A offensive security professional, experienced with penetration tests in Web, Mobile applications andInternal Networks, focused on understand the application architecture and usage flow, not just another toolrunner, writing professional reports in English/Portuguese explaining all finds to the developer team andsuggesting good mitigations to them, writing real-world Proof Of Concepts and showing the real impact ofthe found issues in the application.
-
Cyber Security ConsultantHakai Offensive Security Oct 2023 - Aug 2024White/Black/Gray Box penetration tests, in the following environments:Web applications using the most modern technologies and architectures, such as NodeJS, PHP, Java,Golang, with different types of APIs such as GraphQL, Rest and Soup and different databases, SQLite,Mysql and Microsoft SQL;Android Mobile applications reverse engineering and code review (React Native, Java, Kotlin, Flutterand C/C++ native libraries), implementing anti-tampering bypasses, like Root Detection, SSL Pinning andFrida detection by writing memory Hooks using the Frida tool kit and reversing engineering JNI (JavaNative Interfaces) with Ghidra;Writing professional reports explaining all finds and recommending good mitigations to them; -
Cyber Security AnalystAb Inbev Apr 2022 - Oct 2023RemoteHelping developers to improve your code security skill by doing technical presentations to the team, andexplaining vulnerabilities, tools and offensive techniques;Testing and implementing useful tools in the Secure Development Cycle like Snyk, a dependency andlicense scanner, Checkmarx a SAST and DAST tool, TruffleHog a secret scanner and Semgrep;Realizing multiple penetration tests projects in Web, API & Mobile applications, most focused on FlutterAndroid applications using the OWASP pentesting and reversing methodologies;Reverse engineering Android & IOS applications by using different decompilers and tools for each appimplementation, such as Jadx for Java/Kotlin and Ghidra for Native Libraries and Flutterimplementations;Bypassing Android & IOS Anti-Tampering implementations, such as Root, Emulation & Frida Detections andcommunication protections like AES request body encryption and SSL Pinning by using the modernmemory instrumentation framework named Frida;Writing reports and presentations to explaining all vulnerabilities found and recommending goodmitigations to them;- Bypassing Android & IOS Anti-Tampering implementations, such as Root, Emulation & Frida Detections, and other protection implementations like AES encryption and SSL Pinning by using the modern memory instrumentation framework named Frida and creating custom scripts for that;- Exploring Android IPC missconfigurations and weak implementations; -
Application Security EngineerStone Dec 2021 - Mar 2022Remote- Realizing multiple penetration test projects in Web, API & Mobile; -
Cyber Security ConsultantItaltel Jul 2021 - Dec 2021Remote- Realizing multiple penetration test projects in Web, API, Mobile & Intern Networks applications; -
Cyber Security ConsultantProof Apr 2021 - Jul 2021Remote- Working on several Red Team projects which involved performingtasks such as penetration tests and Open Source Intelligence enumeration;- Realizing multiple penetration test projects in Web/Mobile applications & Intern network applications;
Frequently Asked Questions about Natan S.
What is Natan S.'s role at the current company?
Natan S.'s current role is Cyber Security Consultant.
Not the Natan S. you were looking for?
-
Natan S. Costa
Itapevi, Sp -
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial