© Mapbox, © OpenStreetMap
Carlos Gonçalves

Carlos Gonçalves

Principal Security Engineer @ Banco do Brasil

Brasília, Brazil

Actions

Carlos Gonçalves is a Principal Security Engineer at a large Brazilian financial institution, where he leads cross-domain threat-led defense for an environment serving tens of millions of clients across 88 countries. With 12+ years in financial-sector security, he has spoken at conferences such as RSA Conference and BSides on intelligence-driven purple teaming and attacker journey mapping. His background in physics informs how he approaches security problems.

Area of Expertise

  • Information & Communications Technology

Topics

  • Threat Intel
  • Threat Hunting
  • Threat Intelligence
  • Cybersecurity Threats and Trends
  • Cyberthreats
  • Cyber Threat Intelligence
  • Red Team
  • Red Teaming
  • Red Team / Blue Team / Purple Team
  • purple team
  • Purple Teaming
  • Pentesting
  • Mobile Pentesting

The Attacker Journey: Mapping Techniques Across Security Domains

Techniques classified as rare in global frameworks turn out to be endemic when you look across security domains. In one regional financial ecosystem, hardware-based attacks have been operationally recurrent for over a decade — visible to adjacent security teams long before cyber defenders recognized the pattern.

This talk shares the lessons learned from trying to solve this problem firsthand. Working in cyber defense and seeing attacks flow into adjacent domains with no shared visibility, we set out to build a cross-domain taxonomy modeled on MITRE ATT&CK to map attacker journeys that no single team could see alone. The talk covers what happened when existing global frameworks did not fit regional operational needs, the engineering mistakes and course corrections along the way, and what it took to reach operational use — including automated pipelines that generate cross-domain attack flows and prioritization. The focus is on the journey and what went wrong, not just the result.

A public case study from a Brazilian federal agency illustrates how the same pattern plays out across sectors. Attendees will leave with a concrete understanding of how fragmented visibility creates blind spots — regardless of which domains their organization defends.

1st CSO 360 + CISO 360 Latam

December 2025 Rio de Janeiro, Brazil

RSA Conference 2025

- Lessons Learned from Implementing an Intel-Based Purple Teaming Process
- Is Threat Intel Answering the Right Questions?

April 2025 San Francisco, California, United States

FS-ISAC 2024 Americas Fall Summit

October 2024 Atlanta, Georgia, United States

BSides Las Vegas 2024

August 2024 Las Vegas, Nevada, United States

8th CISO 360

June 2024 Marseille, France

BSides Lancashire 2024

March 2024 Lancaster, United Kingdom

Security Leaders Brasília 2024

March 2024 Brasília, Brazil

Carlos Gonçalves

Principal Security Engineer @ Banco do Brasil

Brasília, Brazil

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top