Senior Offensive Security Engineer with 4+ years executing penetration tests, red team operations, and AppSec programs for Fortune-500 and financial-sector clients. Based in Brazil — open to relocation across EU, Canada, UAE, and APAC.
// work history
4+ years breaking into systems — legally. From DevSecOps pipelines to full-chain Azure red team simulations for national banks.
PwC Brasil
act digital
Claro Brasil
Kyndryl
Sinqia
// capabilities
Full attack-surface coverage — from web and mobile to enterprise Active Directory and multi-cloud environments.
Web & API Pentesting
Red Team Operations
Active Directory Attacks
Cloud Pentesting
Mobile Security
AppSec & DevSecOps
// notable work
Original research, CVEs, bug bounty findings, and freelance engagements. This section grows with every new discovery. Full writeups in the Writeups section.
Research · Network / L2
802.1X Bypass & MACsec Downgrade via MKPDU Suppression
Practical exploitation of Cisco switch port security — bypassing 802.1X authentication and downgrading MACsec through MKPDU frame suppression.
CVE Research
Vulnerability disclosures will appear here
Bug Bounty
HackerOne / Bugcrowd findings will appear here
Freelance
Independent security engagements will appear here
// credentials
Hands-on, lab-based certifications that prove real attack skills — not multiple-choice theory.
eWPTX
Web Application Penetration Tester eXtreme
eLearnSecurity / INE
Certified
CRTA
Certified Red Team Analyst
Altered Security
Certified
eJPT
Junior Penetration Tester
eLearnSecurity / INE
Certified
SC-900
Microsoft Security, Compliance & Identity
Microsoft
Certified
OSCP
Offensive Security Certified Professional
Offensive Security
In progress
// academia
FIAP, São Paulo
UNINOVE, São Paulo
// let's talk
Open to full-time roles internationally, freelance engagements, and vulnerability research.
Drop a message — I reply fast.