Skip to content

RESUME

Resume

Download my resume or browse the web version below.

Download CV

PDF versions are available in English and Spanish.

Summary

Offensive Security Engineer and Computer Science Engineer with three years of experience in Web, API, and mobile application security assessments in enterprise environments. I also have practical exposure to Thick Client and Wi-Fi testing. My work includes identifying vulnerabilities, assessing technical and business impact, and communicating actionable findings to technical teams and stakeholders. I am focused on Application Security, Product Security, Mobile Security, Offensive Security, and security automation.

Experience

NTT DATA

Jan 2022 to Present

Engineer

Mar 2025 to Present

  • Performed Ethical Hacking assessments across Web, API, and Mobile environments for enterprise and global business contexts.
  • Proposed an internal Burp-based reporting assistant MVP focused on sanitized HTTP evidence, structured finding drafts, and analyst-in-the-loop review.
  • Designed and implemented a Windows-based vulnerable lab to support controlled offensive security assessment and training scenarios.

Junior Engineer

Mar 2023 to Mar 2025

  • Performed Ethical Hacking assessments across Web, API, Mobile, Thick Client, and Wi-Fi environments.
  • Participated in offensive security simulations using playbooks covering phishing, social engineering, endpoint compromise, and ransomware response scenarios.
  • Supported international Web/API Ethical Hacking assessments in collaboration with NTT DATA Spain’s Hacking Center.

Professional Internships

2022 and 2023

  • Performed Web Ethical Hacking assessments and documented technical findings and remediation recommendations.
  • Built a vulnerable web application lab for an educational security workshop.
  • Supported documentation work on Cloud Zero Trust controls and API security.

Selected Projects

evidence-sanitizer

A local-first CLI for sanitizing authorized pentest evidence files.

Windows CTF Lab

A Windows-based CTF lab for controlled offensive security assessment and training scenarios.

Education

Universidad Técnica Federico Santa María
B.S. / Ingeniería Civil Informática / Computer Science

Thesis: "Alexandria: a web platform for storing mobile applications and their analysis results, with a focus on information privacy."

Highest grade: 100/100.

Certifications

OSCP+ certification badge

OSCP+

OffSec Certified Professional

eJPT certification badge

eJPT

Junior Penetration Tester

Microsoft Azure Fundamentals AZ-900 certification badge

Microsoft Azure Fundamentals AZ-900

Microsoft Certified

Skills

Offensive Security

Web/API Pentesting Mobile Application Testing Thick Client Testing Wi-Fi Security Assessments Active Directory Network Enumeration Linux/Windows Privilege Escalation Phishing Social Engineering OWASP Top 10

Tools

Burp Suite Caido Nessus Nuclei Metasploit Nmap ffuf sqlmap Wireshark testssl.sh Impacket NetExec BloodHound Mimikatz WinPEAS/LinPEAS Kali Linux Frida Objection MobSF JADX

Development and Cloud Fundamentals

Python JavaScript TypeScript Node.js React Bash AWS Azure Docker Serverless

AI & Automation

Security Automation AI-assisted workflows Technical documentation workflows Pentest documentation workflows

Languages

Spanish Native
English C1