Independent work
Applications, automation and cybersecurity
Development of security scripts and utilities. Assessments of APIs, authentication, authorization and web applications. Server hardening and integration of OWASP practices into development.
Security Operations, AppSec and Security Engineering. Development, automation and analytical thinking applied to protecting systems.


Hands-on practice in vulnerability exploitation, enumeration, Active Directory, privilege escalation and lateral movement in controlled environments.
01 / EXPERTISE
A development background for investigating risk, strengthening applications and automating security workflows.
Monitoring, log analysis and threat investigation. Knowledge of SOC/SecOps, incident response and vulnerability management.
Web application and API assessments, code review, authentication and authorization. Security integrated into development and the software lifecycle.
Web pentesting, enumeration, infrastructure assessment and vulnerability validation. Hands-on lab practice with Active Directory and lateral movement.
Application and server hardening, access control and automation. Development experience applied to scripts, integrations and security workflows.
02 / LAB
An HTTP header analysis: from an exposed configuration to the implementation of protective controls.
HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Server: sample-app
Cache-Control: no-storeAnalysis is limited to the controls in this sample. It does not represent a complete security audit.
LOCAL SAMPLES · NO EXTERNAL SCANS
Completed Hack The Box labs in controlled environments.
03 / EXPERIENCE
More than 17 years in technology, digital development, automation and complex projects. Today, practice and training focused on cybersecurity.
Selected technical contributions from the résumé.
Download résuméDevelopment of security scripts and utilities. Assessments of APIs, authentication, authorization and web applications. Server hardening and integration of OWASP practices into development.
Participation in endpoint and digital environment protection initiatives. Automations, scripts and integrations for operational processes. Multidisciplinary team leadership and complex project management.
Founded and managed a digital company. Full stack development, code review and remediation of vulnerabilities including SQL Injection and XSS. Input validation and server and database hardening.
04 / EDUCATION
Academic training, continuous practice and more than 80 courses, certificates and credentials in Cybersecurity and Technology.
PUCPR · 2021–2022
Universidade Anhembi Morumbi · 2008–2012
Native Portuguese. Advanced English for reading and technical research; intermediate English for conversation and meetings.
SOC · Threat Investigation · Network Security
Incident Response · Forensics · Penetration Testing
Defender · IAM · Azure Security
Network Security · Cloud Security
FortiGate Administrator
Detection & Response · Python · Linux
IAM · Cloud Security · DevOps
Cybersecurity · Generative AI · Zeek
Auditing Generative AI · Risk Mitigation
NEXT CONVERSATION
Opportunities in Cybersecurity, Security Operations, AppSec and Security Engineering.
lmorato@gmail.comSão Paulo, Brazil · Remote work