Giulia R.
Senior Cyber Security Engineer – AppSec Pentester
Experience
May 2025 - Present
8 monthsSenior Cyber Security Engineer – AppSec Pentester
AB InBev
- Penetration testing in AB InBev Ambev’s product environments.
- Offensive security operations and code reviews of critical global applications.
- Collaborating with development teams on security issues.
- Innovating the tech stack.
- Linux, OAuth2, WebSockets, Azure, Active Directory, Nginx, XAMPP, firewalls, APIs, web applications.
Feb 2024 - May 2025
1 year 4 monthsSão Paulo, Brazil
Cyber Security Analyst – Red Team
Segura São Paulo
- White, gray, and black box pentesting of the Senhasegura application and its runtime environments.
- Large-scale testing in government and critical services environments.
- Incident response.
- Research on security and innovation in software architecture and cloud networks.
- Troubleshooting critical issues.
- Linux, OAuth2, Wazuh, WebSockets, AWS, PHP, Nginx, Docker, clustering, XAMPP, AppArmor, APIs, web applications, low-level systems.
Nov 2023 - Jan 2024
3 monthsSão Paulo, Brazil
Pentester – Head of Offensive Security
Spivit Global Technologies Americana
- Established the offensive security and SaaS departments.
- Web application and network pentesting.
- Set security standards and policies for the company and clients.
- Designed and delivered security awareness programs.
- Configured Sophos Firewall and endpoint security environments.
- Linux, Microsoft Azure, Active Directory, NAS, firewalls, XDR, XAMPP.
Apr 2021 - Present
4 years 9 monthsBug Bounty Hunter
Bugcrowd and HackerOne
- Pentesting companies enrolled in bug bounty programs.
Summary
Led the creation of an offensive security department at a mid-sized company in Brazil, and have helped secure critical environments. I’m passionate about free software and a privacy advocate, seeing privacy as a human right.
Skills
- Linux Servers And Environments.
- Burpsuite, Postman, Curl, Strace, Nmap, Metasploit, Ffuf, Git, Sqlmap.
- Http/https, Dns, Smtp, Ssh, Tcp/ip, Udp, Ftp, Smb.
- Cwe Top 25 And Owasp Top 10 Vulnerabilities.
- Scripting In Python, Bash, And C.
- Latex.
Languages
Portuguese
NativeEnglish
AdvancedSpanish
AdvancedEducation
Feb 2025 - Dec 2026
FIAP
Cyber defense · São Paulo, Brazil
Certifications & licenses
Cybersecurity Bootcamp
Santander
Getting Started With AWS Pentesting
EC-Council
Full Stack Attacks On Modern Web Applications
EC- Council
Kali Linux For Ethical Hackers
FreeCodeCamp
CS50’s Introduction To Artificial Intelligence
HarvardX
Full Ethical Hacking Course
FreeCodeCamp
Intermediate Python Programming Course
FreeCodeCamp
Need a freelancer? Find your match in seconds.
Try FRATCH GPT More actions
Similar Freelancers
Discover other experts with similar qualifications and experience