Eduardo Gadotti
I am a Cybersecurity Manager who delivers business value through information security. I have more than 20 years of experience in technology, and the last several years have been fully dedicated to leadership in corporate environments. My background combines a foundation in software development and systems analysis with a strategic, offensive view of security, which lets me work both on identifying vulnerabilities and on building robust protection programs.
In my management roles, I have led ISO 27001 certification processes and audits, built compliance and governance teams, and served as a direct interface with clients and vendors, translating technical security requirements into clear agreements and shared understanding for many different kinds of stakeholders.
I place a strong emphasis on leading people, building and developing security teams through clear performance expectations and structured feedback. I have end-to-end capacity planning experience, forecasting hiring needs and ensuring adequate coverage across corporate and production security domains. I lead through clarity of intent, not micromanagement. I also run performance cycles end to end, including goal setting (OKRs, KPIs, etc.), in line with organizational expectations.
Much of my work is in Application Security and offensive security, with hands-on experience in pentesting, vulnerability analysis, and secure development based on frameworks such as OWASP. I believe security starts in the code and is cemented in the culture, and that intersection is where I focus my energy.
I actively evaluate the impact of AI tools on the development and security ecosystem, weighing their risks and possibilities and integrating them responsibly into environments that demand security maturity.
So long, and thanks for all the fish!