Jonathan Santos is an Application Security Specialist with over a decade of hands-on experience bringing security into the software development lifecycle across fintech, cloud, and enterprise environments. He has led AppSec teams and shift-left initiatives at PagSeguro and Conta Simples, and currently drives application security at Grupo Boticário while teaching Cyber Defense topics like Ethical Hacking and DevSecOps at FIAP. His background spans offensive and defensive security—penetration testing, threat modeling, SAST/SCA automation, secrets scanning, and vulnerability management—paired with secure architecture work in AWS and Azure. Jonathan started as a web developer and still codes in Python, having built tooling for pentests and an AI-based sensitive-data search, which gives him a practical edge when translating findings into developer-friendly fixes. Comfortable presenting to directors as well as mentoring engineers, he blends technical leadership with classroom pedagogy to raise organizational security maturity. Based in São Paulo, he combines a Master in Cyber Security with a pragmatic developer mindset that favors automation and measurable risk reduction.
11 years of coding experience
9 years of employment as a software developer
Master in Cyber Security Information Security, Master in Cyber Security Information Security at DARYUS Consultoria e Treinamento
Bachelor in Information Systems Analyses and System Development, Bachelor in Information Systems Analyses and System Development at Centro Universitário Eniac
Burpsuite extension writed in Python that looking for PII data (CPF) in passive requests, validate CPF and create issue.
Contributions:3 PRs, 2 pushes, 4 branches in 1 year 3 months
appsecburpsuitepluginpythonpython3
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.