Jean Neves

IT Analyst Team Lead at BTG Pactual

Cybersecurity & Infrastructure Engineer • M.S. Cybersecurity at NYU Tandon

jeannevesit.com
Scroll to explore
Jean Neves

M.S. Cybersecurity

NYU Tandon School of Engineering

Expected Graduation: 2027

About Me

IT Analyst / Team Lead specializing in identity and access management — Entra ID, Active Directory, CyberArk, and privileged access governance — alongside endpoint management with Intune and Jamf. I'm currently pursuing an M.S. in Cybersecurity at NYU Tandon, where I've been building hands-on cloud security projects, including an automated SOC pipeline on GCP that uses Gemini, VirusTotal, and live honeypot telemetry for AI-driven threat triage.

My goal is to move deeper into identity and access engineering — combining IAM expertise, automation, and security operations to build access models that scale safely.

Core Expertise

Infrastructure & Networks

Enterprise networking, data-center management, Active Directory administration, DNS/DHCP, and physical systems routing.

Endpoint Management

Microsoft Intune, unified endpoint policies, Group Policy Objects (GPOs), patch management, and hardware compliance auditing.

Cloud & DevOps Sec

Google Cloud Platform (GCP), Terraform infrastructure-as-code, Docker containers, and Cloudflare network routing/tunnels.

AI & Security Automation

LLM orchestration (Gemini API), n8n pipeline orchestration, automated triage playbooks, and threat intelligence ingestion.

Featured Security Projects

Live AI Project GCP Cloud Active

NevesSec: Autonomous AI-Powered SOC Analyst

Designed and deployed a 24/7 Security Operations Center pipeline in Google Cloud Platform. The system automatically ingests system logs, malicious URLs, and threat telemetry from live honeypots, forwarding them via webhooks to invoke a Gemini AI L2 Analyst agent in n8n.

The AI agent queries VirusTotal, performs automated threat audits, maps attacks to MITRE ATT&CK, blocks threat IPs in Palo Alto firewalls, and updates the custom SIEM dashboard. Reduces manual alert triage time by 85% and processes up to 100+ telemetry incidents daily.

GCP VM Docker Compose n8n Gemini 2.5 FastAPI Cloudflare Tunnels
NevesSec Control Center
JeanNeves-SOC:~$ docker compose ps
soc-n8n Up 24/7 (Port 5678)
mock-siem Up 24/7 (Port 8000)
mcp-server Up 24/7 (Port 8500)
threat-generator Up 24/7 (Port 8000)
JeanNeves-SOC:~$ tail -n 2 logs/gemini-analyst.log
[INFO] Triage successful. MITRE ATT&CK: T1105 Ingress Tool Transfer.
[ACTION] Firewall IP blocking triggered. Alert RESOLVED.

Pipeline Architecture & How It Works

Real-Time Threat Triage Pipeline
1. Ingestion Feed 2. SIEM Console 3. Webhook Trigger 4. n8n Task Hub 5. Gemini AI Analyst 6. Containment / Blocking 7. Resolve Incident
Interactively Trigger the Live AI Agent:
  1. Click Open Live Portal above to access your custom SIEM dashboard (soar.jeannevesit.com).
  2. Under the Indicator Triage tab, select an indicator type (URL, IP Address, or Command), paste a test threat value, and click Submit.
  3. Alternatively, switch to the Ad-hoc Audit tab, select Phishing Email, paste a suspicious email draft, and click Run AI Audit.
  4. Watch the Incident Alerts Queue list on the left—the alert will load, invoke the n8n webhook, run the Gemini agent, execute the VirusTotal check, trigger the firewall block, and change to RESOLVED automatically in 10-15 seconds!
IAM & Security Automation

Enterprise IAM Lifecycle Automation Toolkit

Developed and implemented a production-grade identity synchronization and user lifecycle automation engine using PowerShell, Active Directory Services, and Microsoft Graph API.

Automates employee provisioning and deprovisioning, scans Entra ID directory states for security compliance, logs access anomalies, and audits group memberships. Replaced manual access review spreadsheets with automated scripts, cutting user onboarding time by 90% and securing Active Directory hygiene.

PowerShell Active Directory Entra ID Microsoft Graph API Access Governance Auditing
PowerShell Administrator
PS C:\> .\Sync-Identities.ps1 -DryRun $false
[INFO] Fetching identity delta from HR database...
[INFO] 14 new hires, 3 terminations detected.
[ACTION] Provisioning Entra ID accounts & M365 licenses...
[ACTION] Disabling terminated accounts & revoking sessions...
PS C:\> Get-AccessAudit -Group "Domain Admins"
[SUCCESS] Group Membership Audit complete.
[REPORT] 0 unauthorized accounts found. Audit log pushed.

Professional Experience

03/2025 – Present

IT Analyst / Team Lead

BTG Pactual • New York, NY

Serve as the primary escalation point for identity, endpoint, and access incidents globally. Administer Microsoft 365, Exchange Online, Teams, SharePoint, Intune, and Entra ID. Lead Autopilot provisioning, policy management, and compliance auditing. Oversee Palo Alto firewalls, GlobalProtect VPN, and Netskope CASB security controls. Manage privileged access via Senha Segura and Azure JIT.

08/2024 – 02/2025

Infrastructure Analyst

SPX Capital • New York, NY

Administered Google Workspace and Microsoft 365 tenants. Managed Intune and Jamf MDM environments for a hybrid Windows/macOS fleet. Maintained inventory compliance logs and enforced least-privilege lifecycle provisioning.

05/2019 – 08/2024

Technology Analyst

Carnegie Hall • New York, NY

Managed macOS/Windows endpoints using Jamf Pro and Intune. Administered hybrid Active Directory synchronizations, OUs, and Group Policies. Secured access control structures using CyberArk PAM, Zscaler secure web gateways, and Barracuda WAF policies.

06/2017 – 08/2018

Monitoring Analyst

Neogrid • Porto Alegre, Brazil

Monitored end-to-end data pipeline integrity, ran Oracle SQL troubleshooting queries, tracked incidents in Jira, and built telemetry dashboards using Grafana.

Certifications & Credentials

Featured Security & Identity

Microsoft SC-300

Identity and Access Administrator Associate

Microsoft • Issued June 2024

Okta Certified Professional

Okta Identity Governance & Directory Integration

Okta • Issued June 2024

CompTIA CySA+

Cybersecurity Analyst (CS0-004 Exam)

Verification Code: f51bdd56a93a4bf2a0c0cbc14ceceaeb • Issued July 2026

CompTIA CSAP

Security Analytics Professional (Security+ / CySA+ Stackable)

Candidate ID: COMP001022998913 • Issued July 2026

CompTIA Security+

Core Security Operations & Threat Management

Verification Code: 2d1522ca3e9248cebfeba34447d34898 • Issued March 2026

Cisco CCNA

Enterprise Routing & Switching Solutions

Credential ID: 7c6391b3-c02d-455d-acc4-e1e096c262e8 • Valid to Oct 2028

Systems, Automation & Foundations

Microsoft MD-102

Endpoint Administrator Associate

Microsoft • Issued June 2024

LPI Linux Essentials

Linux System Administration

Issued June 2020

Google IT Automation

Python Scripting & Git Version Control

Issued January 2022

MTA: Database Fundamentals

SQL Server & Relational Databases

Microsoft • Issued 2020

Google Data Analytics

Data Analytics Professional Certificate

Issued March 2022

Google IT Support

Network & Operating Systems Admin

Issued August 2020

Celonis Foundations

Process Mining & System Telemetry

Issued January 2022