Rafael Gomes
Analista de segurança de redes
About
Especialista em Segurança da Informação focado em identificar vulnerabilidades críticas e fortalecer perímetros digitais através de uma mentalidade ofensiva. Com sólida experiência em Pentesting e Bug Bounty, atuo na linha de frente da identificação de falhas em infraestruturas complexas, combinando metodologias de análise de vulnerabilidades com o desenvolvimento de ferramentas personalizadas.Minha expertise engloba o Malware Development para fins educacionais, simulação e desenvolvimento de ferramentas, permitindo a criação de vetores de ataque controlados que ajudam organizações a compreenderem e anteciparem táticas de adversários reais. Atualmente, contribuo ativamente como Security Researcher em plataformas como HackerOne, onde foco em testar a resiliência de grandes infraestruturas globais.
Brazil
Manaus
Computer & Network Security
Pesquisa de segurança, Criptografia, GRC, Computação em nuvem, Programação lógica, Análise de malware, Detecção de malware, Reversão de malware, Inteligência artificial, Sistemas de inteligência artificial, Equipe vermelha, Resposta a incidentes de segurança, Liderança de equipe, red team, Antiphising, Forense digital, CCNA, Segurança da informação, Gestão de vulnerabilidade, Operações de segurança
Experience

Analista de segurança de redes
W.A TECHNOLOGY SOLUTIONS
Манаус, AM
Administração e monitoramento contínuo de firewalls e plataformas SIEM/EDR para detecção de ameaças. Mapeamento e análise de superfície de ataque externa (EASM). Implementação de segmentação de rede para mitigação de movimentação lateral. Condução de campanhas controladas de phishing para fortalecimento da cultura de segurança e redução de riscos humanos.

Bug Bounty Hunter
Brasil
Advanced Vulnerability Research: Execute self-directed threat hunting and vulnerability research against hardened Fortune 500 infrastructures and top-tier public/private bug bounty programs, adhering to strict rules of engagement. Attack Surface Automation (EASM): Engineer custom reconnaissance pipelines and automation scripts to conduct continuous, large-scale mapping of external attack surfaces, uncovering shadow IT and uncharted digital assets. Manual Exploitation & Critical Impact: Perform rigorous manual penetration testing to identify, chain, and exploit critical vulnerabilities (e.g., RCE, SSRF, IDOR) that successfully evade automated Dynamic Application Security Testing (DAST) solutions. Business Logic Flaw Discovery: Reverse-engineer complex application architectures and workflows to uncover deep-seated business logic flaws and privilege escalation vectors, demonstrating a profound understanding of application behavior. PoC Development & Weaponization: Program and weaponize highly reliable, custom Proof-of-Concept (PoC) exploits to definitively demonstrate the exploitability, exploit chains, and maximum severity of identified vulnerabilities. Strategic Risk Reporting: Author comprehensive, executive-ready technical reports detailing vulnerability mechanics, realistic business impact (CVSS scoring), and actionable remediation guidance for global engineering teams.

Military Police of Amazonas (PMAM) – Information Security Intern
Diretoria de Tecnologia da Informação - PMAM
Манаус, AM
Threat Monitoring & Triage: Conducted proactive security monitoring across government network infrastructure, analyzing alerts and attacker Tactics, Techniques, and Procedures (TTPs) to identify and escalate anomalous behavior. Log Analysis & Incident Response: Supported the Incident Response (IR) lifecycle by performing in-depth log analysis and telemetry review, assisting in the containment and mitigation of potential security events. Vulnerability Management: Executed vulnerability validation and triage, bridging the gap between automated scan outputs and actionable remediation strategies to systematically reduce the organizational attack surface. Security Awareness & Phishing: Assisted in the strategic design and execution of internal phishing simulation campaigns, evaluating employee threat awareness and helping to enforce a stronger human-layer security culture.

Brazilian Air Force – IT Technician (Military Service)
Манаус, AM
Network Architecture & Segmentation: Architected and deployed secure network topologies, enforcing rigorous network segmentation and defense-in-depth principles to protect critical military communications and restrict unauthorized lateral movement. Infrastructure Hardening: Executed comprehensive system hardening across server environments and endpoint workstations, mitigating known attack vectors and systematically reducing the internal attack surface. Secure Development & Maintenance: Developed, maintained, and secured internal military portals and operational systems (INTRAER), ensuring high availability, data integrity, and strict adherence to defense-grade security protocols. Identity & Access Management (IAM): Engineered and governed strict access control policies, rigorously enforcing the Principle of Least Privilege (PoLP) and Role-Based Access Control (RBAC) across sensitive operational networks.
Rafael Gomes's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.



