João Mendes

João Mendes

About

Detail

Senior Security Engineer
São Paulo, State of São Paulo, Brazil

Contact João regarding: 
work
Full-time jobs

Timeline


work
Job
school
Education

Résumé


Jobs verified_user 0% verified
  • Nortal
    Senior DevSecOps
    Nortal
    Sep 2025 - Current (1 year 1 month)
    Designed and maintained Infrastructure as Code (IaC) using Terraform across AWS and Azure environments.

    Developed and implemented Policy-as-Code solutions using Open Policy Agent (OPA) to enforce governance, security, and compliance.

    Automated infrastructure provisioning, configuration management, and operational tasks using Ansible.

    Supported and maintained Kubernetes clusters, including application deployments, troubleshooting, and platform operations.

    Built and improved CI/CD pipelines, integrating DevOps and DevSecOps best practices.

    Implemented cloud security controls, infrastructure validation, and automated compliance checks.

    Collaborated with development, operat
  • Getnet
    Senior Application Security Engineer
    Getnet
    Oct 2020 - Sep 2025 (5 years)
    Senior Application Security Engineer

    Partnered with development teams throughout the entire Secure Software Development Lifecycle (SSDLC), from design to production.
    Performed Web and API Penetration Testing following the OWASP Testing Guide.
    Conducted Mobile Application Security Assessments for Android and iOS applications.
    Led Threat Modeling sessions using industry-standard methodologies (e.g., STRIDE).
    Designed and supported the Security Champions Program, promoting security awareness and secure development practices.
    Integrated and managed SAST, DAST, and Software Composition Analysis (SCA) within CI/CD pipelines.
    Provided Product Security guidance, including secure architecture reviews, vulnera
  • Stone
    Application Security Engineer
    Stone
    Jan 2017 - Sep 2020 (3 years 9 months)
    Application Security Engineer

    Partnered with development teams throughout the Secure Software Development Lifecycle (SSDLC), from design to production.

    Performed Web, API, and Mobile (Android/iOS) penetration testing.

    Conducted threat modeling sessions to identify and mitigate security risks early in the development lifecycle.

    Led and supported the Security Champions Program to promote secure development practices.

    Integrated SAST, DAST, and SCA into CI/CD pipelines, enabling automated security testing.

    Provided Product Security guidance through architecture reviews, vulnerability management, and remediation support.

    Collaborated with engineering teams to imp
  • C
    DevOps Engineer
    CM Capital
    Mar 2015 - Dec 2016 (1 year 10 months)
    Designed, implemented, and maintained CI/CD pipelines using GitHub Actions, Azure DevOps, and cloud-native services.
    Provisioned and managed cloud infrastructure across AWS and Azure using Terraform and Infrastructure as Code (IaC).
    Administered Kubernetes clusters, supporting application deployments, scaling, upgrades, and troubleshooting.
    Automated infrastructure provisioning and configuration management with Ansible and scripting.
    Implemented monitoring and logging solutions to improve system reliability and observability.
    Optimized deployment processes, reducing manual effort and increasing delivery efficiency.
    Collaborated with development and security teams to improve platform reliability, automate
Education verified_user 0% verified
  • Senac São Paulo
    Bachelor of Technology - BTech, Systems Analysis
    Senac São Paulo
    Jan 2015 - Jan 2018 (3 years 1 month)