My name is Sérgio Charruadas aka itzv3nom- and I'm a cybersecurity professional with Web & API, Mobile (Android), Network and AD Exploitation as core focus, currently working as a Training Developer at Hack The Box. Transitioned from a decade-long career in hospitality into the cybersecurity field, bringing a strong customer-centric mindset and a unique perspective to technical problem-solving.
With hands of experience as an Offensive Security Operator/Penetration Tester, doing security consulting across multiple industries. My efforts directly supported enhancing clients’ security postures by identifying and providing recommendations regarding mitigations in various environments.
I hold several respected certifications from GIAC, HTB, OffSec, PortSwigger, and other industry-leading organizations. Actively contributed to the cybersecurity community by participating in - and speaking at - Hack The Box meetups in Portugal, helping foster local engagement and learning.
| Area | Skills & Tools |
|---|---|
| 🔓 Web & API Pentesting | Identifying OWASP Top 10 vulnerabilities, analyzing API logic flaws, performing authentication and authorization bypass tests |
| 📱 Android Pentesting | Assessing mobile app security, reviewing APKs for insecure storage, analyzing traffic with Burp Suite/Frida, testing for root/jailbreak detection bypass |
| 🧱 Active Directory Security Assessments | Performing comprehensive AD security reviews, evaluating privilege escalation paths, identifying misconfigurations, and assessing domain hardening effectiveness |
| 🌐 Network Security Assessments | Conducting network reconnaissance and vulnerability assessments, evaluating segmentation controls, identifying exposure risks, and validating remediation effectiveness |
| 🧾 Reporting & Client Support | Delivering clear, actionable reports that guide clients in strengthening their security posture, prioritizing risks, and implementing effective remediation strategies aligned with best practices |
Offensive Security
- CPTS – Hack The Box, Certified Penetration Testing Specialist
- CWES - Hack The Box, Certified Web Exploitation Specialist
- ASCP – APISec University, API Security Certified Professional
- CAPenX - SecOps Group, Certified AppSec Pentesting eXpert
- OSCP - OffSec, Offsec Certified Professional
Defensive
- BTL1 – Security Blue Team, Blue Team Level 1
- SAL1 – TryHackMe, Security Analyst Level 1
Other Notable
- GSEC – SANS GIAC, Security Essentials
- GFACT – SANS GIAC, Foundational Cybersecurity
- SY0-601 – CompTIA, Security+
- CLF-C02 – AWS, AWS Cloud Practitioner
- CRTA – CyberWarFare Labs, Certified Red Team Analyst
- AD-RTS – CyberWarFare Labs, Active Directory Red Team Specialist
- MCRTA – CyberWarFare Labs, Multi-Cloud Red Team Analyst
- C-APIPen - SecOps Group, Certified API Pentester
- CNPen – SecOps Group, Certified Network Pentester
- CAPen – SecOps Group, Certified AppSec Pentester

