Senior Cybersecurity Consultant

Pedro Lima

Helping organisations detect, investigate and respond to cyber threats.

Incident Response · Detection Engineering · Security Operations

Open to opportunities

Based in Lisbon · EU citizen · Open to relocation in Switzerland

Pedro Lima
Scroll to explore
01 / About

Security operations with a consulting mindset.

I’m a cybersecurity consultant with a hands-on background in Security Operations, Incident Response and Detection Engineering. I work across complex enterprise environments, combining technical investigation with security automation, detection improvement and client advisory.

I particularly enjoy the point where technical depth meets decision-making — understanding what happened, assessing the real risk and helping teams respond effectively.

02 / Experience

Professional journey

Deloitte Portugal

Cybersecurity Senior Consultant Promoted

May 2025 — Present
Senior Cybersecurity Consultant Jul 2026 — Present

Lead L2/L3 incident response and threat investigations across enterprise environments. Develop detection capabilities and security automation, advise clients on security technologies and best practices, and support major security incidents alongside global security teams.

Cybersecurity Consultant May 2025 — Jul 2026

Advanced threat monitoring and detection across endpoint, cloud and SIEM environments, with ownership of investigation, containment, remediation, detection improvement and risk prioritisation.

Additional responsibility — Internship Mentor Jun 2025 — Aug 2025

Supervised interns researching and evaluating deepfake detection technologies for potential client applications.

Capgemini Engineering Portugal

Consultant — SecOps

Feb 2024 — May 2025

Worked across threat monitoring, detection, incident response, vulnerability management and security automation in enterprise environments, collaborating with IT, Legal, Executive and stakeholder teams.

03 / Why Me

How I work when it matters

My CV shows where I have worked and the technologies I use. This is the part that explains how I approach problems, work with people and contribute when situations become complex.

01

Investigative mindset

I don’t stop at the alert. I want to understand what happened, why it happened and what the real risk is before considering the problem properly addressed.

02

Context before conclusions

Security signals rarely exist in isolation. I combine technical telemetry with the wider operational context before making a judgement, escalating an incident or recommending action.

03

Ownership under pressure

When I take responsibility for a security problem, I stay with it until it is properly understood and addressed — involving additional expertise or resources when the situation requires it.

04

People & communication

I adapt technical communication to the person in front of me and try to be someone colleagues can rely on. With junior team members, I prefer to guide without immediately taking the problem away from them.

What I value
Rigour Teamwork Ownership Curiosity Continuous improvement
04 / Expertise

Core areas

01

Incident Response

Investigation, containment, remediation, escalation and support during major security incidents.

02

Detection Engineering

Detection use cases, alert tuning and security automation designed to improve SOC effectiveness.

03

Threat Investigation

Threat monitoring, triage and investigation across endpoint, cloud, network and SIEM telemetry.

04

Security Consulting

Technology advisory, security best practices, stakeholder coordination and knowledge transfer.

05 / Selected Responsibilities

Where I add value

Major Incident Response

Support and coordination during high-severity security incidents.

Detection Improvement

Development and tuning of detections to improve SOC effectiveness.

Client Advisory

Security technology assessment, recommendations and stakeholder communication.

Team Development

Supporting junior colleagues through guidance, mentoring and knowledge transfer while giving them room to grow independently.

06 / Technology

Security stack

SIEM

Splunk · Microsoft Sentinel · IBM QRadar

Endpoint Security

CrowdStrike Falcon · Microsoft Defender

Network Detection

Darktrace

Security Operations

Tenable · Cortex XSOAR · CyberArk

07 / Why Switzerland

A professional move with personal meaning.

Switzerland is more than a professional move for me.

This is a relocation with long-term intent.

With close family established in the country for almost a decade, Switzerland has been part of my life for years. Through my visits, I’ve had the opportunity to experience the country personally and, over time, I genuinely fell in love with it and began to see it as a place where I could build my future.

I’m looking for a long-term move — not simply a new role. I want to continue growing professionally in cybersecurity while building a life and, eventually, a family in a country to which I already feel personally connected.

For me, relocating to Switzerland represents the opportunity to combine professional ambition with a place where I can genuinely see myself settling down for the long term.

08 / Background

Education, training & languages

Education

BSc in Computer Science ISEC
CTeSP in Mobile Development ISEC

Certifications & Training

Google Cybersecurity Professional Google · 2024
Cybersecurity Fundamentals IBM SkillsBuild · 2022
Introduction to Cybersecurity Cisco Networking Academy · 2023
CPC CyberArk In progress

Languages

Portuguese Native
English Fluent
German Learning
09 / Outside Cybersecurity

There’s more to me than security alerts.

Outside work, I enjoy activities that combine discipline, competition, teamwork, problem solving and attention to detail.

01

Muay Thai

Discipline · Focus · Resilience

02

Padel

Competition · Teamwork

03

Football

Team spirit · Competition

04

Automotive Mechanics

Hands-on problem solving · Curiosity

05

Vehicle Detailing

Precision · Patience · Attention to detail

References Available upon request

Let’s connect

Let’s build secure systems — and stronger responses when things go wrong.

Open to cybersecurity opportunities in Switzerland, particularly across Incident Response, Security Operations and Detection Engineering.