faleir0x

Cauê Faleiros

Offensive Security

I focus on offensive security, specifically web application and API penetration testing. My work involves uncovering vulnerabilities, from OWASP Top 10 to business-logic abuse, developing functional proofs of concept, and writing the code to fix them.

My approach is rooted in my background as a full-stack developer. Because I have hands-on experience building, deploying, and maintaining the systems I now test, including authentication controls, reverse proxies, and centralized logging, I know how these environments are structured in production. This builder's perspective allows me to spot architectural blind spots that automated tools miss and provide practical, dev-ready remediations.

Experience

Agência Compor

Full Stack Developer08/2026 → Present

I develop and maintain web applications using Node.js, TypeScript, and React, implementing secure authentication and strict access controls guided by OWASP. I manage the production infrastructure with Docker and CI/CD pipelines, centralizing log auditing with Loki and Grafana for rapid incident investigation.

Software Development Intern08/2025 → 07/2026

I built APIs and backend integrations using Node.js and Express, working directly on database modeling with PostgreSQL. I collaborated on bug fixing, code review, and analyzing operational failures to ensure the stability and security of internal services.

FMRP · USP

IT Infrastructure Intern07/2024 → 07/2025

I supported the operation of infrastructure services on Google Cloud Platform (GCP) and assisted with containerized environments using Docker. I utilized Zabbix and Grafana to track corporate network availability and monitor the stability of systems in real time.

Stack

Pentest
Burp Suite · Caido · OWASP ZAP · Nmap · ffuf · Gobuster · SQLmap · Nuclei · Nessus
Scripting
Python · Go · Bash · PowerShell · SQL
Infra
Docker · Grafana · Prometheus · Loki · CI/CD · GCP
Certs
eJPT (INE) — studying · PNPT (TCM Security) — planned