Gabriel Lessa

Gabriel Santa Rosa
Lessa

Cybersecurity Risk Management · Vancouver, BC

Building practical skills in SOC operations, threat intelligence, cloud security, and homelab infrastructure.

Dual-background cybersecurity student with hands-on project experience.

I am a Cybersecurity Risk Management student at the Canadian College of Technology and Business (CCTB) in Vancouver, BC, with a prior Associate Degree in Cyber Defense from Estácio de Sá University in Brazil.

My current focus areas include SIEM operations, incident response (NIST SP 800-61), Cyber Threat Intelligence (MITRE ATT&CK mapping), cloud security on AWS, network reconnaissance with Nmap/Wireshark/Scapy, and defense-in-depth security architecture.

Beyond coursework, I maintain a personal Proxmox VE HomeLab running 12+ production services in isolated LXC containers, practicing real-world Zero Trust networking, SSO integration, SIEM monitoring, and infrastructure automation.

0+ HomeLab Services
0h TryHackMe Labs
0+ Academic Projects
0 Degrees

Core competencies and tools

Cybersecurity & SOC

Threat intelligence (MITRE ATT&CK), incident response (NIST SP 800-61 / CSF 2.0), SIEM, IDS/IPS, EDR, log analysis, defense-in-depth architecture.

Networking

TCP/IP, DNS, DHCP, Nmap, Scapy, Wireshark, tcpdump, pfSense, Cisco Packet Tracer, WireGuard VPN, network segmentation.

Cloud & Infrastructure

AWS EC2/VPC/ALB, Proxmox VE, Docker, LXC containers, VMware, VirtualBox, Linux server admin (Ubuntu, Kali, Debian).

Development & Automation

Python, Django, REST APIs, MongoDB, Bash scripting, Git/GitHub multi-branch workflows, CI/CD, infrastructure-as-code.

Analytical & SOC Skills

Root-cause analysis, alert triage, escalation workflows, CTI reporting, risk assessment, RACI matrices, stakeholder documentation.

IT Support & Operations

Help desk, troubleshooting, AV equipment, reverse proxy (Nginx), DNS filtering (AdGuard), monitoring (Uptime Kuma), SSO (Authentik).

Personal Cybersecurity Infrastructure

A self-built Proxmox VE environment running on dedicated hardware, designed as a Zero Trust cybersecurity lab. All services run in isolated unprivileged LXC containers with encrypted VPN mesh access, centralized SSO authentication, and automated monitoring.

SYS_TOPOLOGY

Architecture Overview

Hypervisor Proxmox VE 9.x
Hardware Custom Low-Power Microserver · 32 GB DDR4 · SSD Storage
Network Isolated Bridges (vmbr0/1/2) · WireGuard Mesh VPN
Access Zero Port Forwarding · SSH Ed25519 · SSO + WebAuthn Passkeys
DNS & SSL Wildcard SSL (Let's Encrypt + DNS Challenge) · AdGuard Home

Core Production Services 24/7 Zero-Trust Mesh

OPNsense Firewall

Virtualized firewall/router with VLAN segmentation, reply-to rules for reverse proxy, and air-gapped network isolation for malware analysis.

Authentik SSO

Central Identity Provider with OIDC/OAuth2, WebAuthn/Passkeys biometric MFA, and step-up authentication for all services.

Nginx Proxy Manager

Reverse proxy with wildcard SSL certificates via DuckDNS DNS-Challenge, WebSocket support, and HTTP/2 secure routing.

Vaultwarden

Self-hosted Bitwarden-compatible password manager with SSO integration, disabled public signups, and encrypted vault.

Matrix Synapse + Element

Federated encrypted messaging with OIDC SSO integration, LiveKit WebRTC voice/video, and role-based access control.

Uptime Kuma

Infrastructure monitoring with 18+ service monitors, status page, alerting, and real-time health telemetry.

AdGuard Home

Network-wide DNS filtering and ad blocking for all HomeLab containers, with query logging and analytics.

SimpleLogin

Self-hosted email alias service (Proton-compatible) for privacy-focused email management and anti-spam protection.

AI Agent Workspace

Dedicated container for autonomous AI coding agents with Docker, Ollama local LLM inference, and multi-agent orchestration.

OmniRoute AI Gateway

Intelligent AI API router with rate-limit management (RPM/RPD), multi-provider load balancing across free-tier LLM APIs.

Dozzle & Homepage

Real-time Docker log viewer and unified dashboard with Proxmox API telemetry for infrastructure overview.

Elastic Auto-Scaler & Vault

Native Python cgroups v2 governor (+1GB RAM under load, -256MB decay) and Zero-Knowledge memory-only secret vault.

ZERO_TRUST

Security Architecture Highlights

Zero Trust Access

No ports exposed to the public internet. All access routed through encrypted NetBird WireGuard mesh VPN overlay.

SSH Hardened

Password authentication disabled. Ed25519 key-only access with root login restricted to cryptographic keys.

Multi-Bridge Network Isolation

Triple bridge segmentation (vmbr0 production, vmbr1 air-gapped lab, vmbr2 Tor gateway) with firewall isolation.

Centralized SSO + Passkeys

WebAuthn biometric authentication via Authentik for all critical services with step-up verification.

Elastic Resource Governor

Native Python cgroups v2 auto-scaler dynamically managing memory pressure (+1GB/-256MB) and preserving host stability.

Zero-Knowledge Secret Vault

Shannon entropy evaluation and indirect memory-only injection ensuring credentials never touch disk unencrypted.

CYBERLAB_ON_DEMAND

Isolated CyberLab Capabilities

Specialized testing environments activated on-demand across isolated internal bridges (vmbr1 / vmbr2) to preserve hypervisor resources and prevent lateral movement into production.

Air-Gapped Malware Analysis Sandbox — Completely air-gapped subnet (vmbr1: 172.16.0.0/24) with INetSim simulating web/DNS/mail services for safe malware detonation and DFIR artifact extraction.
Active Wazuh SIEM / XDR — Endpoint telemetry ingestion, custom detection rules, and automated event correlation for continuous security monitoring.
Threat Intel OpenCTI Platform (CT 120) — Structured Cyber Threat Intelligence management, STIX 2.1 data feed ingestion, and MITRE ATT&CK enterprise adversary mapping.
Assessment DefectDojo & SpiderFoot (CT 121) — Vulnerability tracking, automated reporting pipeline, and OSINT attack surface reconnaissance.
Dark Web Robin AI & Whonix Gateway (CT 119) — Dedicated Tor onion-routing gateway on isolated bridge (vmbr2) for OSINT and dark web investigations with zero host IP leakage.
Red Team Active Directory Attack Lab — Windows Server domain controller and workstation pair for practicing Kerberoasting, AS-REP roasting, and pass-the-hash privilege escalations.

Academic and hands-on cybersecurity projects

TryHackMe Cybersecurity Labs

Networking · Linux · Security Fundamentals · 32h+ Completed

Completed the CAPTSTONE_JAN 2026 Learning Path (32h 30min) with hands-on labs in networking, Linux, and cybersecurity concepts.

Hack The Box Academy Learning

Networking Fundamentals · Cybersecurity Practice

Guided modules reinforcing networking fundamentals, structured learning, and practical cybersecurity problem solving.

Verified achievements

TryHackMe – CAPTSTONE_JAN 2026

Learning Path · 32h 30min

Completed July 27, 2026

✓ Verified

Hack The Box Academy

Networking · Cybersecurity Modules

Ongoing

In Progress

CCTB Cybersecurity Coursework

SOC · Risk Management · Cloud Security · CTI

Diploma Program · 2025 – Present

In Progress

Professional and volunteer experience

Student Check-in Assistant

Aug 2025 – Present

StayWise Accommodations · Vancouver, BC

  • Support student check-ins/check-outs with clear guidance during arrivals and departures.
  • Coordinate move-ins, key handoffs, late check-ins, and accommodation instructions.
  • Apply attention to detail, communication, and customer service skills daily.

Volunteer Technical Support / Camera Operations

Jun 2025 – Aug 2025

Faith Fellowship Baptist Church · Vancouver, BC

  • Supported live camera operations for weekly services and special events.
  • Assisted with technical troubleshooting for audio-visual equipment.
  • Ensured smooth video production and reliable technical setup.

Operations Assistant

Jan 2018 – Dec 2020

Granulado Brigaderia · Niterói, RJ, Brazil

  • Supported daily operations including customer service, cash handling, and POS systems.
  • Managed inventory organization and general operational tasks.
  • Developed skills in responsibility, communication, and time management.

Academic background

Diploma in Cybersecurity Risk Management

May 2025 – Expected May 2028

Canadian College of Technology and Business (CCTB) · Vancouver, BC

Coursework: SIEM, incident response, network security, threat intelligence, cloud security, Linux/Windows security, risk management, and business continuity, followed by cybersecurity co-op placement.

Associate Degree in Cyber Defense

2020 – 2022

Estácio de Sá University · Brazil

Foundational studies in cybersecurity, information security, networking, systems, and cyber defence concepts.

Open to co-op, internship, and entry-level cybersecurity opportunities.

Based in Vancouver, BC. Available for SOC analyst, IT support, technical support, network support, and cybersecurity roles.