
Jean M.
Cibersecurity Researcher

Connect with Jean M. to Send Message
Connect
Connect with Jean M. to Send Message
ConnectTimeline
About me
Red Team | Penetration Tester | Offensive Security | Security Architect | Cybersecurity Engineer | Appsec | C/C++ | Python | Java | Linux | CTF | DevSecOps
Education

Universidade Tecnológica Federal do Paraná
2025 -Master's degree Computer ScienceResearch Field: Distributed Systems, Computational Intelligence, and CybersecurityAdvisor: Professor Dr. Rodrigo Campiolo

Universidade Tecnológica Federal do Paraná
2018 - 2023Bachelor of Computer Science Information Technology 100Activities and Societies: Member of the Cybersecurity Research Group at the Federal University of Technology – Paraná (UTFPR-CM) In my final paper, "Creation and Evaluation of Forensic Scenarios in Linux Systems," I had the opportunity to make a significant contribution to the field of computer forensics for the NIST CFReDS and TryHackMe platforms. With the participation of a forensic expert from the Federal Police on my thesis committee, her insights enhanced the quality and practical relevance of my research. Through this project, I applied theoretical knowledge to real-world scenarios, emphasizing the practical… Show more In my final paper, "Creation and Evaluation of Forensic Scenarios in Linux Systems," I had the opportunity to make a significant contribution to the field of computer forensics for the NIST CFReDS and TryHackMe platforms. With the participation of a forensic expert from the Federal Police on my thesis committee, her insights enhanced the quality and practical relevance of my research. Through this project, I applied theoretical knowledge to real-world scenarios, emphasizing the practical applicability of my findings and highlighting the impactful collaboration with law enforcement expertise.My publications:- https://cfreds.nist.gov/all/utfpr/LinuxForensicsScenario- https://tryhackme.com/room/lookingforevidencesrr- https://cfreds.nist.gov/all/JeanMiguel%2FUTFPR/Linuxforensicsscenariosimulatedattackonacompanyserver Show less
Experience

UTFPR
Apr 2017 - Apr 2021Cibersecurity Researcher• Developed tutorials on Information Security and Computer Systems for the community and for undergraduate courses in Computer Science.• Delivered lectures in schools and universities to spread knowledge about information security.• Analyzed and automated attacks and vulnerabilities.• Conducted penetration testing on computer systems and networks using the following tools: Wireshark, Netcat, Maltego, Hydra, John The Ripper, Ettercap, Nikto, Metasploit Framework, Ghidra, SQLmap, Hashcat.• Analyzed and reproduced malware and attacks on Unix/Linux, Android, and Windows systems.• Analyzed logs and wrote technical and scientific reports.• Studied the anatomy and behavior of ransomware, such as WannaCry. Show less

SiDi
Jan 2022 - Jun 2023Software security analyst - (Red team)• Conducted security audits on Samsung software, including mobile devices, IoT, web applications, and APIs, using black-box, gray-box, and white-box approaches.• Performed code reviews on Java, Kotlin, and JavaScript projects, ensuring secure development best practices for the applications.• Led Dynamic Analysis (DAST) and Static Analysis (SAST), as well as penetration testing, referencing OWASP and MITRE ATT&CK standards. Main tools used: BurpSuite, Drozer, MobiSF, Frida, APKTool, ADB (Android Debug Bridge), JadX.• Developed technical reports and Proofs of Concept (PoC) for Samsung's development team, detailing vulnerabilities identified in the systems and providing mitigation strategies.Collaborated in creating a phishing awareness campaign for employees, contributing to a proactive security culture.• Practiced reverse engineering of Android applications, enhancing understanding and security measures.• Participated in the Security by Design process for projects involving major players in the technology industry, providing valuable insights to ensure threat-resistant architecture from the project’s inception. Show less

Quality Digital
Jun 2023 - Feb 2025Information Security Analyst - Mid Level• Responsible for conducting black-box, gray-box, and white-box penetration testing to protect large-scale e-commerce environments: Use of tools such as Burp Suite, OWASP ZAP, SonarCloud, and SonarQube, and frameworks like OWASP and NIST to ensure compliance with security best practices and LGPD/GPDR.• Promoted secure development practices throughout the Software Development Life Cycle (SDLC), collaborating with development teams to perform detailed code reviews (mainly on Node.js and TypeScript projects).• Created information security content, conducting awareness sessions within the organization.• Responsible for creating CI/CD pipeline automation using the Python programming language, enhancing security processes and providing visibility for the development team. Show less

Capitani Group
Jun 2024 - nowInformation Security Architect - SR• CLIENT (ALLOS) - Largest Shopping Mall Network in Brazil• Coordinated management committees and vulnerability prioritization.• Implemented Continuous Integration (CI) pipelines in collaboration with the DevOps team, providing visibility of vulnerabilities to developers by integrating GitLab with static analysis tools such as Snyk and Orca Security.• Led Red Team activities, including penetration testing and reverse engineering on Mobile (Android and iOS), Web, APIs, and Desktop applications.• Responsible for creating secure development best practices documentation for development teams.• Implemented DevSecOps processes within the company, such as the Security Champions program, and raised awareness among developers about secure development practices, secure by design, and SSDLC.• Managed vulnerabilities using tools such as Qualys and Appknox.• Implemented features in Cloud environments (Azure) using Terraform.• Conducted code reviews to ensure security best practices according to frameworks like OWASP and NIST. Show less

RNP
Feb 2025 - nowCybersecurity mentor - "Hackers do bem" technology residency programMentoring of students in the "Hackers do Bem program" with a specialization in Red Team, responsible for providing direct and personalized support to the residents, ensuring their theoretical, practical, and behavioral development, assisting them with doubts, and correcting technical reports.
Licenses & Certifications
- View certificate

Cybersecurity Essentials
CiscoDec 2020 
Programador Web
Senac
Projetos ágeis com SCRUM
Digital Innovation One Inc.May 2020
Linux Beginners in Cloud Online
4LinuxMay 2020- View certificate

Introdução ao PHP
Digital Innovation One Inc.May 2020 - View certificate

Introduction to Cybersecurity
CiscoDec 2020 - View certificate

Formulário com condicionais e sessões com PHP
Digital Innovation One Inc.May 2020 - View certificate

Lógica de Programação
Digital Innovation One Inc.May 2020 - View certificate

Conhecendo Funções e Validação de dados com PHP
Digital Innovation One Inc.May 2020 
Introdução ao Git e Controle de Versões
Digital Innovation One Inc.May 2020
Volunteer Experience
Cybersecurity researcher
Issued by Universidade Tecnológica Federal do Paraná on Apr 2017
Associated with Jean M.Criador de CTF (Capture the Flag)
Issued by TryHackMe on Mar 2023
Associated with Jean M.Data Corpora creator
Issued by National Institute of Standards and Technology (NIST) on Oct 2022
Associated with Jean M.
Languages
- poPortuguês
- inInglês
Recommendations

Alexa lyczba
Product & Pricing Management | Automotive Professional | Car EnthusiastHungary
Prateek garg
Tech Visionary & Group Lead | 7+ Years of Mastery in Java, Spring Boot, Android & Flutter | Empoweri...Gandhinagar, Gujarat, India
Parth sharma, eit
Civil EngineerNew Delhi, Delhi, India
Nihatcan ertuğ
Computer EngineerBakırköy, Istanbul, Türkiye
Eric d.
Gestion de projets IT (Infra, Sécurité, Compliance)La Louvière, Walloon Region, Belgium
Delphine urbin
Consultante en développement professionnel et personnel . Certifiée CCTI, MBTI, Strong, Intelligenc...United Kingdom
Gal shevach
31 Years old, residents in Tel Aviv, Israel. High sales skills in addition to very customer oriented...Tel Aviv District, Israel
Harry fowler
Project Manager at VPS GroupNorwich, England, United Kingdom
Rahul sonker
Manager @ Genpact | MBA, Process Improvement, FinanceGurugram, Haryana, India
Er. rupesh kumar verma
Student at Institute of Technology and Management gorakhpurGorakhpur, Uttar Pradesh, India
Kate tudor, phd
Principal Researcher | Nesta (A Healthy Life Mission)London, England, United Kingdom
Adarsh babu
Exercise Physiology | Physical Education Teacher | ISAK LEVEL 1 Anthropometrist | BCCI Level A crick...Malappuram, Kerala, India
Aayush pagare
Full stack engineer building on RAG and LLMs | TS | Next.jsVadodara, Gujarat, India
Emilson avelino dos santos filho
Gerente Geral de Rede Digital | Caixa Econômica FederalCampina Grande, Paraíba, Brazil
Bruna hallage caporali
Formada em Publicidade e Propaganda pela ESPMSão Paulo, São Paulo, Brazil
Srinivasan vasudevan
Castings Specialist with Techno- Commercial Experience ┃ PDC, GDC, LPDC Castings & Dies Supplier Dev...Chennai, Tamil Nadu, India
Camelia jonathan
Audio Engineer - Music Producer - Voice Over TalentJakarta, Indonesia
Tushar chaudhari
Managing Consultant at IBM India Private LimitedPune, Maharashtra, India
Nicolas wentzell
Trainee Forest TechnologistQuesnel, British Columbia, Canada
Abdelrhman ibrahim
Information Technology Specialist at AlmosaferCairo, Egypt
...