Skip to content
HENDRICH

Arthur Hendrich · Senior Cyber Security Analyst

ABOUT

I find the paths defenders miss, then I write them down.

This is my blog. I am a senior cyber security analyst at Accenture, working in offensive security and red teaming. Most of what lands here starts as a note during a lab or a real engagement and grows into an article worth keeping.

Placeholder portrait slot, an atmospheric security photograph shown until a real photo is added.
Fig. A
Offensive security · Red teamPortrait · placeholder to swap

Field notes

The work

My days run on real engagements: reconnaissance, exploitation, lateral movement, and the long game of staying quiet inside a network. The interesting part is rarely a single exploit. It is how small findings chain into a full path to impact.

The blog

This site is my blog. I publish articles here, writeups of machines from Hack The Box and Proving Grounds, study notes on techniques I want to remember, and lessons that carried over from client work. Each article stays plain and practical.

Tooling

When a workflow gets repetitive, I build for it. AstraRecon is one of those tools, a reconnaissance helper that takes the slow, manual part of an assessment and makes it fast and repeatable, so the time goes into analysis instead of setup.

EXPERIENCE

3 roles
  1. Red TeamCurrent
    May 2025 to Present

    Senior Cyber Security Analyst · Accenture

    Remote, USA

    • Run red team and adversary emulation on major cloud and multinational engagements, coordinating across the full attack lifecycle and aligning objectives with client stakeholders and executive sponsors.
    • Run continuous penetration testing and adversary emulation on large scale cloud native environments for a major global cloud provider, strengthening detection and hardening critical services.
    • Build custom malware and offensive tooling for red team initiatives, enabling realistic simulations of advanced threat actors and improving EDR and XDR coverage.
    • Test iOS and Android applications, and probe LLM and machine learning models for prompt handling, access control, data exposure and weaknesses in AI integrated workflows.
    • Red Team
    • Cloud
    • Adversary Emulation
    • Malware Dev
    • Mobile
    • AI/LLM
  2. AppSec / DevSecOps
    Nov 2024 to May 2025

    Senior Application Security Analyst · Hurb

    Remote, Brazil

    • Owned the application security and DevSecOps program end to end, driving vulnerability remediation across engineering squads alongside the DevOps and FinOps teams.
    • Shifted security left across the software development lifecycle, wiring SCA, SAST, DAST and RASP into GitHub pipelines with SonarQube, Semgrep, Trivy, Snyk, Tenable, SentinelOne and GitGuardian.
    • Delivered controls against card skimming, supported PCI DSS 4.0 audit preparation, and built Attack Surface Management to reduce exposure.
    • DevSecOps
    • AppSec
    • SAST/DAST
    • SCA
    • RASP
    • PCI DSS
  3. Secure Development
    Aug 2022 to Nov 2024

    Information Security Analyst · Facilit Tecnologia

    Remote, Brazil

    • Enabled secure development across engineering and QA, establishing secure GitHub workflows, code review standards and automated security testing.
    • Ran SAST and DAST with Fortify, remediating vulnerabilities before release.
    • DevSecOps
    • Secure SDLC
    • Fortify
    • GitHub

CERTIFICATIONS

9 held · 3 OffSec

OffSec track

  • OSEP2026

    Offensive Security Experienced Pentester

    OffSec

  • OSWE2026

    Offensive Security Web Expert

    OffSec

  • OSCP+2026

    Offensive Security Certified Professional Plus

    OffSec

Also certified

  • eMAPTv32026

    Mobile Application Penetration Tester

    eLearnSecurity

  • CRTP2025

    Certified Red Team Professional

    Altered Security

  • eWPTX2024

    Web Application Pentester eXtreme

    eLearnSecurity

  • CEH2024

    Certified Ethical Hacker, Practical

    EC Council

  • eCPPTv22024

    Certified Professional Penetration Tester

    eLearnSecurity

  • DCPT2023

    Desec Certified Penetration Tester

    Desec Security

EDUCATION

Recife, Brazil

Cesar School

Recife, Brazil

  • Master's in Software Engineering2026 to Present
  • Bachelor's in Computer Science2022 to 2025

CONTACT

Find me

If an article here helps your work, that is the point.

Grab the CV, or reach out on any of these. The quickest replies come by email.