Pós-Graduação
Operações Avançadas em Cibersegurança
A cibersegurança deixou de ser uma opção. Numa era em que os adversários são organizações criminosas sofisticadas, grupos de espionagem patrocinados por estados e atores com acesso a arsenais de exploits de nível militar, a diferença entre uma organização resiliente e uma vítima está na qualidade das pessoas que constroem e operam as suas defesas.
A Pós-Graduação em Cibersegurança Operacional Avançada do ISTEC Lisboa foi criada para formar precisamente essas pessoas.
Este programa não é uma introdução à cibersegurança. É o próximo nível, concebido para profissionais que já operam na área e que querem dominar as ferramentas, técnicas e raciocínio estratégico que definem os melhores especialistas do mundo.
Duração
28 semanas
Início previsto
Outubro 2026
Carga horária
Até 8 horas por semana | 192 horas de contacto
Regime
Pós-laboral | Online
Idioma
Inglês
ECTS
30
Threat-Informed Defense
Uma metodologia única
O programa foi estruturado em torno do princípio da defesa orientada por ameaças reais. Os estudantes não aprendem conceitos abstratos: aprendem a pensar como um atacante para construir defesas que resistam a ataques reais. A progressão curricular segue uma cadeia lógica e sequencial:
- Compreender o adversário: como pensa, como age, quais são os seus objetivos
- Dominar as técnicas ofensivas: não para atacar, mas para saber exatamente o que defender
- Arquitetar sistemas resilientes: segurança by design, não como remendo
- Detetar e responder em tempo real: engenharia de deteção e operações SOC avançadas
- Investigar e preservar evidências: análise forense digital com rigor processual
- Entregar resultados concretos: através de um projeto com impacto real
Infraestrutura de classe mundial
O programa disponibiliza acesso a uma das plataformas de cyber ranges mais avançadas do mercado: ambientes virtuais de simulação de ataques que replicam infraestruturas reais, incluindo redes corporativas e ambientes cloud. É aprender fazendo, em condições que imitam o que os profissionais enfrentam no terreno.
O Learning Management System (LMS) combina conteúdos assíncronos de alta qualidade com sessões síncronas, laboratórios práticos e avaliações baseadas em cenários reais, eliminando a fronteira entre formação e prática profissional.
Docentes com experiência operacional internacional
O corpo docente é composto por profissionais de cibersegurança com carreiras internacionais ativas. São especialistas que trabalham diariamente com as ameaças, ferramentas e plataformas que ensinam. Cada sessão tem o formato de um showcase técnico de alto nível: aprendizagem densa, aplicada e orientada por quem vive o tema.
Esta pós-graduação é o caminho mais direto para se tornar num engenheiro de cibersegurança de referência, com as competências técnicas, a mentalidade estratégica e o reconhecimento académico que o mercado exige.
Plano de Estudos
6 módulos sequenciais | 192 horas de contacto | 30 ECTS | 28 semanas
Fundamentos da inteligência de ameaças aplicada: framework MITRE ATT&CK, análise de TTPs, perfilagem de grupos APT, OSINT avançado e desenvolvimento de threat intelligence acionável. Os alunos aprendem a pensar como um adversário antes de construir qualquer defesa.
Segurança ofensiva com aplicação direta na defesa: metodologias de penetration testing, exploração de vulnerabilidades, técnicas de pós-exploração, pivoting e evasão de deteção. Utilização extensiva de cyber ranges para simulação de ataques em ambientes controlados. Baseado no standard PTES e frameworks OWASP.
Desenho de arquiteturas de segurança resilientes: princípios Zero Trust, microsegmentação, gestão de identidade e acesso privilegiado (PAM/IAM), hardening de sistemas e segurança cloud-native (AWS, Azure, GCP).
Engenharia de deteção baseada em ameaças reais: desenvolvimento de regras SIEM (Sigma, Splunk SPL, KQL), threat hunting proativo, análise comportamental (UEBA) e orquestração de resposta (SOAR).
Forense digital com rigor processual: análise de memória, forense de disco, rede e cloud. Metodologias DFIR para contenção, erradicação e recuperação. Preservação de evidências com admissibilidade legal e elaboração de relatórios técnicos e executivos.
Projeto integrador que simula um cenário de segurança real, integrando competências de todos os módulos anteriores. Pode incluir red team/blue team exercises, investigação forense de um incidente complexo ou implementação de uma arquitetura Zero Trust.
Saídas Profissionais
Os diplomados estarão preparados para desempenhar funções de elevada responsabilidade técnica nas áreas mais críticas da cibersegurança:
- Threat Intelligence Analyst
- Penetration Tester / Red Team Operator
- Security Architect
- Detection Engineer
- SOC Analyst (Nível 2/3)
- Threat Intelligence Analyst
- Penetration Tester / Red Team Operator
- Security Architect
- Detection Engineer
- SOC Analyst (Nível 2/3)
O programa abre igualmente portas para posições de liderança técnica (CISO, Head of Security Engineering, Director of Incident Response) em organizações nacionais e internacionais nos setores financeiro, telecomunicações, defesa, energia, saúde e governo.
Corpo Docente
O corpo docente é composto por profissionais com carreiras internacionais ativas em cibersegurança. São especialistas que trabalham no terreno e trazem para a sala de aula casos reais, ferramentas em uso ativo e a perspetiva de quem enfrenta adversários sofisticados. A maioria dos docentes opera a nível internacional, conferindo ao programa uma dimensão global única no panorama educativo português.

Marcos Campos
Postgraduate Programme in Advanced Cybersecurity Operations | ISTEC Lisboa
Marcos Campos is a cybersecurity program manager with more than 20 years across public and private sector operations. At Premium Cloud he leads several teams and directs security roadmaps for clients in healthcare, government and banking. Earlier roles at Microsoft took him through more than 18 countries across EMEA, and he has designed and delivered a full Blue Team training track for in the Middle East. He holds several cybersecurity and IT certifications and is a certified trainer, a graduate of ISTEC, postgraduate and Master’s level, and is currently pursuing a PhD.

Ricardo Villanueva-Polanco
Cryptography and Post-Quantum Security Researcher
Ricardo Villanueva-Polanco is a cryptographer working on post-quantum cryptography: encryption designed to survive the arrival of quantum computers. He is an Assistant Professor at Universidad del Norte and spent two years as Senior Cryptography Engineer at the Technology Innovation Institute in Abu Dhabi, evaluating how cryptographic implementations hold up in practice. His research on side-channel and fault attacks has appeared at CRYPTO, Latincrypt and Indocrypt. He takes students from the mathematics of a cipher to the ways it actually breaks.

Khalid Al Obaidly
AI Adoption and Performance Strategist
Khalid Al Obaidly is a strategist working where people, business and intelligent systems meet. His focus is AI adoption: moving organisations from interest in these tools to a governed, working deployment, alongside performance systems and business development. He starts by listening and understanding the full organisational picture before proposing anything, with a consistent bias toward practical execution. For students, he connects technical security work to the business decisions and human behaviour that determine whether it succeeds.

Hala Aldosari
Cybersecurity Researcher
Hala Aldosari is a cybersecurity researcher and a scholar of Qatar’s National Cyber Security Agency, holding a Computer Science degree with a concentration in cybersecurity. Her interest sits where digital and physical threats overlap, and in what is arriving next: quantum computing, AI-driven attacks and advanced malware. As one of the programme’s newer voices, she brings a current view of the research frontier and of what it genuinely takes to enter this field today.

João Vaz de Carvalho
Senior Manager, Non-Financial Risks
João Vaz de Carvalho has more than twenty years of management experience leading technology project teams. Since 2019 he has held direct responsibility for the first and second lines of defence (the operational teams who own a risk, and the independent function that challenges them), and for the past two years has led second-line management of technology risk. He shows students how a security finding becomes a governance decision: the evidence, language and framing that a risk committee will actually act on.

Ivo Rosa
Cybersecurity Operations, Incident Response and Threat Intelligence Specialist
Ivo Rosa has more than 15 years in the field and is currently responsible for global security operations at a critical infrastructure organisation running across several countries. His work covers security monitoring, incident response, vulnerability management and threat intelligence, spanning IT, operational technology (the systems that control physical processes), IoT and cloud. He is an Invited Professor and an applied researcher in threat intelligence, digital forensics and the human factors behind security failures, and is active in Portugal’s national cybersecurity community.

Paulo Pinto
Senior Cybersecurity and Identity Consultant
Paulo Pinto is founder of XKONSULTING, a boutique consultancy working between Portugal and the United States. Across 27 years in IT and more than two decades in security, he has designed identity and access management programmes (deciding who can reach what, and being able to prove it) for enterprise, government and military environments, with hands-on depth in CyberArk, Delinea and SailPoint. A CISSP-certified practitioner, he advises on identity modernisation, cloud security and, increasingly, AI security and governance.

Pedro Vargues
Technical Success Manager
Pedro Vargues has been building software security practice since 2005, focused on how systems are hardened at the design and architecture stage rather than patched afterwards. He also helped establish the security operations centre at one of Portugal’s largest security companies, which gives him a view from both sides: the developers who write the code, and the analysts who defend it in production. That combination is useful for anyone trying to understand where vulnerabilities are actually introduced.

Pedro Monteiro
Senior Cybersecurity Engineer
Pedro Monteiro is a cybersecurity and IT audit specialist with over 18 years in regulated financial services, currently Senior Cybersecurity Engineer at IQVIA. He led a SOC 2 Type II certification end to end, covering control design, penetration test coordination and external audit management, and is driving an ISO 27001 implementation toward dual certification. At Haitong Bank he selected and implemented the bank’s security operations centre and presented it to the Executive Committee. He holds CEH Master, ISO/IEC 27001 Lead Auditor, Security+ and CPTE.

Ricardo Moura
Security Hardening and Resilience Specialist
Ricardo Moura works in enterprise security engineering and threat-informed defence: building defences around how real adversaries actually behave rather than around theoretical risk. He implements security baselines (DISA STIG, CIS Benchmarks) and Zero Trust controls across hybrid and cloud environments, and bridges offence and defence through adversary emulation, purple teaming and detection engineering. His work on hardened identity architectures and privileged access across Azure, Intune and Microsoft 365 gives students a concrete picture of reducing an attack surface.

João Inácio
Infrastructure and Cloud Security Engineer | Invited Lecturer
João Inácio is a computer engineer specialising in infrastructure, cloud and cybersecurity, with more than two decades across systems, networks and hybrid environments. As an Infrastructure Engineer at Marex PLC he works in an international team running critical global infrastructure spanning Azure, AWS, Microsoft 365 and on-premises data centres, covering digital identity, certificate lifecycle management (PKI), automation and platform migration. He has taught in higher education since 2020 at ISTEC and IPS, and as a certified Cisco NetAcad instructor has trained hundreds of students and teachers.

Daniele Malerba
IT Service Manager
Daniele Malerba is an IT professional with extensive experience in international organisations, currently at the European Space Agency and previously at the United Nations. He specialises in centralised IT operations, continuous improvement and complex service delivery, and has orchestrated global enterprise cybersecurity strengthening projects. He holds a Master’s in International Relations from the University of Sussex, reflecting a long-standing interest in the social impact of technology on the people using it, along with ITIL v4, Scrum and project management certifications.

António Vasconcelos
Cybersecurity Strategist and Product Leader
António Vasconcelos has over 20 years spanning security strategy, product leadership and enterprise advisory, with senior roles at Microsoft, SentinelOne, Logpoint and Zero Networks. His work covers endpoint security, XDR, SIEM, SOAR and NDR: the detection and response tooling most security teams live inside every day. As a former Field CISO and Senior Director of Product Management he has advised C-level executives across EMEA on cyber resilience and Zero Trust, and he now works in Solutions Engineering at Intezer. He brings a practitioner’s view that connects technical depth to business context.

Carlos Hilarion
Senior Information Systems Leader and Executive Coach | Humanitarian and Crisis Operations
Carlos Hilarion has over 20 years in the United Nations system, specialising in enterprise ICT infrastructure, cloud transformation and resilient service delivery. He has led large-scale technology operations in humanitarian emergencies including Sudan, Haiti and Indonesia, managing network recoveries and business continuity under conditions most practitioners never encounter. A certified ICF coach, he pairs technical governance with people-centred leadership, and is completing a Master’s in Management and Human Resources on how organisational resilience and inclusive leadership strengthen security posture.

Walid Moselhy
Microsoft Cloud Solutions Architect
Walid Moselhy is a Microsoft Cloud Solutions Architect specialising in secure cloud architecture, identity management, automation and hybrid environments, including the infrastructure that sits underneath AI workloads. Across nearly two decades he has helped large enterprise organisations worldwide adopt and secure Microsoft cloud technologies, working closely with Microsoft product teams. A Certified Trainer and Azure Solutions Architect, he has trained hundreds of IT professionals and administrators in designing and implementing secure cloud solutions.
Emolumentos - Com Protocolo
- 100,00 € Candidatura de Acesso
- 100,00 € Matrícula
- 10,00 € Seguro Escolar
- 3.500,00 € Pagamento Anual
- 1.750,00 € Pagamento Semestral
- 350,00 € Valor por Unidade Curricular
Emolumentos - Diplomado ISTEC Lisboa
- 100,00 € Candidatura de Acesso
- 100,00 € Matrícula
- 10,00 € Seguro Escolar
- 3.110,00 € Pagamento Anual
- 1.555,00 € Pagamento Semestral
- 350,00 € Valor por Unidade Curricular
Emolumentos - Restantes Estudantes
- 100,00 € Candidatura de Acesso
- 100,00 € Matrícula
- 10,00 € Seguro Escolar
- 4.000,00 € € Pagamento Anual
- 2.000,00 € Pagamento Semestral
- 350,00 € Valor por Unidade Curricular

