Jonathan Santos

Application Security Specialist

São Paulo, Brazil
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

👤
Senior
🎓
Top School
Jonathan Santos is an Application Security Specialist with over a decade of hands-on experience bringing security into the software development lifecycle across fintech, cloud, and enterprise environments. He has led AppSec teams and shift-left initiatives at PagSeguro and Conta Simples, and currently drives application security at Grupo Boticário while teaching Cyber Defense topics like Ethical Hacking and DevSecOps at FIAP. His background spans offensive and defensive security—penetration testing, threat modeling, SAST/SCA automation, secrets scanning, and vulnerability management—paired with secure architecture work in AWS and Azure. Jonathan started as a web developer and still codes in Python, having built tooling for pentests and an AI-based sensitive-data search, which gives him a practical edge when translating findings into developer-friendly fixes. Comfortable presenting to directors as well as mentoring engineers, he blends technical leadership with classroom pedagogy to raise organizational security maturity. Based in São Paulo, he combines a Master in Cyber Security with a pragmatic developer mindset that favors automation and measurable risk reduction.
code11 years of coding experience
job9 years of employment as a software developer
bookMaster in Cyber Security Information Security, Master in Cyber Security Information Security at DARYUS Consultoria e Treinamento
bookBachelor in Information Systems Analyses and System Development, Bachelor in Information Systems Analyses and System Development at Centro Universitário Eniac
languagesEnglish, Portuguese
github-logo-circle

Github Skills (13)

scanning8
secrets-detection7
plugin6
security5
sast5
devsecops4
security-scanner4
python4
security-automation4
html3
pentest2
blueteam2
sectools1

Programming languages (2)

HTMLPython

Github contributions (5)

github-logo-circle
jmessiass/devsecops

Nov 2023 - Sep 2025

Exemplo de workflow de segurança que realiza testes SAST, SCA, Secrets Scan e IaC Scan via GitHub Actions utilizando ferramentas open source.
Contributions:19 PRs, 81 pushes, 5 branches in 1 year 10 months
ci-cddastdevsecopsdevsecops-pipelinegithub-workflows
jmessiass/burp-pii-scan

Jun 2024 - Sep 2025

Burpsuite extension writed in Python that looking for PII data (CPF) in passive requests, validate CPF and create issue.
Contributions:3 PRs, 2 pushes, 4 branches in 1 year 3 months
appsecburpsuitepluginpythonpython3
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial