Offensive Security Researcher
Penetration Tester
Red Team Operator
Hacking n' Roll
I'm an Offensive Security Researcher and Senior Cybersecurity Engineer with more than 10 years of hands-on experience in penetration testing, vulnerability research, exploit development, red teaming, and security engineering.
My work spans web applications, APIs, mobile platforms, internal infrastructure, wireless environments, and adversary simulation. Over the years, I have disclosed 15+ CVEs affecting widely used products from vendors including Nagios, PRTG, 3CX, Centreon, ManageEngine, and Trend Micro.
I hold the OSWE, OSWP, and GIAC GMOB certifications and have presented offensive security research at international conferences including Security BSides Las Vegas and OrangeCon Amsterdam. I also contribute to open-source security projects and publish technical research focused on understanding systems deeply enough to break assumptions, uncover attack paths, and turn complex vulnerabilities into reproducible findings.
Deep technical security assessments across web applications, APIs, mobile platforms, external attack surfaces, internal infrastructure, and complex enterprise environments, with an emphasis on manual testing, exploitation, attack-path discovery, and demonstrable impact.
Security research focused on discovering previously unknown vulnerabilities through source-code analysis, reverse engineering, dynamic analysis, protocol inspection, attack-surface mapping, and systematic exploration of unexpected application behavior.
Development of reliable proof-of-concept exploits and technical demonstrations designed to validate exploitability, understand root cause, measure real-world impact, and support responsible vulnerability disclosure.
Threat-driven offensive operations that emulate realistic adversaries by combining application, infrastructure, identity, wireless, social, and physical attack vectors to evaluate detection, response, and organizational resilience.
Executing offensive security assessments across web applications, APIs, mobile platforms, and infrastructure environments. Responsible for manual exploitation, attack-path analysis, vulnerability validation, technical reporting, and translating complex security findings into actionable remediation guidance.
Co-founded an offensive security consultancy focused on penetration testing, red teaming, vulnerability research, and exploit development. Led technical initiatives to improve assessment quality, research methodology, team development, and offensive-security capabilities while conducting independent vulnerability research and contributing to the security community.
Performed offensive security assessments and security engineering activities with a strong emphasis on mobile application security. Evaluated protections including SSL pinning, root and jailbreak detection, Frida and instrumentation detection, anti-tampering mechanisms, runtime protections, and application hardening controls.
Led offensive security research and development initiatives supporting Stone and organizations across the broader group, including Pagar.me, Mundipagg, Equals, Cappta, and Elavon. Conducted vulnerability research, developed offensive techniques and tooling, and contributed to STOlabs security research activities.
Conducted penetration testing and security engineering activities across application and mobile environments, including analysis of runtime protections, SSL pinning, anti-tampering controls, root and jailbreak detection, instrumentation resistance, and application security architecture.
Performed penetration testing and vulnerability research across enterprise applications and infrastructure supporting Stone and other organizations within the group. Participated in STOlabs, contributing to security research, vulnerability disclosure, offensive tooling, and the identification of vulnerabilities affecting widely adopted technologies.
Executed offensive security operations across web applications, mobile platforms, internal infrastructure, wireless networks, physical security, and adversary-simulation scenarios, focusing on realistic attack paths and practical exploitation.
Supported application security and penetration-testing activities with emphasis on mobile security engineering, runtime protections, SSL pinning, anti-tampering mechanisms, instrumentation detection, root and jailbreak detection, and defensive control validation.