Seguridad desde el código y pentesting de infraestructura, APIs y aplicaciones web
- Protagonista: Juan Rodríguez Monti
- Año: 2025
- País: Argentina
- Género: Terror
- Track: Development
- Idioma: Español
Esta charla introduce a devs, DevOps y perfiles relevantes como managers a los fundamentos del pentesting y la protección de servidores y APIs. Explica qué es el pentesting en entornos cloud y web, su importancia, todo ilustrado con ejemplos. Cubre vulnerabilidades comunes en APIs como inyección, autenticación rota, OWASP10, exposición de datos en servidores Linux. También se analizan situaciones con reverse proxies como Nginx, manejo de puertos, hardenización de SSH, y se proponen soluciones ágiles que puedan ser implementadas de la forma más eficiente posible. Introduce herramientas como nmap, nikto, sqlmap y Burp Suite, entre muchas otras, con demos en vivo. Ofrece prácticas de mitigación: validación de entradas, HTTPS, control de ataques y escaneos en CI/CD. Enfocado en que la seguridad comienza desde el desarrollo y termina en producción, con demos prácticas y casos reales, una charla que puede servir a desarrolladores, ingenieros cloud, y mánagers interesados en aspectos técnicos.
Sobre Juan Rodríguez Monti
Hello, I am Juan! I am an experienced Backend Developer with over 20 years of industry experience. I have a broad profile that covers backend and frontend Software Development, Devops and Cloud, Team management, Security and Compliance, besides and strong Academic profile with Data Structures and Computer Sciences. My technical skillset includes expertise in a wide range of languages and frameworks like Go, Rust, Python, Flask, FastAPI, TypeScript, React, Next.js, Node.js, PHP, C. Also, I have an strong experience with Linux, Terraform, AWS, Google Cloud, Bash, SQL and No-SQL databases, Redis, Rabbit-MQ, Apache Kafka, Airflow, etc. I have experience in managing Agile teams and am proficient in the utilization of Amazon Web Services, Google Cloud Platform, and Microsoft Azure, Docker, Kubernetes, Lambdas, among others. Rust is another technology that I have been working on in my latest projects in 2023. Also, I´ve been working in recent projects with big-data and Machine Learning projects. My expertise extends to multiple architectural patterns, ranging from monolithic, microservices, and cloud-based architectures, to more complex and advanced structures. I have used many platforms and SaaS and PaaS, as well as containerization and orchestration tools such as Docker and Kubernetes, in conjunction with serverless deployment strategies using Cloud Providers like AWS and Vercel. As an Assistant Professor of Data Structures and Computer Sciences at the University since 2018, I have had the opportunity to share my knowledge and experience with the next generation of software developers and engineers. My experience in managing remote and onsite teams and implementing best practices in software development is well-documented, and I am committed to ensuring that all projects under my purview are executed with the highest standards of security and quality. Furthermore, my communication and leadership skills are strong, and I have successfully led cross-functional teams. I am adaptable to different project requirements and have experience working in both Agile and Waterfall methodologies. I am confident that I can lead and inspire team members to achieve project goals and drive business success. In conclusion, I possess extensive experience in a variety of technologies, methodologies, and industry sectors. I am excited to leverage my skills and experience to take on new challenges and contribute to the success of the projects I become a part of.
🇨🇱 Charlas de Nerdearla Chile 2026 que te van a interesar
Llega la tercera edición de Nerdearla en Chile. 16 al 18 de abril en Santiago.
Asegura tu lugarCharlas de ediciones anteriores