
Magno Rodrigues de Oliveira
Verified Expert in Engineering
Security Engineer and Developer
Ottawa, Canada
Toptal member since July 14, 2026
Magno is a staff product security engineer with over 15 years of experience in offensive security, secure development, and developer enablement for clients such as Jane Software, Okta, and Trend Micro. His primary expertise is in penetration testing, DevSecOps, and cloud and container security for technology and financial industries, where Magno thrives in cross-functional engineering environments. He engineered org-wide AI security guardrails and automated secure code review while at Jane.
Portfolio
Experience
- Incident Response - 15 years
- Threat Modeling - 15 years
- Penetration Testing - 15 years
- Vulnerability Management - 15 years
- Secure Coding - 10 years
- DevSecOps - 10 years
- Cloud Security - 5 years
- AI Security - 3 years
Preferred Environment
AI Security, Cloud Security, Container Security, DevSecOps, Incident Response, OWASP, Penetration Testing, SCA, Secure Coding
The most amazing...
...vulnerability feed testing pipeline I've automated for a container security tool reduced test time for container vulnerabilities from days to minutes.
Work Experience
Staff Product Security Engineer
Jane Software
- Led the secure adoption of AI and agentic developer tooling across the organization, engineered org-wide Claude Code guardrails that block secret leakage and dangerous commands, and authored security automation Cursor rules and Claude skills.
- Performed security code reviews, design reviews, and assessments of web applications and APIs, identifying vulnerabilities and articulating their business impact to drive remediation prioritization.
- Led security architecture and design reviews for large, business-critical projects, partnering with engineering and product to design and ship secure features.
- Helped engineering teams deploy and operate SAST, DAST, and SCA tooling and triage findings into actionable fixes.
- Ran the security champions program and delivered monthly technical learning sessions and internal CTFs, building a culture of collaborative security across engineering.
Staff Product Security Engineer
Okta
- Built and delivered technical security training (secure coding, DevSecOps, container, and Kubernetes security) for engineering teams as part of the product security team.
- Led a security champions program of nearly 100 participants, guiding security tool deployment and the remediation of vulnerabilities.
- Performed security code reviews and assessments of web applications and APIs, and helped teams deploy and triage SAST, DAST, and SCA tooling.
- Organized company-wide CTFs and monthly learning sessions on technical security topics.
Information Security Specialist and Senior Threat Researcher
Trend Micro
- Researched cloud, container, and Kubernetes security, cloud-native, and open-source software supply-chain security, and DevSecOps.
- Built threat models, proof-of-concept exploits, honeypots, and threat-hunting capabilities to surface and demonstrate real-world risk.
- Automated the container vulnerability-feed testing pipeline in Python, cutting test cycles from hours to minutes.
- Contributed runtime protection capabilities to the container security product.
- Designed and ran red team and blue team exercises for the entire engineering organization.
Information Security Specialist and Team Lead
SkipTheDishes
- Led penetration testing across all major web applications and APIs.
- Led the security team, the PCI-DSS compliance program, and DevSecOps adoption across the development pipeline.
- Ran incident response and monitoring using Splunk and a WAF.
- Deployed software composition analysis (Sonatype Nexus IQ) for dependency and vulnerability scanning of 3rd-party libraries.
- Managed vulnerability scanning and remediation for PCI, container, and cloud environments (Tenable.io, Rapid7 InsightVM), and delivered recurring secure coding training on the OWASP Top 10 Proactive Controls.
Application Security Specialist and Consultant
Dasa
- Delivered web and network application security testing and secure code reviews as a consultant.
- Ran vulnerability scanning using Nessus and performed vulnerability management.
- Created application security and secure coding training based on OWASP.
Application Security Specialist and Lead Pentester
TecBan - Tecnologia Bancária
- Discovered and exploited vulnerabilities in enterprise products from SAP, Oracle, IBM, Microsoft SharePoint, and Segura, building working exploits to demonstrate business impact and reporting them through responsible disclosure.
- Led the penetration testing team and DevSecOps adoption across the development pipeline.
- Performed network and application penetration testing across all systems, including the Banco24Horas transactional ATM network.
- Managed and protected external web applications with a WAF (F5 BigIP ASM).
- Performed security code review and application security auditing.
Experience
JampaSec
https://jampasec.wordpress.com/OWASP João Pessoa Chapter
https://owasp.org/www-chapter-joao-pessoa/Claude Skills - Code Review and Threat Modeling
Awesome Kubernetes (K8s) Security
https://github.com/magnologan/awesome-k8s-securityAwesome SCA List
https://github.com/magnologan/awesome-scaThe following repo contains a collection of SCA tools that can be used to analyze risks in third-party components used in the code.
Kubernetes Security Research
https://www.trendmicro.com/vinfo/us/security/news/virtualization-and-cloud/the-basics-of-keeping-your-kubernetes-cluster-secure-part-1Trend Micro
Trend Micro
TeamTNT Targets Kubernetes, Nearly 50,000 IPs Compromised in Worm-like Attack — May 2021, with David Fiser.
The Fault in Our Kubelets — May 2022. Found over 243,000 publicly exposed Kubernetes clusters via Shodan, many with the kubelet port open.
Trend Micro
A Deep Dive Into Kubernetes Threat Modeling
Understanding the Kubernetes Security Triad: Image Scanning, Admission Controllers, and Runtime Security — Nov 2023.
Mitigating the Threat of Sidecar Container Injection — Apr 2024.
How to Secure Your Kubernetes Cluster — Cloud Native Now, Oct 2020.
GitHub Actions Security Research
https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/github-action-runners-analyzing-the-environment-and-security-in-actionUnpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines — Trend Micro Research, 2022.
Abusing a GitHub Codespaces Feature For Malware Delivery — Jan 2023, with Nitesh Surana. Examines how sharing forwarded ports publicly in GitHub Codespaces could be abused to stand up a malware file server on a legitimate account. Codespaces rather than Actions specifically, but closely adjacent
Education
Master of Business Administration (MBA) in Information Security
Faculdade De Tecnologia De João Pessoa - Brazil
Bachelor's Degree in Information Technology
Instituto Federal Da Paraíba - Brazil
Associate of Arts and Sciences Degree in Computer Forensics
Tompkins Cortland Community College - Dryden, NY, USA
Certifications
EC-Council ECDE (Certified DevSecOps Engineer)
EC-Council
AWS Certified Cloud Practitioner
AWS
AWS Certified Solutions Architect
AWS
Microsoft Azure Fundamentals
Microsoft
GIAC GCSA (Cloud Security Automation)
GIAC
CompTIA PenTest+
CompTIA
CompTIA CySA+
CompTIA
EXIN Ethical Hacking Foundation
EXIN
CompTIA Cloud Essentials
CompTIA
EXIN Secure Programming Foundation
EXIN
CompTIA Security+
CompTIA
Skills
Libraries/APIs
React
Tools
Claude Code, Claude, Splunk, Nessus, Jira, Metasploit, OWASP Zed Attack Proxy (ZAP), Docker Hub, Docker Compose, Docker Swarm, Kubernetes Operators, Amazon EKS, Jenkins, Azure Kubernetes Service (AKS), GitHub, Amazon CloudWatch, AWS CloudTrail, Google Kubernetes Engine (GKE)
Paradigms
Penetration Testing, DevSecOps, Agile Software Development, Automation, Security Orchestration, Automation, and Response (SOAR)
Industry Expertise
Cybersecurity, Healthcare, Insurance
Languages
Python, TypeScript
Platforms
Imperva Incapsula, AWS IoT, Kubernetes, Docker, Burp Suite, Azure, Amazon EC2, Amazon Web Services (AWS), AWS Lambda
Storage
Docker Cloud, PostgreSQL
Other
Threat Modeling, Vulnerability Management, Incident Response, Ethical Hacking, IT Security, Web Applications, Security, SOC 2, Certified Ethical Hacker (CEH), MITRE ATT&CK, Endpoint Security, Artificial Intelligence (AI), Cursor AI, AI Security, Cloud Security, Container Security, Kubernetes Security, PHI, Compliance, Large Language Models (LLMs), SIEM, NIST, AI Agents, Agentic AI, Prompt Injection, APIs, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), SCA, Secure Coding, Web Application Firewall (WAF), OWASP, Information Security, GitHub Actions, Secure Containers, Computer Forensics, Docker Security, OWASP Top 10, Self-managed Kubernetes, GitHub Actions Security, Open Source, Open Source Security, JFrog, Software Composition Analysis (SCA), Snyk, Dependabot, Veracode, Black Duck, Renovate, Semgrep, Pipelines, CI/CD Pipelines, CI/CD Security, Supply Chain, Supply Chain Security, Software Supply Chain, Security Architecture, SOC Compliance, Relational Database Services (RDS), Amazon RDS, ISO 27001, Detection Engineering, Incident Handling, Incident Management, Containers, Rancher Kubernetes Engine (RKE), Cloud Native Computing Foundation (CNCF), PCI, PCI DSS, Security Incident Triage, ISO/IEC 27017, ISO/IEC 27018, HIPAA, Application Security, Vulnerability Assessment, Security Engineering, Security Policies & Procedures, Documentation, Policies & Procedures Compliance, Security Policy Analysis, Application Security Posture Management (ASPM), AI Trust, Risk and Security Management (AI TRiSM)
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring