Offensive security isn't about finding bugs — it's about proving what's actually exploitable. With 10+ years of experience spanning software development and security, I work across web, API, mobile, and cloud environments, helping teams identify real attack paths and turn findings into stronger security controls.
My focus is application security and penetration testing: exploiting business logic flaws, authentication and authorization weaknesses, and validating high-risk flows — then translating findings into remediation that engineering teams actually implement. I also leverage AI-augmented security workflows, including LLM-assisted vulnerability discovery and OWASP LLM Top 10 testing. I hold an MSc in Cyber Security with Distinction from the University of Birmingham and previously worked as a Security Engineer (Penetration Testing) at CERN.
Outside of work, I share what I learn with the community: speaking at well-known security conferences including DEF CON 34 (Las Vegas), BSides Colombia, and PWN or DIE (Ecuador), publishing research, and creating open security testing resources.
Conferences where I've presented original research:
DEF CON 34 — Las Vegas, USA (2026): Your APP Thinks I'm You: A Complete Kill Chain Against Mobile App Security — talk info BSides Colombia (2026): Your Brain > Your Toolkit: Real Bugs, Zero Code, Zero Tools PWN OR DIE — Ecuador (2026): Frustration Kill Chain: un framework para depurar rechazo en seguridad ofensiva PWN OR DIE — Ecuador (2025): When Your Mind Becomes the Exploit: No Code, No Tools