Information Security · Oracle GRC

Vinicius K. Q. Tanigawa

Information Security Analyst | Oracle GRC, IAM and SoD

Oracle Cloud Fusion ERP security with the rigor of court-appointed expert work.

I design and implement access models in Oracle Cloud Fusion ERP that survive audit: RBAC, Segregation of Duties (SoD) and Sensitive Access under Oracle Risk Management Cloud. I translate access risk into defensible control — before the audit committee and before the court.

São Paulo, Brazil

Portrait of Vinicius K. Q. Tanigawa
  • 160+

    Business processes

    Covered by the RBAC role and persona design in Oracle Cloud Fusion ERP.

  • 250+

    SoD and Sensitive Access risks

    Identified and assessed with functional leads; mitigating controls proposed.

  • 4

    Active certifications

    Oracle Risk Management Cloud 2025, ISC² CC, OCI AI Foundations and healthcare cybersecurity.

  • TJSP

    Court-appointed IT expert

    Registered with and appointed by the São Paulo State Court of Justice.

About

An engineer who does GRC

ERP security is not solved with a checklist. It is solved by understanding the business process, the permission model and who can do what — and by proving it with evidence.

Today I work as an Information Security Analyst at Deloitte, dedicated to Oracle Cloud Fusion ERP security on a large-scale implementation. My work is to design the role and persona model under RBAC and least privilege, to map Segregation of Duties (SoD) and Sensitive Access risks together with the functional leads, and to sustain governance in Oracle Risk Management Cloud. For Information Security teams, Internal Audit and SOX programs, what I deliver is an access model that holds up under testing: 160+ business processes covered and 250+ SoD and Sensitive Access risks assessed and treated.

In December 2025 the São Paulo State Court of Justice appointed me as an Information Technology expert, with a technical expert report under preparation to inform the court's ruling. That credential says something specific about how I work: court-appointed expert work demands a reproducible method, traceable evidence and a conclusion that stands up to adversarial scrutiny. It is exactly the standard I apply to an access control design — because a control that cannot be demonstrated with evidence is not a control; it is only an intention.

My foundation is Electrical Engineering at the University of São Paulo — Escola Politécnica (Poli-USP), with a focus on Telecommunications, combined with a period in software engineering at BTG Pactual. That changes how I approach the problem: I read an SoD matrix as a systems problem, not as a spreadsheet, and I use Python to automate repetitive manual analysis — the same approach that, in volunteer work at Kenren, cut accreditation time by 80%. That is what separates an engineer who does GRC from a traditional auditor: I do not simply flag the risk — I build and test the mechanism that contains it.

  • Oracle Fusion ERP in depth

    RBAC roles, SoD and Sensitive Access designed, configured and tested through go-live — not merely reviewed on paper.

  • Evidence that holds up in audit

    Court-appointed expert rigor applied to access controls: reproducible method, evidence trail and defensible conclusions across SOX, ISO 27001 and LGPD.

  • Automation as a differentiator

    An engineering foundation and Python to turn manual access analysis into a repeatable, fast and auditable process.

Career

Experience

  1. Information Security Analyst

    Dec 2024 – Present

    Deloitte São Paulo, Brazil Current

    Oracle Cloud Fusion ERP security on a large-scale implementation: RBAC role design, SoD and Sensitive Access risks, and governance in Oracle Risk Management Cloud.

    • Led the design of RBAC roles and personas in Oracle Cloud Fusion ERP within a large-scale implementation, applying least privilege, Segregation of Duties (SoD) and Sensitive Access controls — resulting in 160+ business processes covered by a single, consistent access model.
    • Drove risk identification and assessment together with the functional leads of each process, mapping 250+ SoD and Sensitive Access risks and proposing the mitigating controls that made the role model auditable end to end.
    • Configured and tested the roles with the business teams ahead of go-live, validating every security configuration in a controlled environment and preventing access exceptions from reaching production.
    • Established governance of OTBI report permissions with key users, defining who can query which sensitive ERP data and closing an exposure path that commonly escapes role-based control.
    • Oracle Fusion ERP
    • RBAC
    • SoD
    • Oracle RMC
    • OTBI
  2. Court-Appointed Expert — Information Technology

    Dec 2025 – Present

    São Paulo State Court of Justice (TJSP) São Paulo, Brazil Current

    Information Technology expert registered with the TJSP and appointed by the court to produce technical evidence in a judicial proceeding.

    • Appointed by the court as the expert in a judicial proceeding involving Information Technology matters, leading the preparation of the technical expert report that will inform the ruling, under a reproducible method, traceable evidence and language accessible to the parties.
    • Court-appointed expert work
    • IT technical evidence
    • Expert report
  3. Software Engineer

    Jan 2022 – Apr 2022

    BTG Pactual São Paulo, Brazil

    Development of dashboards for an internal banking system and support for the migration of on-premises functionality to the cloud.

    • Built dashboards in ReactJS and C# for an internal banking system, giving business users direct visibility over information that previously depended on manual extraction.
    • Supported the migration of on-premises functionality to AWS, adapting system components to the cloud environment throughout the transition.
    • ReactJS
    • C#
    • AWS
    • Financial services

Credentials

Certifications and credentials

  • Cybersecurity for Healthcare Employees

    The HIPAA Journal

    June 2026

  • Oracle Risk Management Cloud 2025 — Certified Implementation Professional

    Oracle

    May 2026

  • Certified in Cybersecurity (CC)

    ISC²

    May 2024 · Valid through May 2027

  • OCI 2024 Certified AI Foundations Associate

    Oracle

    January 2025 · Valid through January 2027

Education

Education

  • University of São Paulo — Escola Politécnica (Poli-USP)

    Bachelor of Science in Electrical Engineering — focus on Telecommunications

    São Paulo, Brazil · Expected graduation: Dec 2027

    A quantitative foundation in systems, networks and telecommunications. It is the technical foundation behind how I read access architecture, automate in Python and analyze risk in complex environments.

Skills

Core competencies

Security and Governance

  • IAM
  • Role design (RBAC)
  • Segregation of Duties (SoD)
  • Sensitive Access
  • Least Privilege
  • Risk management (GRC)
  • Access governance

Compliance and Standards

  • SOX (internal controls and SoD)
  • ISO 27001
  • LGPD
  • GDPR

Platforms

  • Oracle Risk Management Cloud
  • Oracle Cloud Fusion (ERP)
  • OTBI
  • Oracle Cloud Infrastructure (OCI)
  • AWS

Development and Automation

  • Python (process automation)
  • ReactJS
  • C#

Languages

Languages

  • Portuguese Native
  • English Fluent — C1 Advanced (Cambridge)
  • Spanish Advanced

Projects

Research and projects

  • Undergraduate Research — Joule effect curing of composites

    Poli-USP

    Aug – Dec 2023

    Research on the Joule effect curing of composite parts, published in the Journal of Engineering Research and presented at the 31st SIICUSP, the University of São Paulo International Symposium of Undergraduate Research.

    • Applied research
    • Composite materials
    • Scientific publication
    View publication
  • Keep Flying

    Poli-USP

    Apr 2022 – Present

    Flight data acquisition and telemetry system, with aeronautical simulation developed in Julia and Python.

    • Telemetry
    • Python
    • Julia
    • Simulation
  • Dragão Branco Aerodesign

    Poli-USP · Administrative Director

    May 2020 – Mar 2022

    Administrative leadership of the team: managing logistics, marketing and fundraising to sustain operations and the team's participation in competitions.

    • Management
    • Fundraising
    • Team leadership

Volunteering

Activities and volunteering

  • Organizing Committee

    Kenren

    Jan 2022 – Present

    Team coordination and the creation of a Python automation script that generates accreditation QR codes, cutting volunteer registration time by 80%.

  • Access control and operations volunteer

    World Youth Day — Lisbon

    Jul – Aug 2023

    Worked in access control and field operations at a large-scale international event.

Contact

Let's talk

I respond to opportunities in Oracle Security, GRC and IAM, to technical questions about SoD, Sensitive Access and ERP access controls, and to inquiries from lawyers and the courts about Information Technology expert work. Send me the context of the problem and I will come back with a direct answer.

Send a message