Sebastian Oros

Product Manager

Buenos Aires, Buenos Aires Province, Argentina3 yrs 4 mos experience

Key Highlights

  • Expert in web and mobile penetration testing.
  • Strong background in application security practices.
  • Passionate about continuous learning and offensive security.
Stackforce AI infers this person is a Cybersecurity Specialist with a focus on Application Security and Vulnerability Assessment.

Contact

Skills

Core Skills

Application SecurityVulnerability AssessmentRisk Analysis

Other Skills

Identifying vulnerabilitiesDeveloping custom toolsSecurity assessmentsCollaborating with engineering teamsVulnerability assessmentsIncident responseDevelopment of security policiesNetwork troubleshootingIncident reportingopen source intelligencedigital forensicsdark web operationsISO 27001NIST 800-53PCI DSS

About

Application Security Engineer and Offensive Security Specialist with hands-on experience in web and mobile penetration testing, vulnerability research, and application security practices. I work identifying security flaws across web applications, APIs, and mobile environments, combining manual testing techniques with source code analysis in technologies such as Java, JavaScript, Python, and Go. While secure code review is an area I continuously strengthen, I already apply it in real-world assessments to better understand root causes and support effective remediation. With a background in network engineering, I approach security from a full-stack perspective — understanding how infrastructure, authentication mechanisms, business logic, and application layers interact within the attack surface.I have collaborated with development teams to communicate findings clearly and contribute to practical remediation strategies aligned with secure development practices. Passionate about offensive security, and continuous learning. Actively involved in CTF competitions, security research, and technical training in application security. Certs: BSCP, CAPenX, PWPE, PNPT, C-APIPen, C-AI/MLPen, API-RTA, CSCR, CASP Pentesterlab: Code review (PHP, Java, Js/Ts, Python, Ruby, Go)

Experience

3 yrs 4 mos
Total Experience
9 mos
Average Tenure
--
Current Experience

Hawks security academy

Web Application Security Trainer

Dec 2025Present · 5 mos · San Jose, Costa Rica · Remote

  • Educational content creator focused on web application security.

Hackerone

Bug Hunter

Nov 2025Present · 6 mos · Remote

  • Performing web vulnerability assessments on web apps of different programs / companies

Fluid attacks

Application Security Engineer

Jul 2025Oct 2025 · 3 mos · Antioquia, Colombia · Remote

  • Identifying complex, non-trivial, and high-impact vulnerabilities across web, and source code environments with different technologies (Java, JavaScript, Python)
  • Develop and use custom tools and scripts to support in-depth security assessments, and I integrate security testing directly into the SDLC
  • Collaborate closely with engineering teams and clients (in both English and Spanish) to ensure vulnerabilities are clearly communicated and remediated effectively, often advising on secure development practices.
Identifying vulnerabilitiesDeveloping custom toolsSecurity assessmentsCollaborating with engineering teamsApplication SecurityVulnerability Assessment

Banco ganadero s.a.

Cybersecurity Analyst

Nov 2023Jul 2025 · 1 yr 8 mos · Santa Cruz de la Sierra, Santa Cruz, Bolivia · On-site

  • Risk Analisis
  • Vulnerability assessments (App web/mobile, network)
  • Working with development team to improve code security
  • Working with infraestructure team to mitigate security risks
  • Incident response for cyber threats
  • Optimitation tasks
  • Development of security policies
Risk AnalysisVulnerability assessmentsIncident responseDevelopment of security policiesVulnerability Assessment

Millicom (tigo)

Network Operations Center Engineer

Jul 2023Oct 2023 · 3 mos · Santa Cruz, Bolivia · Hybrid

  • Monitoring and Troubleshooting CORE Devices
  • Reporting and keep record all incidents by Support Tickets

Logicalis latam

Technical Support Engineer L1/L2

Apr 2022Jun 2023 · 1 yr 2 mos · Santa Cruz de la Sierra, Santa Cruz, Bolivia

  • Post Sales Analyst in service of Tigo Business NOC Corporate
Network troubleshootingIncident reporting

Education

UAGRM School of Engineering

Diplomatura — Seguridad informática

May 2022Nov 2022

Universidad Autónoma Gabriel René Moreno

Network and Telecommunications Engineering

Jan 2015Jan 2021

CBA SANTA CRUZ - CENTRO BOLIVIANO AMERICANO

English as Foreign Language

Jan 2017Jan 2020

Stackforce found 100+ more professionals with Application Security & Vulnerability Assessment

Explore similar profiles based on matching skills and experience