Marcos Santos

Systems Analyst Cyber Security DevSecOps


A brief summary of my career

I am a systems analyst and programmer from São Bernardo do Campo, Brazil now living in Karlsruhe, Germany. I have always focused on information security and currently study Cyber Security programming. One of my differentials is that I like to pass on information and teach those who are entering in the area of Technology as I went through several functions over time in which I learned about infrastructure, software development, and currently I found myself in Cyber Security. I support other developers make their codes more secure, while also creating softwares to help me in my routines, thus increasing my productivity. I also create softwares and commercial sites on my spare time.

About me


Open to Work


September 9th


University Degree Completed


Work Contract, Freelance


Cyber Security / DevSecOPs/ Application Security

Personal Skills

After Effects & Premiere

Content creation using adobe tools.


Focused on results, I have great expertise in analyzing and making decisions to bring the best possible result at the best possible cost.


Constant personal improvement, always seeking to reduce time in all activities that allow me to do so, bringing more productivity over time.


With knowledge ranging ​from infrastructure to Cybersecurity, that allow me to talk to different areas for better integration.


  • Mar 2021 - Today

    Nova8 Cybersecurity, Alphaville

    CyberSecurity Coordinator

    • Preparation of Pre-Sales Processes
    • Creation of PoC Reports and presentations to the Board
    • Creation and configuration of environments, SAST, DAST, IAST and SCA
    • Realization of PoC of SAST, DAST, IAST and SCA products
    • Presentation of final meeting with CISO and customer directors
    • Creation of vulnerability search rules
    • Integration with CI/CD Tools, IDE, Bug Tracking, etc.
    • Vulnerability management based on OWASP TOP 10, NIST, FISMA and PCI compliance
    • Fixing vulnerabilities with the help of SAST tools
    • Azure Firewalls/WAF/KMS
    • Security Tools: Checkmarx, Acunetix/NetSparker, Bright(Neuralegion), Probely, WhiteSource, Imperva

  • Mar 2020 - Mar 2021

    BrScan, Brooklin

    Information Security Analyst

    • Code Review with Veracode
    • Vulnerability analysis using SAST tools (Veracode)
    • Application Testing
    • Fixing vulnerabilities with the help of SAST tools
    • Creation of scopes, procedures, DRN, DFP, Specifications and Functional Documents
    • Modification and creation of queries and procedures
    • Documentation of new features to the system
    • Preparation of test scripts

  • Nov 2016 - Jan 2020

    Grupo Tejofran, Barra Funda

    Systems Analyst

    • Analysis and Development of Internal Systems in PHP and .NET
    • Creating queries using MS SQL and Oracle SQL
    • SAFX creation for submission to MasterSAF
    • Functional Analyst LG FPW (Payroll)
    • Environment Management MS Azure and AWS
    • Customization of ERP People Soft
    • TOTVS Functional Analyst HR and Inventory modules
    • MS Dynamics Functional Analyst
    • Preparation of Procedures, DFP, DRN, Scopes, Specifications, etc.
    • Implementation of SCRUM and Kanban

  • Mai 2016 - Out 2016

    GBB, São Caetano do Sul

    Systems Analyst

    • Complete development of the Benefits Purchase System (PHP Laravel)
    • Creation and Management of MS Azure and AWS environments
    • Search automation using robots in C#
    • Automation of BackUp routines
    • Database Tuning
    • Presentation at business meetings and new customers
    • Development of systems architecture
    • Development of API Rest integrations using .NET and PHP

  • Jun 2015 - Mai 2016

    JIDD Sistemas, São Bernardo do Campo

    Systems Analyst

    • Creation and Management of MS Azure and AWS environments
    • Search automation using robots in C#
    • Automation of BackUp routines
    • Implementation and integration in MS BizTalk environment
    • Presentation at business meetings and new customers
    • Development of systems architecture
    • Creation and maintenance of .NET and PHP codes
    • Analysis and systems development
    • New features for applications using web architecture
    • Business meetings
    • Development of APP's for android using the PhoneGap framework
    • PHP Developer Trainin


  • Ago 2021 - Ago 2023

    FIAP, Aclimação, SP

    Defesa Cibernética

    • CyberSecurity & Hacker Techniques
    • Development & Coding for Security
    • Hardware Hacking (Internet of Things)
    • Security Management (Policy and Vulnerability)
    • Cyber Threat Intelligence (DeepWeb & Cyberwars)
    • Defensive Cyber OPS (Forensics & Incident Handling)
    • Malware Analysis

  • Jun 2016 - Dez 2018

    SBTec, São Bernardo do Campo


    • IT Governance
    • Strategic Planning
    • Architecture 
    • Database

  • Jan 2013 - Jan 2015 (trancado)

    IMT (Instituto Mauá de Tecnologia), São Caetano do Sul


    • Software Engineering
    • Software development
    • Quality Management
    • Application architecture
    • Database