EDGAR
HUÉMAC

Penetration Tester & Cybersecurity Engineer

View Work ↓ Get in touch
6+Years in
cybersecurity
120+Engagements
conducted
1Purpose to
keep learning

Hello!

I'm a Computational Systems Engineer with deep expertise in cybersecurity, specially offensive security. I conduct full-scope pentests, red team engagements and vulnerability research across web, network, Active Directory, and cloud environments.

I follow industry methodologies including PTES, OSSTMM, OWASP, ISSAF, and NIST 800-115, and I have a strong background in security governance, compliance, and AppSec auditing (SAST, DAST, SCA). I try to stay up to date doing CTFs and trainings.

Beyond computers, I like reading, cycling, and tea culture. I play the piano sometimes. Started hiking in 2026. I'm fluent in english (TOEFL C1 ↗) and french (DELF B2 ↗), and beginner in japanese.

Say hello →

[ Work history ]

Experience

Offensive security engagements and cybersecurity engineering across multiple organizations. Click on each one to display the full details.

  • pentesting following PTES & NIST frameworks for web, APIs, cloud, infra & desktop.
  • application security (AppSec) assessments (SAST, DAST, & SCA).
  • evaluations for PCI, SOC2, HIPAA, & GDPR compliance standards.
  • risk assessment with CVSS scoring & technical remediation guidance.
  • secure design reviews & security training aligned with OWASP & SANS.
  • assessed and implemented security controls for AI-integrated systems.
  • web, API, and mobile penetration testing & cybersecurity audits.
  • technical reporting on identified risks & vulnerabilities.
  • mitigation strategies, post-assessment restest & validation
  • coordinated & led offensive security operations (red teaming & risk assessments)
  • web, application, and internal network engagement pentesting
  • technical & executive report generation & remediation guidance
  • design of methodologies & playbooks for security operations
  • internal teams training on security tools & TTPs
  • target prioritization in collaboration with IT & SecOps
  • design & creation of organizational security policies
  • front-end & back-end production web application maintenance & refactoring
  • feature implementation, bug fixing, & third-party API/service integration
  • incident triage, root cause analysis, & hotfix deployment
  • production release management & deployment pipeline execution>
  • modular React front-end application development within agile methodologies
  • technical requirement definition & microservice architecture design
  • Azure cloud architecture setup & containerized microservice deployment
  • CI/CD pipeline implementation & unit testing suite integration
  • full-stack software development & deployment across Linux & Active Directory envs
  • network & system architecture design & optimization
  • system monitoring, performance tuning, & security hardening
  • CI/CD pipeline implementation for web applications
  • B.S. in Computer Systems Engineering (GPA: 85.87 / 100)
  • specialization in Information Security
  • degree awarded via software development practicum for enterprise clients

[ Expertise ]

Skills & Tools

Offensive security methodologies, tooling, and engineering built across real-world engagements.

Offensive Security
Penetration Testing
PTESOSSTMMOWASP TGISSAFNIST 800-115Linux · AD · Web · Network · Cloud
Red Teaming
MITRE ATT&CKCyber Kill ChainTTP EmulationEDR/AV EvasionC2 Ops
AppSec & Code Review
SASTDASTIASTDevSecOpsSDLCOWASP Top 10Web/API/Mobile
Malware & Custom Tooling
C / C#PythonNIMShellcodePayload ObfuscationImplant Dev
Tooling
Recon, Scanning and OSINT
NmapMasscanRustScanNessusZAPNiktoWPScanMaltegoShodanAmassTheHarvesterspiderfootffufFeroxbuster
Exploitation and Post-Exploitation
MetasploitBurpSuiteSQLmapDalfoxXSStrikeCommixpwncatPwntoolsPEASS-ngSearchSploitCore Impact
Red Team · C2 · AD
Cobalt StrikeHavocSliverMythicMimikatzBloodHoundCrackMapExecImpacketevil-winrmCertipyKerbrute
Credentials · Network
HashcatJtRHydraCeWLWiresharktcpdumpAircrack-ngWifiteKismetScapy
Forensics · Social Eng.
AutopsyVolatilityBinwalkForemostGoPhishEvilginxHiddenEyeSocialFish
OS & Platforms
Kali LinuxParrotOSBlackArchDockerProxmoxVMwareActive Directory
Development & Scripting
Languages
Python ★★★JS ★★★NIM ★★★Bash ★★PowerShell ★★C/C++ ★★C# ★★PHP ★★Java ★★Lua ★
Web & Frameworks
Node.jsFastAPIDjangoFlaskReactVueLaravelBootstrapJQuery
Infrastructure & DB
DockerTerraformGitHub ActionsPostgreSQLMySQLSQLiteGitLab CI

[ My Work ]

Projects

Security tooling & personal projects I'm (maybe) proud of.
Note: I'm constantly updating this website & my Github projects. Sorry for any sync fault.


[ Writing ]

Blog

Thoughts on malware development, offensive security, and the industry, published on Medium.

See all posts on Medium →

[ Bragging section ]

Other Achievements

Trainings, certifications and courses completed across offensive security, cloud, governance, and engineering. Playing Pokemon as a kid got me an addiction to collecting digital badges; you can see mine on Credly ↗.


[ Let's connect ]

Get in touch

Whether you want to collaborate,
or just want to say hi, my inbox is open.

huemac.contact@gmail.com