Skip to content
View PedroKetzer's full-sized avatar

Highlights

  • Pro

Block or report PedroKetzer

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
PedroKetzer/README.md

🛡️ Pedro Ketzer

Application Security Engineer

LinkedIn

🔐 Securing fintech systems processing $2.3B+/quarter
🎯 Identified a $300M financial risk through attack simulation
🐛 Managed 500+ unique vulnerabilities | 95% SLA

🧬 About Me

Application Security Engineer with 3+ years shipping security at scale in high-growth fintech. I partner with engineering teams to design and build security solutions that let developers move quickly and safely — from threat modeling and secure code review to building AppSec tooling that scales across services.

Passionate about pragmatic risk management, developer experience, and turning vulnerability data into actionable insights.


🔧 Arsenal

Domain Tools & Techniques
🎯 AppSec Core Threat Modeling (STRIDE) · Pentesting · Secure Code Review · Bug Bounty Triage · Security Reviews · OWASP Top 10
🔬 Security Tooling SAST · DAST · Network Scanners · Dependency Scanning
💻 Languages Go · Java · TypeScript · JavaScript · Python · PHP
☁️ Cloud & Infrastructure AWS Security · Terraform · Kubernetes · Docker · GitHub Actions · GitLab CI/CD

💼 Experience

🟡 Mercado Libre — Cyber Security Developer

Aug 2023 – Present · Osasco, Brazil

  • Secured financial products processing $2.3B+/quarter via threat modeling, pentesting, and code reviews across Go, Java, Python, and JS systems
  • Identified a $300M financial risk by reproducing insider attack scenarios in the financial ecosystem using AI-powered tools in 2 weeks
  • Managed 500+ vulnerabilities through bug bounty programs with 95% SLA compliance

🪵 MadeiraMadeira — Application Security Engineer

Sep 2022 – Aug 2023 · Curitiba, Brazil

  • Secured 30+ applications through threat modeling and code reviews, identifying 5 critical vulnerabilities
  • Led security initiative generating ~$40M annual savings (~1% quarterly revenue)
  • Integrated security practices into DevSecOps cycle with two key development squads

🔴 Daryus Consultoria — CyberSecurity Consultant

Jun 2022 – Aug 2022 · São Paulo, Brazil

  • Executed penetration testing for 5 enterprise clients in 2 months, reporting directly to C-level

📚 Alura — Instructor

Jun 2025 – Present · Osasco, Brazil

  • Co-designed "Security in Web Applications" with 70+ hands-on videos covering OWASP Top 10 across Node.js, React, Spring, and GraphQL

🇧🇷 RNP – Hackers do Bem — Mentor

Feb 2025 – Aug 2025 · Osasco, Brazil

  • Guided residents in Brazil's first government-backed DevSecOps residency ($5.5M initiative), implementing SAST and dependency catalog

🎓 Education

Degree Institution Year
MBA Software Architecture Instituto Full Cycle 2025
P.D Ethical Hacking & CyberSecurity Faculdade VINCIT 2023
B.A. Business ULBRA 2019

📜 Certifications

Code Review AWS CCP


🌐 Languages

🇧🇷 Portuguese (Native) · 🇺🇸 English (Advanced) · 🇪🇸 Spanish (Advanced)


Profile Views

Pinned Loading

  1. roadmap-appsecbr roadmap-appsecbr Public

    Junção de conteúdos, dicas e considerações da comunidade do Br de AppSec para divulgar a palavra do DevSecOps e orientar aspirantes que não se encaixam nem com Red e nem com Blue team

    263 29

  2. roadmap-appsec roadmap-appsec Public

    A collection of content, tips and considerations from the AppSec community to spread the word of DevSecOps and guide aspirants who don't fit in with either Red or Blue team.

    26 1