Rafael Bosch
@rafaelbosch
CRTE/CRTP-certified red team operator delivering CVE-driven enterprise security improvements.
What I'm looking for
I’m a CRTE/CRTP-certified Red Team operator focused on offensive security that leads to measurable risk reduction. I’ve authored 3 published CVEs and documented enhanced security posture through exploits on Exploit-DB.
In my roles, I execute large-scale penetration testing and adversarial simulations mapped to MITRE ATT&CK TTPs. I’ve run 10 adversarial simulations to drive outcomes like domain compromise, credential harvesting, and EDR bypass across multiple kill chain phases.
I bring hands-on experience across web, mobile, wireless, and infrastructure environments—penetrating targets beyond one layer of the attack surface. I’ve executed 300+ penetration tests, covering OWASP Top 10, and I’ve supported enterprise remediation by reporting and guiding cross-functional teams.
I also contribute to malware research and security tooling. I’ve reverse-engineered macOS malware, developed detection logic (including Yara rules), and improved internal threat detection through adversary simulations—pairing operational findings with training and Secure Development Lifecycle (SDLC) discipline.
Experience
Work history, roles, and key accomplishments
Offensive Security Team Lead
Samsung SDS
Aug 2025 - Present (10 months)
Conducted penetration testing for Samsung Electronics applications and led Red Team operations, presenting findings and remediation guidance. Authored 3 CVEs and supported cloud security automation using AWS and SCP.
Senior Penetration Tester
Samsung SDS
Jan 2024 - Aug 2025 (1 year 7 months)
Executed 100+ Web/API and infrastructure security assessments, triaging critical issues and reducing the enterprise attack surface. Led Red Team engagements with domain admin compromise in 85% of assessments and achieved EDR evasion; identified auth flaws aligned to PCI DSS.
Application Security Engineer
Claro Brasil
Jan 2023 - Jan 2024 (1 year)
Improved security threat detection by applying 60+ CI/CD application manual reviews and authoring custom security rules. Validated remediation using SAST/DAST findings and helped integrate regex-based detection patterns into the CI/CD pipeline.
Offensive Security Engineer
Ernesto Borges Advogados
Jul 2022 - Jan 2024 (1 year 6 months)
Performed advanced infrastructure penetration testing and security assessments for web extensions and RPA systems. Conducted Red Team operations including WPA2-Enterprise and Evil Twin wireless assessments, delivering executive reports and remediation guidance while reducing cloud assessment overhead by 40%.
Malware Researcher
Mosyle
Jan 2022 - Jun 2022 (5 months)
Reverse-engineered macOS malware and produced documented malicious indicators and behavioral fingerprints. Developed YARA rules and conducted threat intelligence research to identify emerging macOS malware and malicious groups.
Penetration Tester
IBLISS Digital Security
Oct 2021 - Apr 2022 (6 months)
Performed mobile penetration testing and Red Team operations across client sectors. Improved assessment kickoff and delivery practices while strengthening penetration testing methods.
Penetration Tester
Tripla
Jul 2021 - Oct 2021 (3 months)
Conducted web/API, mobile, and infrastructure security assessments for clients and delivered detailed reports. Guided clients through findings and recommendations to support complete understanding of security vulnerabilities and mitigations.
Education
Degrees, certifications, and relevant coursework
FIAP - Paulista Faculty of Informatics and Administration
Master of Business Administration (MBA), Cybersecurity & Governance
2026 - 2027
Completed an MBA in Cybersecurity & Governance at FIAP (remote) from 2026 to 2027.
IPOG - Postgraduate and Undergraduate Institute
Postgraduate Degree, Cyber/Computer Forensics and Counterterrorism
2024 - 2025
Completed a postgraduate degree in Cyber/Computer Forensics and Counterterrorism from 2024 to 2025.
IDESP - Daryus Institute of Higher Education
Postgraduate Degree, CyberThreat Intelligence (CTI)
2024 - 2025
Completed a postgraduate degree in CyberThreat Intelligence (CTI) from 2024 to 2025.
FIAP - Paulista Faculty of Informatics and Administration
Degree, Cybernetic Defense
2021 - 2023
Completed a degree in Cybernetic Defense at FIAP from 2021 to 2023.
Availability
Location
Authorized to work in
Website
saravejo.comPortfolio
github.com/saravejoJob categories
Interested in hiring Rafael?
You can contact Rafael and 90k+ other talented remote workers on Himalayas.
Message RafaelFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
