Andrei A.

Andrei A. Email and Phone Number

Application Security Specialist @ Natura
State of São Paulo, Brazil
Andrei A.'s Location
São Paulo, São Paulo, Brazil, Brazil
About Andrei A.

Throughout my career, I have worked extensively within application security teams and participated in offensive security initiatives, providing consultancy to clients across diverse industries. My expertise includes integrating security tools and best practices into development pipelines to foster a robust culture of secure software development.In addition, I have led multiple research projects in information security, focusing on identifying and mitigating critical vulnerabilities. I have also developed sophisticated exploitation and post-exploitation tools, underscoring my commitment to proactive and innovative approaches in the field of cybersecurity.

Andrei A.'s Current Company Details
Natura

Natura

View
Application Security Specialist
State of São Paulo, Brazil
Website:
natura.com.br
Employees:
44908
Andrei A. Work Experience Details
  • Natura
    Application Security Specialist
    Natura
    State Of São Paulo, Brazil
  • Natura &Co
    Application Security Specialist
    Natura &Co May 2024 - Present
    São Paulo, Brasil
    Application Security Assessment Security in CI/CD pipelinesSecure Code ReviewAPI Security Assessment Experience with Application Security Enterprise SolutionsWorking in Cloud environments (GCP, AWS and Azure)Vulnerability management for applications (Web, Mobile, API)SAST, DAST, SCA, IAC SecurityDevelopment Automations in SSDLCRisk assessment in applications (Web, Mobile)Support with Secure Development Standards and GuidelinesDocumentation of procedures and technical materials
  • Natura &Co
    Application Security Consultant
    Natura &Co Feb 2023 - Apr 2024
  • Capitani Group
    Information Security Specialist
    Capitani Group May 2024 - Present
    São Paulo, Brasil
    Capitani Group a next-generation global technology consulting company that helps enterprises reimagine their businesses for the digital age.It has been supporting its clients in developing solutions with innovation and cybersecurity specialized.With a presence in Brazil & Latam, USA, Europe and Australia, the group is recognized for the quality and commitment of its professionals in the projects it works on.
  • Nova8
    Application Security Engineer
    Nova8 Jul 2021 - Apr 2024
    São Paulo E Região, Brasil
    • DevSecOps• CI/CD (Azure DevOps, Jenkins, Bitrise)• TAM - Technical Account Manager• SSDLC - Helping Introduce Security in SDLC process. (Software Development Life Cycle)• Security awareness• Source Code Review • Vulnerability Management• Vulnerability Risk Assessment • AppSec• SAST, DAST, SCA, IAC Security• Pentest• Web Application Analysis• Checkmarx | Acunetix | Burp Suite• Log Analysis• Agile methodology | SCRUM• Advanced Technical Support• Data Protection• Secure Coding Best Practices• Web Application Risk Assessment• Threat Modeling
  • Nova8
    Application Security Analyst
    Nova8 Feb 2020 - Jul 2021
    São Paulo, Brasil
    • Introduction of SAST, DAST, SCA, IAC Security tools on CI/CD Pipelines.• Participation in Application Architecture meetings for greater understanding of the functionalities, features and design patterns of applications..• Assessment and validation of vulnerabilities and alerts coming from almost discovery sources such as SAST, DAST, CSIRT, Pentest, Bug Bounty, WAF.• Exploitation of vulnerabilities found in security tools such as SAST, DAST or Pentest. demo via proof-of-concept.• Expertise in the implementation of Security on the Development pipelines of large Companies.• Already work on tickets related to technical problems, analyzing the health of the environment to have the best usability.• I worked on ticket analysis in On-Premises environments, Log analysis and advanced problems investigation.• Vulnerability management and validation/post-exploitation for identified vulnerabilities in Web Applications.• Experience with Agile methodology (SCRUM), Completion of tasks and projects in agreed time.
  • Cogna Educação
    Application Security & Devsecops Consultant
    Cogna Educação Mar 2021 - Nov 2022
    • Azure DevOps CI/CD Secure pipelines• SAST, DAST, SCA• Development tools for automations• Penetration Testing• API Security assesment• Automated dashboards for KPI's• PowerBI• Checkmarx• Acunetix• Burp Suite• Assessment and validation of vulnerabilities and alerts coming from almost discovery sources such as SAST, DAST, CSIRT, Pentest.• I worked on ticket analysis in On-Premises environments, Log analysis and advanced problems investigation.• Vulnerability management and validation/post-exploitation for identified vulnerabilities in Web Applications.• Experience with Agile methodology (SCRUM), Completion of tasks and projects in agreed time• Exploitation of vulnerabilities found in security tools such as SAST, DAST or Pentest. demo via proof-of-concept.
  • Bugcrowd
    Cyber Security Analyst
    Bugcrowd Aug 2018 - Jul 2019
    Crowdsourced security company that safeguards organizations' assets from sophisticated threat actors before they can strike—by uniting our customers with trusted hackers via our AI-powered platform to take back control and stay ahead of attackers.
  • Hackerone
    Cyber Security Analyst
    Hackerone May 2018 - Dec 2018
    HackerOne empowers the world to build a safer internet. As the world’s trusted hacker-powered security platform, HackerOne gives organizations access to the largest community of hackers on the planet. Armed with the most robust database of vulnerability trends and industry benchmarks, the hacker community mitigates cyber risk by searching, finding, and safely reporting real-world security weaknesses for organizations across all industries and attack surfaces.
  • United States Department Of Defense
    U.S. Dept Of Defense - Responsible Disclosure Program
    United States Department Of Defense May 2018 - Dec 2018
    The program is intended to give security researchers terms and conditions for conducting vulnerability discovery activities directed at publicly accessible Department of Defense (DoD) information systems¹, including web properties, and submitting discovered vulnerabilities to DoD. If questions arise, please take no action until that action is discussed with the VDP lead at the Department of Defense Cyber Crime Center (DC3).Position: 14th 2018 Rankhttps://hackerone.com/deptofdefense/thanks/2018

Frequently Asked Questions about Andrei A.

What company does Andrei A. work for?

Andrei A. works for Natura

What is Andrei A.'s role at the current company?

Andrei A.'s current role is Application Security Specialist.

Who are Andrei A.'s colleagues?

Andrei A.'s colleagues are Bruna Silvestre, Alvaceli Dos Santosmoyses, Amaro Emiliano Trindade Silva, Dora Aliaga, Mara Lucia Sobral Santos, Michel Lima, Guillermina Brindis.

Not the Andrei A. you were looking for?

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.