Penetration Tester & Cybersecurity Engineer
[ About me ]
I'm a Computational Systems Engineer with deep expertise in cybersecurity, specially offensive security. I conduct full-scope pentests, red team engagements and vulnerability research across web, network, Active Directory, and cloud environments.
I follow industry methodologies including PTES, OSSTMM, OWASP, ISSAF, and NIST 800-115, and I have a strong background in security governance, compliance, and AppSec auditing (SAST, DAST, SCA). I try to stay up to date doing CTFs and trainings.
Beyond computers, I like reading, cycling, and tea culture. I play the piano sometimes. Started hiking in 2026. I'm fluent in english (TOEFL C1 ↗) and french (DELF B2 ↗), and beginner in japanese.
[ Work history ]
Offensive security engagements and cybersecurity engineering across multiple organizations. Click on each one to display the full details.
End-to-end pentests (PTES/NIST) and SAST, DAST & SCA assessments for PCI, SOC2, HIPAA and GDPR compliance across infra, web, APIs, cloud, and desktop; manual exploitation and custom vuln discovery on critical business logic, with risk rating (CVSS) and technical remediation. Deliver secure design reviews & stakeholder training aligned to OWASP/SANS. Assess and implement security controls for AI-integrated systems.
Conducting full cybersecurity audits and penetration testing for web, API, and mobile applications, and elaborating technical reports on the identified vulnerabilities, and their mitigation techniques.
Led offensive security ops (pentest, vuln assessments, red teaming), coordinating a team and executing web/app/network engagements; performed recon, exploitation, and post-exploitation, producing technical reports and remediation guidance. Defined testing methodologies/playbooks, collaborated with IT/SecOps for target prioritization, and trained team on tools/TTPs.
Maintained and refactored production web apps (FE/BE), implemented features/bug fixes, and integrated services/APIs; collaborated via Agile workflows, handling incident triage, deployments, and stakeholder-driven requirements.
Built modular frontend apps in React (SCRUM), defined requirements, and designed microservices-based deployments (Elixir/React) on Azure; implemented CI/CD and unit testing.
Managed Linux/Windows (AD), designed network & system architectures, and implemented CI/CD for web apps & infrastructure; drove monitoring, performance, and security improvements.
Student of Engineering in Computer Systems and specialty in Information Security at the Technological Institute of Mexico, Morelia campus.
[ Expertise ]
Offensive security methodologies, tooling, and engineering built across real-world engagements.
[ My Work ]
Security tooling & personal projects I'm (maybe) proud of.
Note: I'm constantly updating this website & my Github projects. Sorry for any sync fault.
[ Writing ]
Thoughts on malware development, offensive security, and the industry, published on Medium.
[ Bragging section ]
Trainings, certifications and courses completed across offensive security, cloud, governance, and engineering. Playing Pokemon as a kid got me an addiction to collecting digital badges; you can see mine on Credly ↗.
[ Let's connect ]
Whether you want to collaborate,
or just want to say hi, my inbox is open.