Jean Neves

Endpoint Security & Systems Engineer

IT Analyst / Team Lead at BTG Pactual • M.S. Cybersecurity at NYU Tandon

jeannevesit.com
Scroll to explore
Jean Neves

M.S. Cybersecurity

NYU Tandon School of Engineering

Expected Graduation: 2027

About Me

Endpoint-focused IT/security professional with 5+ years administering enterprise device fleets end to end — provisioning, compliance, and lifecycle — through Microsoft Intune, Jamf Pro, and Windows Autopilot. Background spans the full endpoint stack: MDM policy and compliance, patch/software deployment (PDQ Deploy), scripting-driven automation, and endpoint-adjacent identity controls (Conditional Access, Entra ID, privileged access).

Currently pursuing an M.S. in Cybersecurity at NYU Tandon, where recent project work includes building EDR-triggered endpoint containment and self-remediation tooling. Targeting endpoint security engineering roles where device lifecycle ownership meets detection and response.

Core Expertise

Endpoint Security & Management

Microsoft Intune, Jamf Pro, Windows Autopilot, macOS & Windows administration, PDQ Deploy patch/software distribution, and device compliance reporting.

Automation & Scripting

PowerShell, Python, Bash — custom endpoint automation scripts, security auditing/reporting queries, and automated deployment tooling.

Identity & Directory Services

Entra ID, Active Directory, hybrid identity architecture, Conditional Access policies, Group Policy (GPO), and OU structure management.

Privileged & Identity Governance

CyberArk PAM, Senha Segura Vaulting, Azure Just-in-Time (JIT) access policies, SailPoint provisioning, and Okta identity integrations.

Networking & Security

TCP/IP, DNS, DHCP, VPN (Palo Alto GlobalProtect), Netskope CASB/DLP, Zscaler Secure Web Gateways, and Barracuda WAF rules.

SaaS & Collaboration Platforms

Microsoft 365, Exchange Online, SharePoint Online, Teams governance, Google Workspace directory, Slack, and Zoom administration.

Ticketing & Documentation

Jira Service Desk, Zendesk ticketing workflows, Confluence documentation, operations runbooks, and SLA compliance standards.

Featured Security Projects

Endpoint SOAR GCP Cloud Active

NevesSec ERCO: Endpoint Response & Compliance Orchestrator

Developed and deployed a dual-mandate Endpoint Detection, Response, and MDM automation gateway that bridges security enforcement with user self-remediation.

Simulates critical EDR alerts (Wazuh/CrowdStrike) executing on endpoints, which trigger automated REST API calls to isolate devices via mock Mobile Device Management (MDM - Jamf/Intune) and suspend SSO sessions in Identity Providers (Google Workspace). Integrates a mobile-responsive employee self-remediation portal where users can scan their own systems, clean threats, and restore network access instantly.

Python FastAPI SQLite Wazuh Webhooks Intune/Jamf API Google Admin SDK Docker
Orchestration Gateway
erco-soar:~$ tail -f data/orchestrator.log
[22:04:12] [EDR_ALERT] CRITICAL CobaltStrike.Beacon on jean-macbook-pro.
[22:04:13] [MDM_API] POST /api/v1/devices/15/isolate -> Status: 202 Accepted.
[22:04:13] [IDP_API] POST /users/jean.neves/suspend -> G-Suite session revoked.
[22:06:45] [SELF_HEAL] Local scan completed. Malware quarantined.
[22:06:46] [MDM_API] POST /api/v1/devices/15/restore -> Network active.
[22:06:46] [IDP_API] POST /users/jean.neves/unsuspend -> SSO session active.
Live AI Project GCP Cloud Active

NevesSec: Autonomous AI-Powered SOC Analyst

Designed and deployed a 24/7 Security Operations Center pipeline in Google Cloud Platform. The system automatically ingests system logs, malicious URLs, and threat telemetry from live honeypots, forwarding them via webhooks to invoke a Gemini AI L2 Analyst agent in n8n.

The AI agent queries VirusTotal, performs automated threat audits, maps attacks to MITRE ATT&CK, blocks threat IPs in Palo Alto firewalls, and updates the custom SIEM dashboard. Reduces manual alert triage time by 85% and processes up to 100+ telemetry incidents daily.

GCP VM Docker Compose n8n Gemini 2.5 FastAPI Cloudflare Tunnels
NevesSec Control Center
JeanNeves-SOC:~$ docker compose ps
soc-n8n Up 24/7 (Port 5678)
mock-siem Up 24/7 (Port 8000)
mcp-server Up 24/7 (Port 8500)
threat-generator Up 24/7 (Port 8000)
JeanNeves-SOC:~$ tail -n 2 logs/gemini-analyst.log
[INFO] Triage successful. MITRE ATT&CK: T1105 Ingress Tool Transfer.
[ACTION] Firewall IP blocking triggered. Alert RESOLVED.

Pipeline Architecture & How It Works

Real-Time Threat Triage Pipeline
1. Ingestion Feed 2. SIEM Console 3. Webhook Trigger 4. n8n Task Hub 5. Gemini AI Analyst 6. Containment / Blocking 7. Resolve Incident
Interactively Trigger the Live AI Agent:
  1. Click Open Live Portal above to access your custom SIEM dashboard (soar.jeannevesit.com).
  2. Under the Indicator Triage tab, select an indicator type (URL, IP Address, or Command), paste a test threat value, and click Submit.
  3. Alternatively, switch to the Ad-hoc Audit tab, select Phishing Email, paste a suspicious email draft, and click Run AI Audit.
  4. Watch the Incident Alerts Queue list on the left—the alert will load, invoke the n8n webhook, run the Gemini agent, execute the VirusTotal check, trigger the firewall block, and change to RESOLVED automatically in 10-15 seconds!
Live PAM Project GCP Cloud Active

NevesSec PAM: Privileged Access Simulator

Developed and deployed an interactive, zero-standing-privileges (ZSP) access broker and secure credential vault mimicking production PAM operations (CyberArk / Senha Segura).

Implements **AES-256 Fernet encryption** to secure admin passwords at rest, a time-boxed check-out/check-in engine, and a JIT access elevation request workflow with admin approval gating. A background daemon automatically revokes sessions, triggers password auto-rotations on expiry, and maintains a cryptographically separated audit trail.

Python FastAPI SQLite Cryptography (Fernet) Docker JIT Access Security Auditing
NevesSec PAM Engine
pam-daemon:~$ tail -f data/vault.audit
[19:02:14] [JIT_REQUEST] User jean.neves requested JIT access to Windows DC Admin (30m).
[19:02:45] [APPROVAL] Admin approved JIT Request #402. Session active.
[19:02:45] [DECRYPT] Temp password revealed for AD_ADMIN.
[19:32:45] [EXPIRED] JIT session expired. Revoking token.
[19:32:45] [ROTATION] Password auto-rotated. AES vault updated. Secure.
Autonomous Agent GCP Cloud Active

NevesSec JobHunter: AI Application Review Console

Developed an autonomous job hunting agent tailored for Endpoint Security & Systems Engineering roles. Automatically scans top security ATS portals (Greenhouse, Lever) for US-based remote postings matching candidate expertise.

Pre-drafts tailored technical responses and custom question fields, presenting them in an interactive review dashboard. Enables one-click candidate review, edit, and simulated browser application submission via Playwright automation.

Python FastAPI SQLite Playwright Docker Cloudflare Tunnels
JobHunter Agent Console
job-hunter:~$ tail -f data/automation.log
[13:52:10] [DISCOVERY] Found: Staff Security Engineer at SmarterDx (95% Match).
[13:52:11] [LLM_DRAFT] Generated 2 technical answer drafts.
[13:52:11] [QUEUE] Added to human review queue.
[13:55:04] [USER_APPROVE] Candidate approved application.
[13:55:06] [PLAYWRIGHT] Filled 4 form inputs. Application submitted.

Professional Experience

03/2025 – Present

IT Analyst / Team Lead

BTG Pactual • New York, NY

  • Lead endpoint lifecycle management including Autopilot provisioning, Intune-based device provisioning and policy management, PDQ Deploy software distribution, and device compliance reporting for audit readiness.
  • Serve as primary escalation point for identity, endpoint, and access incidents across global teams, administering Microsoft 365, Exchange Online, Teams, SharePoint, Intune, and Entra ID.
  • Administer Active Directory and Entra ID, managing identity governance, group policies, and access controls across hybrid environments.
  • Administer Palo Alto firewalls, GlobalProtect VPN, and Netskope CASB (including mobile) to enforce network and cloud access security controls.
  • Manage Conditional Access configurations and enforce DLP policies, including endpoint DLP scoping by user and device.
  • Support privileged access governance, administering Senha Segura for credential/session management and Azure Just-in-Time access; use SailPoint to streamline user access requests.
  • Manage identity and access requests via Jira Service Desk; document processes and standards in Confluence.
08/2024 – 02/2025

Infrastructure Analyst

SPX Capital • New York, NY

  • Managed Intune and Jamf MDM environments for a mixed Windows/macOS fleet; enforced least-privilege access and lifecycle-based provisioning policies.
  • Administered Google Workspace and Microsoft 365 tenants for enterprise users, managing licensing, access controls, and user lifecycle operations.
  • Maintained detailed asset inventory and device compliance documentation to support audit readiness and security reviews.
  • Identified and resolved recurring issues at the root-cause level, reducing ticket volume and improving end-user experience.
05/2019 – 08/2024

Technology Analyst

Carnegie Hall • New York, NY

  • Deployed and maintained macOS endpoints integrated with Active Directory using JAMF; administered Microsoft Intune for Windows endpoint compliance and Autopilot provisioning.
  • Administered CyberArk for privileged access management, securing and governing privileged credentials across the environment.
  • Managed Active Directory and hybrid identity, overseeing user lifecycle, group policies, OU structure, and directory synchronization between on-premises AD and Azure AD.
  • Administered Microsoft 365 in a hybrid Exchange environment, managing Exchange Online/on-premises mailboxes, SharePoint sites, and Teams governance for 300+ users.
  • Administered Zscaler as the organization's cloud security gateway, enforcing web filtering, SSL inspection, and zero-trust network access policies.
  • Managed Barracuda Web Application Firewall, maintaining security policies and monitoring traffic for threats.
  • Managed access and support requests via Zendesk for ticketing and Confluence for documentation.
06/2017 – 08/2018

Monitoring Analyst

Neogrid • Porto Alegre, Brazil

  • Monitored end-to-end data pipeline integrity between retail partners and internal applications; queried Oracle Database to troubleshoot discrepancies and support incident investigations.
  • Managed incident tracking via Jira and leveraged Grafana dashboards to monitor system performance and proactively identify anomalies.
04/2014 – 11/2016

IT Support Analyst

Axur • Porto Alegre, Brazil

  • Served as the sole IT resource for the organization, owning user support, hardware lifecycle, vendor management, and documentation as the first and only IT stakeholder.

Certifications

Featured Security & Identity

Microsoft SC-300

Identity and Access Administrator Associate

Microsoft • Issued June 2024

CompTIA CySA+

Cybersecurity Analyst (CS0-004 Exam)

Verification Code: f51bdd56a93a4bf2a0c0cbc14ceceaeb • Issued July 2026

Okta Certified Professional

Okta Identity Governance & Directory Integration

Okta • Issued June 2024

CompTIA Security+

Core Security Operations & Threat Management

Verification Code: 2d1522ca3e9248cebfeba34447d34898 • Issued March 2026

Systems, Network & Foundations

Microsoft MD-102

Endpoint Administrator Associate

Microsoft • Issued June 2024

Cisco CCNA

Enterprise Routing & Switching Solutions

Credential ID: 7c6391b3-c02d-455d-acc4-e1e096c262e8 • Valid to Oct 2028

LPI Linux Essentials

Linux System Administration

Issued June 2020