Offensive Security Expert with a Master's degree in Cyber Security from the University of Birmingham and 10+ years of experience across mobile, API, cloud, and infrastructure security. Currently leading offensive security operations at a Latin American fintech, with deep specialization in Android security research — including RASP bypass, KYC biometric evasion, and mobile application reverse engineering using dynamic instrumentation.
Former security engineer at CERN, where I focused on web penetration testing and vulnerability analysis for critical research infrastructure. My work spans the full offensive security lifecycle: from attack surface reconnaissance and vulnerability discovery to exploitation, reporting, and remediation guidance. I hold industry certifications including CEH, eJPT, and CAPIPEN, and have presented original security research at international conferences including DEF CON 34 (Las Vegas), BSides Colombia, and PWN or DIE (Ecuador). At DEF CON 34 I presented 'Your Bank Thinks I'm You: A Complete Kill Chain Against Mobile Banking Security', and at BSides Colombia and PWN or DIE I presented 'Your Brain > Your Toolkit: Real Bugs, Zero Code, Zero Tools', a talk on finding critical vulnerabilities through pure logical reasoning without automated tooling.
For more information, have a look at my curriculum vitae .
Please, contact me for anything related to information security.