Curriculum Vitae
Check all my certifications in my Accredible wallet!
About Me
Experience
Senior Cybersecurity Consultant | Pentester @ Áudea
01/2026 - Present
Remote
- Perform security assessments for multiple clients across web applications, cloud environments, internal and external infrastructure, Active Directory, and EDR solutions on different operating systems.
- Manage the full lifecycle of offensive security testing for a global client with more than 10 entities across different locations: scoping, effort estimation, testing, reporting, and presenting the results.
- Carry out penetration tests and security reviews using widely adopted tools and methodologies, adapting the approach to each environment and engagement.
- Test the effectiveness of EDR solutions against various attack techniques and flag where detection and response could actually improve.
- Contribute to a banking client’s cyberintelligence/threat monitoring service (built on Recorded Future), producing periodic briefings on threat actor activity, critical vulnerabilities, the ransomware landscape, and geopolitical risk relevant to the client.
- Present findings and recommendations in a clear, practical way, helping clients understand risk and actually prioritize remediation instead of filing the report away.
Senior Ethical Hacker @ Cipher
09/2024 - 01/2026
Remote
- Conducted advanced security assessments and Red Team exercises in complex corporate environments, including Active Directory, web applications, and internal networks, demonstrating increased autonomy and technical depth in each engagement.
- Designed and implemented customized security strategies, leveraging ethical hacking techniques and industry-standard methodologies (e.g., OWASP, MITRE ATT&CK) to identify, exploit, and mitigate critical vulnerabilities, effectively strengthening clients’ security posture.
- Collaborated closely with presales and consulting teams to develop and present tailored cybersecurity solutions aligned with each client’s unique requirements and risk profile.
- Led and coordinated multidisciplinary teams, managing project timelines, task allocation, and performance oversight to ensure the timely delivery of high-quality pentesting and Red Team services.
Ethical Hacker @ Cipher
05/2023 - 09/2024
Remote
- Conducted audits and penetration tests on infrastructures, web and mobile applications, networks, and Active Directory environments to identify and mitigate security vulnerabilities.
- Executed penetration tests on both external and internal assets, identifying critical risks and suggesting mitigation measures.
- Deployed, managed, and executed automated pentesting processes using Pentera, ensuring thorough security assessments.
- Prepared comprehensive reports detailing findings, risks, and security recommendations, tailored for both technical and non-technical stakeholders.
IT Auditor @ Cipher
09/2022 - 05/2023
Remote
- Developed IT and OT system auditing frameworks based on widely recognized standards and regulations.
- Provided consulting services for the enhancement of network architecture and securing communications.
- Conducted risk assessments and contributed to risk management strategies to mitigate cybersecurity threats.
- Led continuous improvement initiatives for internal management systems, optimizing processes and security measures.
IT Risk Consultant @ PwC
03/2022 - 07/2022
Madrid
- Provided consulting services related to cybersecurity for various clients across different industries.
- Conducted audits to ensure compliance with cybersecurity regulations in the banking sector.
- Developed frameworks for banking regulations and fraud control, focusing on cybersecurity measures.
- Supported the implementation of best practices in cybersecurity to enhance overall security posture.
Certifications
Certified Azure Red Team Professional (CARTP)
Altered Security
Certified WiFiChallenge Professional (CWP)
WiFiChallenge Academy
Certified Red Team Professional (CRTP)
Altered Security
Certified Ethical Hacker Master
EC Council
- Certified Ethical Hacker (CEHv13)
- Certified Ethical Hacker Practical
Certified Red Team Analyst (CRTA)
Cyberwarfare Labs
eLearn Junior Penetration Tester (eJPTv2)
INE
INE Certified Cloud Associate (ICCA)
INE
AI Red Teamer Job Role Path (“AI Ninja”)
HTB Academy - Not an exam-based vert, but hands-on
Technical Skills
Only a few, not going to mention all tools
Penetration Testing & Red Team
External/internal pentests, vulnerability assessment, adversary simulation, attack surface analysis, red team operations, MITRE ATT&CK-based campaign design.
Active Directory
Enumeration, privilege escalation, lateral movement: BloodHound, Rubeus, Mimikatz, PowerSploit, Impacket, NetExec, Certify.
Web & Mobile
OWASP Top 10, Burp Suite, SQLmap, Feroxbuster, MobSF, Frida.
Cloud & Kubernetes
Cloud security assessments on Azure and AWS, EDR evasion and detection testing, Kubernetes internals (BadPods, RBAC privilege escalation, container escape, secrets exposure, etcd).
Social Engineering & Physical
Phishing campaigns, QRishing, piggybacking and physical access testing, including critical infrastructure environments like airports.
C2 Frameworks
Havoc, Empire, Metasploit.
AI Red Teaming
Prompt injection, model evasion, data tampering, LLM security evaluation, plus using AI day to day to speed up recon, reporting, and tooling.
Scripting
Python, Bash, PowerShell, etc.
Tools & Frameworks
Pentera, Horizon3, Nessus, Nmap, Nuclei, TestSSL, MITRE ATT&CK, OWASP, OSSTMM, PTES, TLPT.
Education
Cybersecurity master’s degree
Universidad de Alcalá de Henares 10/2021 - 07/2022
Computer Engineering degree
Universidad de Salamanca 09/2017 - 09/2021
Languages
- Spanish ⭐️⭐️⭐️⭐️⭐️
Native - English ⭐️⭐️⭐️⭐️⭐️
Advanced professional - French ⭐️⭐️⭐️☆☆
Basic professional


