hardened systems engineered to endure under real pressure.

01 / Practice Areas

Where I operate

My work connects deep engineering precision to executive business consequence. From authentication tokens and multicloud identity architecture to resilience decisions, automation, and sustainable cost reduction.

A — IDENTITY & ACCESS (IAM / ZTA)

Identity Architecture & Zero Trust Governance

Worked on IAM architecture and governance for over 45,000 accounts at Itaú Unibanco. Led the strategic migration project from IBM ISAM to Azure Entra ID, deployed automated identity lifecycle workflows with SailPoint IdentityIQ, Conditional Access, and adaptive MFA, cutting critical access lead time by 40% aligned with ISO 27001 and NIST.

Azure Entra ID SailPoint IGA Zero Trust Conditional Access OAuth 2.0 / SAML PIM
B — CLOUD & RESILIENCE (AZURE & MULTI-CLOUD)

Mission-Critical Architecture & Well-Architected

Worked on enterprise architectural assessments at Avanade (Microsoft) for US clients. Engineered multiregion failover and resilience topologies in Azure, eliminating over 40 single points of failure (SPOFs), reaching 99.99% service availability, and rolling out cloud-native posture controls with Azure Defender for Cloud and Health Family.

Azure Solutions Architect AWS Well-Architected BCDR 99.99% Defender for Cloud Zero SPOF
C — GENERATIVE AI & WORKSPACE

Agentic AI Governance & Enterprise RAG

Worked on prompt engineering, enterprise RAG pipelines, and business task agentification using LangGraph and CrewAI. Engineered runtime guardrails to prevent authority escalation across autonomous agents, and orchestrated the enterprise rollout of Microsoft Copilot Studio and DEX, enforcing strict data boundaries and Graph authorization.

Agentic AI Microsoft Copilot Secure RAG LangGraph Guardrails DEX
D — DEVOPS, PLATFORM & SRE

Platform Automation & Reliability Engineering

Modernized the engineering infrastructure at TAESA by establishing a DevOps culture, automated CI/CD pipelines in Azure DevOps, and container orchestration with Docker and Kubernetes. Engineered proactive observability using Dynatrace, Datadog, and Grafana, deploying Python and PowerShell automations to accelerate delivery and operational stability.

CI/CD Kubernetes Docker Dynatrace Datadog SRE PowerShell / Python
E — OFFSHORE & MISSION-CRITICAL INFRASTRUCTURE

Hyperconvergence & High-Severity Operations

Worked on managing Dell VxRail hyperconverged infrastructure (VMware with 300+ VMs) at PRIO, spanning corporate offices and offshore vessels (FPSOs). Engineered high availability for SAP S/4HANA, satellite link redundancy, secure remote access via BeyondTrust, and hybrid backup routines with NetApp and Amazon S3.

Dell VxRail VMware SAP S/4HANA Offshore FPSOs BeyondTrust Amazon S3
F — DIGITAL TRANSFORMATION & FINOPS

Platform Migration & Cloud Cost Optimization

Modernized the operational cost structure at TAESA through disciplined FinOps practices, delivering a 30% reduction in OpEx (R$ 12 million saved) and a 40% reduction in Microsoft/Azure licensing costs. Led the full migration project of the SAP S/4HANA ecosystem to private cloud and spearheaded the delivery of a R$ 2.5M corporate Datacenter.

FinOps OpEx -30% (R$ 12M) SAP S/4HANA Datacenter R$ 2.5M TCO Cloud Contracts
G — TECHNICAL LEADERSHIP & M&A INTEGRATION

Strategic IT Management & Post-Merger Consolidation

Led cross-functional teams of up to 15 engineers and analysts across multinational operations. Planned and deployed the entire IT infrastructure for the Sheraton Santos hotel for Marriott International — the first LATAM integration following the Marriott/Starwood merger —, sustaining 100% operational uptime during the Rio 2016 Olympic Games.

Marriott International M&A Integration Leadership 15+ Rio 2016 SLA 100% ServiceNow
H — COMPLIANCE & CYBER DEFENSE

Security Auditing, CTEM & Defense-in-Depth

Worked on enterprise audits as an ISO/IEC 27001 Lead Auditor, designing controls aligned to NIST SP 800, CIS Benchmarks, and GDPR/LGPD. Engineered continuous threat exposure management (CTEM with XM Cyber), WAF governance, perimeter protection, and XDR architecture, actively reducing attack surfaces across hybrid cloud estates.

ISO 27001 Auditor NIST CTEM / XM Cyber WAF & XDR LGPD Risk Management

Security is not the number of controls you own. It is the set of assumptions an adversary or system failure cannot break.

Deny standing privileges by default (ZSP) Production access must be ephemeral, scoped just-in-time, and continuously verified. Static credentials in servers or databases are latent liabilities waiting to be exploited.
Follow the actual flow of data and tokens Architecture blueprints and compliance spreadsheets are hypotheses. Real protection is measured where identity, sessions, APIs, endpoints, and effective permissions meet in production.
Test claims through adversarial validation Vendor marketing and licensing terms do not substitute for empirical stress testing, failover simulations, and continuous verification of defensive posture.
Design for blast radius containment Operational failures and compromise attempts will occur. Mature engineering prioritizes rapid isolation, instantaneous authority revocation, and continuous business continuity.
02 / About

Pragmatic by method.
Resilient by design.

Carlos Eduardo Barbosa is a Senior Solutions Architect with over 15 years of technical and executive experience designing, modernizing, and hardening complex enterprise environments. Holding a B.S. in Computer Engineering and an Executive MBA in IT Management from FIAP, he merges deep systems infrastructure and security engineering with financial and strategic business rigor.

Throughout his career, he worked with industry leaders across banking, energy, oil and gas, global consulting, and hospitality — including Itaú Unibanco, Avanade (Microsoft), TAESA, PRIO, and Marriott International. He led the migration project of 45,000 user identities to Azure Entra ID, engineered mission-critical multiregion cloud topologies with 99.99% availability, and modernized corporate cost structures via disciplined FinOps, delivering over R$ 17 million in verified OpEx savings.

At the cutting edge of platform modernization, he engineered runtime security guardrails for autonomous AI agents and Microsoft Copilot, managed multinational post-merger technology consolidations, and conducted rigorous corporate audits as an ISO/IEC 27001 Lead Auditor, converting regulatory frameworks into reliable, operable systems.

Core FocusCloud Solutions Architecture & Azure Resilience
Identity SecurityZero Trust, Entra ID, SailPoint & Ephemeral Privileges
Applied AI & AgentsLLM Governance, Copilot Studio & Secure RAG
Platform EfficiencyFinOps, TCO Reduction & DevOps/SRE Automation
Compliance & AssuranceISO/IEC 27001 Lead Auditor, NIST & CTEM
03 / Credentials & Education

Validated expertise

Global certifications and graduate education covering cloud architecture, identity security, governance, and computer engineering.

Cloud Architecture

Azure Solutions Architect Expert (AZ-305)

Microsoft Certified

Cloud Architecture

Solutions Architect — Associate (SAA-C03)

Amazon Web Services (AWS)

Information Security

ISO/IEC 27001 Lead Auditor

ISMS Global Standard

Identity Security

Certified Identity Security Leader

SailPoint Technologies

Exposure Management

Continuous Threat Exposure Management (CTEM)

XM Cyber Specialist

Cloud Platform

Oracle Cloud Infrastructure (OCI) 2025

Oracle Certified Architect

Governance & Operations

ITIL 4 Foundation & COBIT 2019

AXELOS / ISACA

Executive Graduate Degree

MBA in IT Strategic Management

FIAP • São Paulo, Brazil

Engineering Degree

B.S. in Computer Engineering

Universidade Estácio de Sá • Rio de Janeiro