Matías Schiappacasse

Self-taught pentester focused on web application security.

Penetration Tester, Chile

Matías Schiappacasse

About

Cybersecurity Specialist with experience in web, mobile, and internal network penetration testing. I have led and executed security assessments, as well as participated in security research. I am experienced in various security frameworks and penetration testing methodologies.

Work Experience

NIVEL4 CybersecurityRemote
April 2024 — Present
Cybersecurity Specialist
  • Conducted comprehensive web application and internal network penetration tests leveraging industry-standard methodologies (OWASP, WSTG) to effectively identify, validate, and prioritize security vulnerabilities.
  • Analyzed and categorized security findings using established frameworks and scoring systems (CWE, CVSS), facilitating accurate risk assessment and informed decision-making for both technical and business stakeholders.
  • Authored and presented detailed technical vulnerability reports with clear, actionable mitigation recommendations, actively supporting teams throughout the remediation lifecycle.
  • Led security assessment teams of up to three penetration testers, coordinating task delegation, defining engagement scopes, and ensuring the precise execution of ethical hacking activities.
  • Contributed to the security research team by conducting public and private research focused on the identification and in-depth analysis of vulnerabilities across applications, services, and software components.
NIVEL4 CybersecurityRemote
September 2023 — May 2024
Pentester
  • Performed penetration testing and ethical hacking engagements targeting web and mobile applications, internal networks, and ad-hoc wireless environments, identifying security weaknesses from a realistic, threat-actor perspective.
  • Leveraged industry-standard security methodologies (e.g., OWASP) to uncover technical and business logic vulnerabilities, documenting findings systematically and providing practical, actionable remediation guidance to facilitate risk mitigation by development and security teams.

Certifications

OffSec Web Assessor (OSWA)
2026
OffSec
Web Application Penetration Tester eXtreme (eWPTXv3)
2025
INE Security
Web Application Penetration Tester (eWPTv2)
2025
INE Security
Practical Web Pentest Associate (PWPA)
2024
TCM Security
Junior Penetration Tester (eJPTv1)
2022
INE Security

Skills

Penetration Testing / Ethical HackingBurp SuiteNmapNetExecOWASP Top 10 / OWASP API Security Top 10 / WSTGAPI Security TestingGobusterCVSS 3.1 & 4.0CWEMetasploitNessus / AcunetixPrivilege Escalation / Pivoting / Lateral MovementKali LinuxVulnerability ManagementHTTPTCP/IPWiresharkPython3Bash Scripting

Projects & Publications

© 2026 T3slaChile