Network Security, Vulnerability Assessment, Exploit Development, Python, Bash, PowerShell, Linux Administration, Windows Security, SQL, Nmap, Burp Suite, Metasploit, Active Directory Security.
- B.S., Computer Engineering, Networks, and Telecommunications | Instituto Superior de Engenharia de Lisboa (ISEL) (August 2023)
Cybersecurity Analyst @ CyberSafe (Feb 2024 - Present)
- Conducted phishing site takedowns and documented findings to support comprehensive vulnerability assessments.
- Leveraged SIEM tools such as Rapid7 InsightIDR, Darktrace, and ArcSight to analyze logs and identify root causes of security incidents.
- Created detailed incident reports to guide the remediation of identified vulnerabilities within defined scopes, collaborating with clients to determine optimal mitigation strategies.
Cybersecurity Academy Trainee @ Cisco (Oct 2023 - Feb 2024)
- Simulated real-world cyberattacks using Cisco tools (ASA, Firepower, ISE) to identify vulnerabilities and enhance incident response.
- Participated in reverse engineering sessions led by Cisco Talos Head in Portugal.
- Collaborated on team projects for network configuration simulations, including client meetings and task coordination.
Bug Bounty Hunter (Aug 2025 - Present)
- Discovered P4 vulnerability (Broken Access Control) on NASA's Vulnerability Disclosure Program: Exposed unauthenticated API endpoints.
- Active researcher on HackerOne and Bugcrowd platforms, specializing in API security, authentication bypass, access control issues, and web application testing.
- Applied practical skills from PortSwigger Web Security Academy to identify OWASP Top 10 vulnerabilities in real-world targets.
Advanced Penetration Testing Studies (Self-Directed)
- OSEP (PEN-300) - In Progress: Completed all Offensive Security lab modules, focusing on AV/EDR evasion, process injection, and advanced Active Directory techniques. Pivoted to bug bounty for practical application before exam.
- Cloud Penetration Testing: Completed all PwnedLabs exercises across AWS, Azure, and GCP, practicing cloud-native attack techniques, misconfigurations, IAM exploitation, and resource enumeration.
- Web Application Security: Completed all labs in PortSwigger Web Security Academy (OWASP Top 10, advanced vulnerabilities, API security). Mastered SQL injection, XSS, CSRF, authentication bypass, SSRF, XXE, and prototype pollution. Ranked #50 in Hall of Fame. Preparing for Burp Suite Certified Practitioner (BSCP) certification.
- Compromised 150+ machines across Hack The Box (HTB), Proving Grounds, VulnLab, and Offensive Security labs.
- Completed HTB ProLabs: Dante (pivoting techniques), Zephyr (Active Directory), Cybernetics (advanced exploitation).
- Automated tasks with Python/Bash/PowerShell scripts for enumeration, brute-forcing, and exploitation.
- HTB Rank: Hacker | TryHackMe Rank: Hacker
- Offensive Security Certified Professional (OSCP/OSCP+) (December 2024 - December 2027)
- Penetration Tester Path from Hack The Box (HTB) (July 2024)
- Practical Ethical Hacking from TCM Security (May 2024)
- HTB Pro Labs: Dante (June 2024), Zephyr (June 2025), Cybernetics (June 2025)
- PortSwigger Web Security Academy Completion (Oct 2025) All labs; Ranked #50 in Hall of Fame
- eLearnSecurity Junior Penetration Tester (eJPT) (April 2024)
- Cisco Certified Specialist - Network Security: Firepower (CCSNS-Firepower) (February 2024 - February 2027)
- Certified Ethical Hacker (CEH v12) (February 2024 - February 2027)
- Cisco Certified Network Associate (CCNA) (November 2023 - November 2027)
- Cisco Certified CyberOps Associate (CCCA) (October 2023 - February 2027)