🇪🇸 Español X-Men '97

Hi, I'm Xavier Riofrío,

WhoAmI

Offensive Security Expert with a Master's degree in Cyber Security from the University of Birmingham and 10+ years of experience across mobile, API, cloud, and infrastructure security. Currently leading offensive security operations at a Latin American fintech, with deep specialization in Android security research — including RASP bypass, KYC biometric evasion, and mobile application reverse engineering using dynamic instrumentation.

Former security engineer at CERN, where I focused on web penetration testing and vulnerability analysis for critical research infrastructure. My work spans the full offensive security lifecycle: from attack surface reconnaissance and vulnerability discovery to exploitation, reporting, and remediation guidance. I hold industry certifications including CEH, eJPT, and CAPIPEN, and have presented original security research at international conferences including DEF CON 34 (Las Vegas), BSides Colombia, and PWN or DIE (Ecuador). At DEF CON 34 I presented 'Your Bank Thinks I'm You: A Complete Kill Chain Against Mobile Banking Security', and at BSides Colombia and PWN or DIE I presented 'Your Brain > Your Toolkit: Real Bugs, Zero Code, Zero Tools', a talk on finding critical vulnerabilities through pure logical reasoning without automated tooling.

Skills

Android Security
Mobile Application Security
KYC / Biometric Security
Dynamic Instrumentation
API Security
Web Application Security
Cloud Security
Reverse Engineering
Network Security
Burp Suite
Frida
MobSF
JADX
Nmap
Nuclei
Metasploit
AWS CLI
OWASP Mobile Top 10
OWASP API Security Top 10
OWASP Web Testing Guide
OWASP Mobile MASVS
PTES

Education & Experience

  • Deuna December 2023 - Present
    Offensive Security Expert
    Mobile Ethical Hacker API Pentesting Biometric Security Research KYC Security
  • DEF CON 34 August 2026
    Speaker — Your Bank Thinks I'm You: A Complete Kill Chain Against Mobile Banking Security
    Biometric Bypass KYC Security Research
  • Speaker — Your Brain > Your Toolkit: Real Bugs, Zero Code, Zero Tools
    Logic Flaw Exploitation Zero Code, Zero Tools
  • Certified API Penetration Tester — The SecOps Group
    Credential ID 11585074
  • Speaker — Your Brain > Your Toolkit: Real Bugs, Zero Code, Zero Tools
    Logic Flaw Exploitation Zero Code, Zero Tools
  • eJPT October 2024
    eJPT — INE (Exp. Oct 2027)
    Junior Penetration Tester
  • Unicomer Group January 2023 - November 2023
    Cyber Security Specialist
    Ethical Hacking Microsoft Defender Cloud Security
  • CERN April 2021 - June 2022
    Security Engineer (Penetration Testing)
    Web penetration testing CI/CD Security Vulnerability Analysis
  • Independent Security Consultant December 2017 - Present
    Security Consultant & Bug Bounty Researcher
    Security researcher Trainer Bug bounty hunter
  • UTPL October 2017 - June 2023
    Administration and Public Management
  • Universidad de Cuenca May 2018 - March 2021
    Cyber Security Researcher
    White-Black box hacking Zero-day attacks
  • Universidad Nacional de Loja October 2018 - April 2019
    Professor
    Teaching Research experience
  • University of Birmingham September 2016 - December 2017
    MSc Cyber Security with Distinction
  • Universidad de Cuenca August 2014 - August 2016
    Software Developer
    Frontend - Angular JS Backend - Java Spring Boot
  • BSc in Computer Science and Engineering

For more information, have a look at my curriculum vitae .

Personal posts

Contact

Please, contact me for anything related to information security.

CEH
CEH
eJPT (INE)
eJPT (INE)
CAPIPEN (SecOps Group)
CAPIPEN (SecOps Group)