Jonathan Joshua
Offensive Security Engineer @ Nubank
About
Hello, my name is Jonathan. Nice to meet you! 👋 I’m an offensive security engineer with over 6 years of experience in penetration testing, red team operations, and adversary emulation across infra, web, mobile, and cloud environments (AWS/GCP). My work focuses on identifying and exploiting vulnerabilities to uncover weaknesses, validate defenses, and elevate security resilience. Currently, I specialize in red team operations focused on multi-cloud environments such as (aws/gcp/az), phishing campaigns, and also developing several templates for integration with gophish and evilginx, available on my GitHub. At the same time, I focus my research on the Web3 and blockchain ecosystem, with an emphasis on infrastructure (layers, ZK, and related protocols). In my spare time, I investigate Web3 hacks and thefts, tracking transactions using tools such as TRM, Chainalysis, and open-source solutions. I frequently participate in Capture The Flag (CTF) competitions, which help me stay sharp and continuously evolve my skill set. CTFs: 1st Place | Blockchain CTF by Kraken at DEFCON 6th Place | International Cybersecurity Championship & Conference (IC3) 3rd Place | Cyber 9/12 Strategy Challenge 10th Place | SANS Brasil Army Netwars Core v7
Brazil
Brasília
Computer & Network Security
Resposta a incidentes, Pentest, Red Team, Blockchain, Ethical Hacking, Product Security, Phishing, Segurança cibernética, Engagements, OWASP ZAP, Autenticação, Liderança, Estratégia de mitigação, Revisões de design, Digital Assets, Ruby, Modelagem de ameaças, Economia, Habilidades analíticas, Requisitos de negócio
Experience

Offensive Security Engineer
Бразилиа, DF
As an offensive security engineer, I specialize in penetration testing and adversary emulation across web, mobile, and cloud environments. My mission is to uncover weaknesses before adversaries do by replicating advanced attack chains, validating defensive controls, and strengthening overall cyber resilience through continuous testing and automation. Technologies & Skills: • Offensive Operations: Penetration testing, adversary emulation, and web3/blockchain assessments • Penetration Testing: Web, mobile, API, infrastructure, and cloud environments (mainly AWS) • Automation & Tooling: Python, Go, Rust, Bash, and Clojure • Threat Simulation: Purple Team collaboration and detection validation • Security Research: Emerging threat analysis in blockchain environments Results: • Identified and exploited critical vulnerabilities across production environments, improving detection coverage and response time • Strengthened defensive engineering by integrating offensive telemetry into SOC and detection pipelines • Elevated organizational readiness through advanced simulations and continuous offensive exercises

Sr Cyber Security Analyst
Brasília, Distrito Federal, Brasil
As a cybersecurity analyst at Morphus Security (now Accenture), I specialized in developing and executing advanced adversary emulation and attack simulation programs. My work involved designing automated adversary simulation techniques, deploying cyber range infrastructures, and validating the effectiveness of enterprise security controls through realistic breach and attack simulations. This role required deep collaboration with Blue Teams and SOC analysts to strengthen detection capabilities and improve the organization’s overall security posture. Technologies & Solutions: • Breach and Attack Simulation (BAS) platforms, mainly Caldera C2 • Adversary Emulation and Red Teaming frameworks • Cyber Range Lab Infrastructure Design • Automation and Scripting for Attack Scenarios • SIEM and SOC Integration to create threat detection rules • Testing Endpoint Security Solutions (e.g., Sophos, Kaspersky, CrowdStrike, and SentinelOne) Results: • Enhanced the organization’s defensive readiness by automating recurring attack simulation procedures • Helped reduce incident detection time by improving SOC correlation and playbook validation • Increased security control coverage through structured testing of prevention and detection layers • Strengthened executive visibility on cyber risk by delivering technical findings translated into strategic insights

Cyber Security Analyst
As a cybersecurity analyst, I focused on administering enterprise security solutions, performing vulnerability assessments, and leading offensive security operations. My role involved managing IPS/IDS controls, coordinating red team and penetration testing initiatives, and securing critical industrial environments through assessments of SCADA systems. Technologies & Solutions: • Endpoint Protection: Kaspersky Endpoint Security • Vulnerability Management: Nessus / Tenable.io / Tenable.ot / Tenable.sc • Network Defense: IDS/IPS implementation and tuning (mainly Watchguard) • Offensive Security: Penetration testing and red teaming • SCADA/ICS Security Assessments: (Coca-Cola infrastructure and Brasal Energia) Results: • Strengthened security posture by identifying and mitigating high-impact vulnerabilities across industrial and corporate networks • Enhanced threat detection and prevention capabilities through proactive IPS/IDS configuration and tuning • Reduced incident exposure time by streamlining vulnerability remediation and cross-team collaboration • Conducted penetration tests in SCADA environments, validating the resilience of critical control systems and industrial networks

Network Security Technician
Brasília, Distrito Federal, Brasil
As a network security technician, I was responsible for managing and implementing enterprise-level firewall and endpoint protection solutions, as well as leading penetration testing and red team initiatives to identify and mitigate security risks. My work included designing IDS/IPS policies, conducting vulnerability assessments, and collaborating with multidisciplinary teams to enhance network resilience and data protection across the organization. Technologies & Solutions: • Firewall & Endpoint: Sophos envirometns (Sophos Firewall / Sophos EDR Endpoint) • Threat Detection: IDS/IPS policy design and deployment (mainly Sophos) • Offensive Security: Penetration Testing and vulnerability management with Tenable Results: • Strengthened network and endpoint defense through optimized firewall rules and endpoint protection strategies • Improved threat detection accuracy by designing and fine-tuning IDS/IPS policies across multiple environments • Reduced response time to incidents by integrating Red Team findings into defensive playbooks • Ensured regulatory and internal compliance through systematic vulnerability audits and remediation planning

Network Technician
Brasília, Distrito Federal, Brasil
As a network technician, I was responsible for planning, monitoring, and maintaining the firm’s computer network infrastructure to ensure availability, performance, and reliability. My work included managing local area networks (LAN), administering Active Directory environments, configuring network resources, and supporting IT operations with a strong focus on cybersecurity and system integrity. Technologies & Solutions: • Network Administration: Local Area Networks (LAN), TCP/IP, DHCP, DNS • Directory Services: Active Directory, Group Policy Management • Server & Infrastructure: Windows Server, Network File Sharing, Backup Systems (Veeam) • Monitoring & Troubleshooting: Wireshark, PRTG, and performance diagnostic tools • Security: Network Hardening, Access Control, Firewall Configuration • Documentation & Standards: IT asset documentation, configuration standardization, process improvement Results: • Improved network uptime and reliability through proactive maintenance and continuous monitoring • Streamlined user and resource management in Active Directory, reducing administrative overhead • Enhanced security and compliance by implementing access control policies and structured network segmentation • Contributed to the optimization of IT processes, improving documentation and deployment consistency

Technical support
D'Tudo Serviços & Tecnologia
Brasília, Distrito Federal, Brasil
As a technical support professional, I was responsible for assembling, configuring, and maintaining computer systems and peripherals to ensure smooth daily operations. I supported local network configuration, troubleshooting, and performance optimization, contributing directly to system reliability and user productivity. My work also focused on improving standardization, minimizing downtime, and ensuring compliance with IT best practices. Technologies & Solutions: • Hardware & Systems: Microcomputer assembly, component replacement, OS installation (Windows/Linux) • Networking: LAN configuration, IP management, router and switch setup • Diagnostics & Troubleshooting: Hardware testing, network analysis tools, driver, and firmware updates • Support Tools: Remote desktop management, help desk systems, ticket-based support • Documentation & Standardization: Setup procedures, asset inventory, deployment templates • Security & Compliance: Basic endpoint protection, policy enforcement, IT maintenance standards Results: • Reduced system downtime through faster troubleshooting and proactive maintenance • Improved equipment deployment efficiency by standardizing configuration processes • Enhanced user productivity by ensuring stable network connectivity and reliable hardware • Supported the alignment of IT operations with internal policies and security best practices
Jonathan Joshua's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


