Ethical hacker and bug bounty hunter with over 6 years of experience in Information Security across multinational consulting and financial firms, with hands-on experience in penetration testing and bug bounty programs through platforms like Bugcrowd. Specializes in web application security and exploitation techniques to uncover and remediate complex vulnerabilities.Known for a proactive approach to security challenges, I engage cross-functional teams to present findings and develop robust solutions, ensuring alignment with industry standards such as OWASP, NIST, MITRE ATT&CK, GDPR, PCI-DSS, and FISMA. I am also the cofounder of Zero2Flag, where I share content on the fundamentals of offensive security. Active in industry events and security awareness initiatives, I bring a client-centered approach to vulnerability management and cybersecurity strategy.
-
Security ResearcherZero2FlagState Of São Paulo, Brazil -
Security ResearcherSelf-Employed Sep 2024 - Present
-
Information Security SpecialistEletrobras Apr 2024 - Oct 2024São Paulo, Brasil* Conduct penetration testing on web applications.* Serve as the Principal Engineer for the Red Team.* Manage vulnerability assessments and remediation processes.* Create detailed technical reports on vulnerabilities, including corrective actions and recommendations. -
Associate Director (Cybersecurity)Btg Pactual Dec 2021 - Jan 2024São Paulo, Brasil* As a Red Team Specialist, I managed the pentesting schedule according to project criticality and priority, ensuring that all critical points were verified for optimal quality and understanding, both technically and executively.* Presentation and alignment of results for developers and managers.* I coordinated the assessment and hiring of third-party companies for penetration testing, managed contracts, allocated work hours, and tracked results.* I promoted BTG at Security events such as Roadsec and delivered lectures on vulnerabilities and specific attacks on behalf of BTG Pactual.* Over the past two years, I have been recognized and distinguished in the bank's performance program. -
Cyber Security AnalystBtg Pactual Jan 2020 - Dec 2021* I conducted penetration testing on web applications, executables, and mobile applications (iOS and Android).* I participated in Attack-Defense simulations.* Responsible for evaluating services and tools for the department and presenting to the Purchasing Committee.* I created the CTF University project (ctf.btgpactual.com), an interactive and competitive Capture The Flag aimed at attracting university students to the field of Information Security and participating in internships within BTG.* I was responsible for managing Bug Bounty programs, conducting research for rewards, reviewing assets, and promoting campaigns to engage hunter participation.* I conducted an inventory of all exposed applications at BTG Pactual, classifying and prioritizing them for penetration testing.* I developed phishing campaigns to aid in the security awareness of the bank. -
Security Consulting AnalystAccenture Brasil May 2019 - Dec 2019* Deployed on a project for a major Brazilian bank, I conducted penetration testing on over 800 APIs using the agile Kanban methodology.* Responsible for drafting both technical and managerial reports. * Collaborated with Maglan Technical Unit (Israel). -
Wintel ApprenticeDxc Technology Sep 2018 - Feb 2019* I rotated across two teams in the infrastructure area, UNIX and Wintel..* Server virtualization using VMware vSphere and Microsoft Hyper-V.* I became familiar with the ITIL processes used in the company.* Provisioning and decommissioning of UNIX/Linux and Windows servers.* I participated in workshops and training sessions in technology areas suchas programming logic, networking fundamentals, ITIL, gamification, databases, operating systems, etc. -
Unix ApprenticeDxc Technology Mar 2018 - Sep 2018São Paulo* I rotated across two teams in the infrastructure area, UNIX and Wintel..* Server virtualization using VMware vSphere and Microsoft Hyper-V.* I became familiar with the ITIL processes used in the company.* Provisioning and decommissioning of UNIX/Linux and Windows servers.* I participated in workshops and training sessions in technology areas suchas programming logic, networking fundamentals, ITIL, gamification, databases, operating systems, etc. -
Forensic AccountantConfidential Mar 2016 - Dec 2016I worked on performing labor calculations for legal proceedings in governmental agencies. -
Student InternshipAgu - Advocacia-Geral Da União Jan 2015 - Nov 2015São Paulo, BrasilIn the internship, I organized the incoming cases and distributed them to the lawyers.
Ana Elizaur Skills
Frequently Asked Questions about Ana Elizaur
What company does Ana Elizaur work for?
Ana Elizaur works for Zero2flag
What is Ana Elizaur's role at the current company?
Ana Elizaur's current role is Security Researcher.
What schools did Ana Elizaur attend?
Ana Elizaur attended Fatec São Caetano - Antônio Russo, Etec Prof. Camargo Aranha, Fiap.
What skills is Ana Elizaur known for?
Ana Elizaur has skills like Linux, Python, Microsoft Windows, Video Games, Virtualization, Sistemas Operacionais, Microsoft Excel, Chatbots, Nightbot, Gameplay, Entertainment.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial