
Israel Guzman
Verified Expert in Engineering
Cybersecurity Architect and Threat Intelligence Lead Developer
Bogotá - Bogota, Colombia
Toptal member since April 22, 2021
Isra is a cybersecurity architect and threat intelligence lead with over 23 years of experience. He specializes in designing resilient defenses and delivering actionable intelligence to governments, global enterprises, healthcare organizations, and financial institutions. Isra's expertise lies in transforming complex cyber risks into strategic advantages, bridging the gap between robust security architecture and decisive executive strategy.
Portfolio
Experience
- Cybersecurity - 20 years
- Digital Forensics - 20 years
- Ethical Hacking - 13 years
- Palo Alto Networks - 11 years
- Cisco - 11 years
- Okta - 5 years
- Zero-day Vulnerabilities - 3 years
- Threat Intelligence - 3 years
Preferred Environment
Cybersecurity, Threat Intelligence, Zero-day Vulnerabilities, Incident Response, Bug Triage
The most amazing...
...bug bounty hunter awards I received were Top 25 and Hall of Fame in 2018 by AT&T, and I also won hackathons using the HackerOne platform as "akax."
Work Experience
IT Infrastructure Engineer III
Optum
- Sustained 99.99% system availability for mission-critical healthcare claims processing applications by implementing proactive monitoring and failover strategies across a hybrid server environment.
- Remediated 200+ high-severity vulnerabilities across Windows and Linux endpoints, ensuring 100% adherence to HITRUST and HIPAA regulatory standards before quarterly security audits.
- Automated server provisioning and configuration management workflows using PowerShell and Ansible, reducing manual deployment time by 60% and effectively eliminating human error during patch cycles.
- Resolved complex L3 infrastructure incidents with a 95% same-day closure rate, conducting detailed root cause analysis (RCA) that permanently fixed recurring database connectivity issues.
- Configured and optimized load balancing rules for high-traffic member portals, successfully supporting 13,000+ concurrent user sessions while maintaining sub-second application response times.
- Eliminated critical identity attack paths identified by SpecterOps BloodHound Enterprise, specifically severing risky edges related to "DCSync" and "GenericAll" privileges to protect Tier 0 assets.
- Remediated high-priority Active Directory misconfigurations flagged by SpecterOps, reducing the domain’s overall exposure score by 35% within the first 90 days of implementation.
- Orchestrated the deployment of SpecterOps collection agents across the domain controller environment, establishing continuous mapping of trust relationships to detect and block lateral movement attempts in real-time.
- Conducted a comprehensive ransomware readiness assessment using RSA Archer IRM, identifying and mitigating 12 distinct process gaps across the backup and recovery workflow to ensure data immutability.
- Centralized ransomware risk tracking within the RSA Archer platform, creating a unified dashboard that provided executive leadership with real-time visibility into control maturity for 20+ mission-critical applications.
Security Researcher | Bug Bounty Hunter | Hacker101 Capture the Flag (CTF) Player
HackerOne
- Received a Certificate of Appreciation from Verizon Enterprise Vulnerability Management Response Team in 2024.
- Received two honors from HackerOne and AT&T (2018 and 2019): https://ctf.hacker101.com.
- Earned 13 invitations and 3/26 points toward my next private program invitation and placed among the top three in Colombia in 2020: https://hackerone.com/att/thanks/2018 and https://hackerone.com/akax/year-in-review.
- Reported and helped fix several vulnerabilities in Okta's products and services. Participated in Okta's bug bounty programs.
- Attained a deep understanding of Okta's architecture and security features. Used my experience with bug bounty tools and techniques to make Okta more secure for companies.
- Found and reported several vulnerabilities in Okta's products and services. Worked with the Okta security team to remediate vulnerabilities and improve security. Shared knowledge and expertise with other security researchers.
- Led cross-functional teams through the entire SDLC.
Board Member
SkyVirt
- Worked as a key architect of the cyber range catalog; designed cybersecurity solutions covering advanced IT, digital forensics, and emerging Crimewall threats.
- Worked with government ministries and agencies to integrate AI and machine learning solutions, enhancing national cybersecurity.
- Implemented robust cybersecurity policies, leveraging AI and machine learning for enhanced threat detection and mitigation.
- Promoted awareness and readiness through training, workshops, and campaigns, highlighting AI's role in cybersecurity.
- Conducted investigations using AI-driven analysis and large language models (LLMs) to produce detailed threat intelligence reports.
- Hunted and neutralized threats targeting critical infrastructure using machine learning operations (MLOps) and adversarial testing.
- Utilized cutting-edge techniques for threat detection, including OSINT, dark web monitoring, and malware analysis, focusing on AI and machine learning.
- Developed labs for OSINT, dark web monitoring, malware, and network analysis, incorporating AI security principles for advanced threat research and training.
- Operationalized StealthMole’s Darkweb Tracker and Telegram Monitoring modules to proactively identify leaked credentials, automating the revocation of 50+ compromised tokens via XSOAR before exploitation could occur.
Board Member
TI Corporation
- Provided a full range of cybersecurity services: research, threat intelligence, monitoring and cyber surveillance of national critical information infrastructure (NCII), network protection, penetration testing, and ethical hacking.
- Consulted on forensic investigation, bug bounty, DevSecOps, cloud computing, blockchain, machine learning, and AI, as well as provided support and training.
- Delivered three training programs: "Creating Disruptive Differentiation with Innovation Management," "The Fundamentals of Cybersecurity and IT Security," and "Cybersecurity and Secure IT Infrastructure, from Policies to Technology and IT Operations."
- Became an IT Geek Trusted Advisor and delivered courses for the chief information security officer (CISO).
- Spoke on Gartner's Nexus of Forces, describing how the convergence and mutual strengthening of social media, mobility, cloud computing, and information patterns create new business opportunities.
- Leveraged areas of expertise to advise clients on security (ethical hacking and cybersecurity), web application security (network security and application security), and ransomware and malware (DeepWeb, DarkNet, ZeroNet, ZeroDay, and Exploit).
- Provided risk advisory services to the Open Web Application Security Project (OWASP).
- Advised clients on cloud security and a law enforcement agency on cybercrime and cyber investigation.
- Served as an active member in the information security community of the current cyberspace.
- Led cross-functional teams throughout the entire SDLC.
Lead Security Systems Engineer A4
EPAM Systems
- Orchestrated the security architecture modernization for 2 global enterprise environments, integrating cloud-native security tools to support a hybrid infrastructure of 10,000+ endpoints.
- Eliminated 95% of critical vulnerabilities across the P&G manufacturing network segment within 60 days by designing and deploying an automated patch management workflow.
- Architected and enforced strict HIPAA-compliant access controls for the TWP environment, securing 5TB+ of sensitive patient data against unauthorized access and data exfiltration.
- Developed custom automation scripts in PowerShell and Python to integrate threat intelligence feeds into the SIEM, reducing mean time to detect (MTTD) by 40%.
- Led a cross-functional team to implement a Zero Trust network solution, migrating legacy VPN access to identity-aware proxies for 1,500+ remote users.
IT Security Expert for Audit Support
Samuel Giacinto
- Remediated 15 critical-severity vulnerabilities across the server infrastructure within a 30-day window, ensuring 100% technical compliance prior to the external audit engagement.
- Configured and validated strict Role-Based Access Control (RBAC) policies in Active Directory for 50+ privileged accounts, aligning system access with the principle of least privilege.
- Executed a technical gap analysis of the existing firewall rule sets, removing 20+ obsolete allow-rules to reduce the attack surface in preparation for network segmentation testing.
- Generated and compiled technical evidence artifacts for 10 distinct security controls, directly supporting the successful closure of the client’s ISO 27001 surveillance audit.
- Hardened 30+ Linux and Windows endpoints by applying industry-standard benchmarks (CIS), resolving configuration drift issues identified during preliminary scans.
Senior Ethical Hacker
STS, LLC
- Enhanced social media security. Mitigated malicious activities on social networks. Proactively profiled threat actors to reduce future risks, safeguarding company assets.
- Executed comprehensive revisions to resolve a significant data breach. Investigated the root cause and implemented corrective security measures to restore data integrity and protect sensitive information.
- Deployed multi-factor authentication with security keys and fixed Data Breaches. Performed mobile digital forensic analysis to investigate and neutralize active security threats.
- Remediated vulnerabilities on Cloud. Updated websites, restricted access for malicious actors, and generated a detailed CTI report for presentation to law enforcement authorities.
Cyber Security Specialist
CTL Law
- Orchestrated proactive cyber threat hunting campaigns using globally sourced CTI feeds, identifying and neutralizing potential intrusion attempts targeting sensitive litigation case files and debtor PII.
- Led digital forensic investigations for suspected data breach incidents, preserving the chain of custody for digital evidence in full compliance with cyberlaw standards and legal discovery requirements.
- Designed and executed adversarial testing scenarios within a custom cyber range, validating the firm's defense mechanisms against ransomware and social engineering, resulting in a 40% improvement in incident detection speed.
- Hardened the enterprise cybersecurity posture by mapping defense controls to the Cyber Kill Chain, successfully disrupting the delivery phase of targeted phishing campaigns aimed at the finance and collections departments.
- Optimized cybersecurity operations by tuning SIEM alert logic, reducing false positives by 60% and ensuring 24/7 visibility into the security status of remote debt collection agents.
- Integrated cyberpsychology principles into the security awareness program, conducting phishing simulations that reduced employee click rates by 75% across the legal and administrative teams.
- Streamlined the GRC roadmap using Vanta to automate evidence collection, successfully securing SOC 2 Type II attestation and PCI DSS compliance while reducing manual audit preparation time by 70%.
- Architected an AutoDevSecOps framework by embedding security controls directly into Infrastructure as Code (IaC) pipelines, automatically blocking 98% of non-compliant configurations before deployment.
Penetration Tester
InspecTiv
- Uncovered critical-severity vulnerabilities (including RCE and SQL Injection) in Verizon’s high-traffic customer portals, effectively preventing potential data exposure for over 1 million subscribers.
- Executed rigorous black-box and gray-box penetration tests against RESTful API endpoints, identifying and assisting in the remediation of Broken Object Level Authorization (BOLA) flaws before global release.
- Simulated Advanced Persistent Threat (APT) attack scenarios to test internal network segmentation, validating the resilience of critical infrastructure, and identifying five distinct monitoring blind spots in the SOC.
- Authored comprehensive technical reports and executive summaries that streamlined the remediation process, resulting in a 30% reduction in Mean Time to Remediate (MTTR) for high-risk findings.
- Developed custom Python automation scripts to accelerate reconnaissance on large IP ranges, reducing the initial scanning phase duration by 40% while increasing asset discovery accuracy.
- Collaborated directly with DevSecOps teams to integrate automated security checks into the CI/CD pipeline, catching 95% of common OWASP Top 10 vulnerabilities before they reached the staging environment.
- Received a formal Certificate of Appreciation by Verizon for the critical discovery and responsible disclosure of a high-risk logical flaw in the billing infrastructure, recognizing the significant mitigation of reputational and financial risk.
- Assessed Okta Identity Cloud configurations and SSO workflows, uncovering five distinct privilege escalation vectors within the federated authentication model that were subsequently remediated to secure employee access.
Security Officer
PayValida
- Directed the annual PCI DSS Level 1 audit preparation, remediating 40+ technical controls to achieve 100% compliance with zero non-conformities during the external assessment.
- Engineered a real-time fraud detection framework that decreased chargeback rates by 18%, directly protecting over $5 million in monthly transaction volume against financial abuse.
- Hardened the Secure Software Development Lifecycle (SSDLC) for core payment APIs, reducing critical vulnerabilities in production code by 90% through the integration of automated SAST/DAST pipelines.
- Orchestrated the incident response strategy for financial threats, cutting containment time for suspected account takeovers from four hours to under 30 minutes using automated playbook triggers.
- Enforced strict data privacy controls across the cloud infrastructure, aligning with Colombian Law 1581 and GDPR standards to secure 100,000+ sensitive user records.
- Deployed Endpoint Detection and Response (EDR) agents, successfully blocking 50+ targeted phishing and ransomware attempts within the first quarter of operation.
Identity Access Management (IAM) Specialist/Consultant for Project Support
Incode Technologies Inc.
- Engineered a custom identity verification workflow within the Incode Omni platform, integrating passive liveness detection to reduce customer onboarding drop-off rates by 22% for a high-volume fintech client.
- Orchestrated the migration of 5,000+ internal workforce identities to a biometric-first authentication model, eliminating password fatigue and reducing helpdesk tickets related to credential resets by 65%.
- Designed and implemented a dynamic risk-scoring engine using Incode’s behavioral biometrics, successfully blocking 99.8% of synthetic identity fraud attempts during a peak retail transaction period.
- Configured and validated a cross-border KYC solution aligning with GDPR and local Mexican banking regulations, enabling compliant digital onboarding for 10,000+ new users within the first month.
- Led the technical integration of Incode’s API with a legacy LDAP system, automating the provisioning lifecycle and cutting average user access grant time from two days to under 15 minutes.
- Conducted a comprehensive security audit of the biometric data retention policies, enforcing strict encryption standards (AES-256) to achieve full compliance with SOC 2 Type II requirements ahead of a scheduled external audit.
Cybersecurity Threat Intelligence Specialist
National Cyber Security Centre
- Authored 30+ strategic threat assessments for high-level government stakeholders, detailing Advanced Persistent Threat (APT) activities targeting UK Critical National Infrastructure (CNI) to inform national defense policy.
- Applied the Diamond Model of Intrusion Analysis to pivot across infrastructure and capability features, successfully attributing a sophisticated cyber-espionage campaign to a specific nation-state actor with high confidence.
- Orchestrated the rapid dissemination of actionable intelligence via the Cyber Security Information Sharing Partnership (CISP) platform, delivering verified Indicators of Compromise (IoCs) and zero-day disclosures.
- Reverse-engineered state-sponsored malware artifacts to extract behavioral signatures, contributing 150+ high-fidelity YARA rules to the national defense repository and effectively neutralizing evasive payloads.
- Standardized intelligence exchange workflows using STIX 2.1 and TAXII protocols, automating the ingestion of allied intelligence feeds (Five Eyes) and reducing manual processing time by 50%.
- Led the CTI workstream during a major national ransomware incident simulation, attributing the attack vectors to a specific criminal syndicate and guiding remediation strategies for the healthcare sector.
- Identified and disrupted a coordinated spear-phishing campaign targeting government officials by pivoting on passive DNS data to take down 40+ malicious command-and-control (C2) domains proactively.
Chief Information Security Officer
Katharsis
- Implemented a secure data center while working in a freelance capacity.
- Installed a Cisco firewall for IP security, VPN, and site-to-site VPN.
- Protected devices and networks with Sophos security solutions.
- Led cross-functional teams through the entire SDLC.
- Gained experience with firewalls, including Cisco ASA, Palo Alto Networks, and Fortinet. Became proficient in configuring, managing, and troubleshooting firewalls. Accumulated experience in network on-premises and cloud projects.
AES Encryption Specialist
DRUO SAS
- Architected and deployed a field-level AES-256 encryption strategy for the core payment ledger, securing sensitive banking metadata for over 50,000 daily transactions against unauthorized database access.
- Designed a FIPS 140-2 compliant Key Management Service (KMS) workflow, automating cryptographic key rotation cycles and eliminating hard-coded credentials to satisfy PCI DSS Requirement 3.
- Optimized the cryptographic library integration within the payment API, maintaining sub-200ms latency for real-time B2B fund transfers while enforcing maximum security standards.
- Conducted a cryptographic code review of legacy payment modules, identifying and remediating 10+ instances of weak ciphers (RC4/DES) to align with modern banking security protocols.
- Implemented strict transport security (HSTS) and TLS 1.3 mutual authentication (mTLS) for all bank-integration endpoints, effectively neutralizing Man-in-the-Middle (MitM) attack vectors.
Lead Security Systems Engineer
Google Cloud
- Architected high-throughput ingestion pipelines for 50+ TB of daily security telemetry, normalizing data from 100+ distinct log sources into the Google Unified Data Model (UDM) to ensure consistent analysis.
- Engineered 50+ custom detection rules using YARA-L, significantly improving the identification of complex APT tactics and reducing false positives by 40% compared to the legacy SIEM solution.
- Optimized hot data retention and indexed search performance, enabling sub-second query responses for historical threat hunting across one year of archived security data.
- Integrated VirusTotal and internal threat intelligence feeds directly into the Chronicle analysis engine, automating the enrichment of indicators of compromise (IOCs) for 10,000+ daily events.
- Led a distributed team of five security engineers in the strategic migration of detection workflows from Splunk to Google Chronicle, achieving 100% feature parity while reducing operational licensing costs by 30%.
- Developed automated response playbooks for high-fidelity alerts, utilizing Chronicle’s API to trigger immediate isolation actions on compromised endpoints within the Middle East region.
- Engineered Cortex XSOAR playbooks to automate incident response for high-fidelity alerts, reducing mean time to resolution (MTTR) by 60% through the orchestration of containment actions across the endpoint and network layers.
- Implemented Kusto Query Language (KQL) logic within the Google SecOps environment to directly query Azure Activity logs and Azure Monitor data, enabling unified threat hunting across multi-cloud (GCP and Azure) infrastructure.
- Established a vendor-agnostic detection repository using Sigma, translating 200+ community-sourced attack signatures into optimized YARA-L rules for Google Chronicle and KQL queries for Azure Monitor, ensuring unified coverage across environments.
Cybersecurity Threat Intelligence Specialist
National Cyber Security Agency
- Hunted threats by utilizing AI security competencies, targeting critical government infrastructure.
- Integrated AI technologies into threat detection and response workflows, ensuring timely and effective defense against evolving cyber threats.
- Conducted rigorous vulnerability testing on AI models to uphold security standards and adherence to ethical AI principles.
- Conducted data cleaning and adversarial testing to ensure model vulnerability testing.
- Utilized prompt engineering, AI model training, and LLMs for threat modeling and intelligence.
- Applied ethical AI principles and RAG for malware analysis and removal.
- Ensured security compliance and malicious activity tracking.
Security Software Engineer
Bank Popular
- Managed cybersecurity projects and developed standards for pen testing, SDLC, AWS, and APIs, integrating AI security practices such as prompt engineering and model vulnerability testing.
- Conducted security assessments and audits, identifying and mitigating security gaps and leading AI model training to ensure robustness and accuracy.
- Ensured compliance with ISO 27001, NIST, PCI, SOC, and other cybersecurity frameworks while establishing MLOps practices for efficient ML model deployment and monitoring.
- Led software security projects, promoting security awareness and continuous improvement and implementing RAG techniques for enhanced AI outputs.
- Enhanced software security policies and standards, improving lifecycle security and resilience, and conducted adversarial testing to bolster AI system resilience.
- Implemented and secured large language models (LLMs) and promoted ethical AI principles for responsible AI development.
- Oversaw data cleaning and security protocols to ensure high-quality and secure data for AI models.
Spanish-speaking IT Security Expert
Tienda Amiga ER S.A.
- Configured, managed, and troubleshot Cisco ASA, Cisco Catalyst 2960 switch, and Router 2901, 3560 L3 y 4321. SPI, DPI, apps, URL filter, IDS/IPS, IAM, threat intel, Umbrella, etc.
- Implemented protection against denial-of-service attacks by configuring, managing, and troubleshooting Meraky AP MR53 and MR46 using features like WPA2-Enterprise, guest access, RADIUS, and SNMP.
- Configured, managed, and troubleshot Fortinet Firewalls Fortigate 60F HA, VPN, IDS, IPS, and content web filter.
Senior Security Engineer
- Joined Pinterest as an active member of the security operations, in charge of PII, SOX, IAM, GMT, and S3 policy management.
- Implemented secure changes with Terraform and Phabricator.
- Supervised Splunk daily to avoid security breaches and threats.
- Worked with Palo Alto Networks firewalls and configured the GlobalProtect.
- Integrated Active Directory, GitHub, GMT, holograms, certificates, and YubiKey within Okta across the entire infrastructure.
- Designed, implemented, and managed Okta-based IAM solutions for enterprise customers, using SSO, MFA, and strong authentication to improve security, reduce risk, and streamline operations.
Senior Security Engineer
Bloomberg Industry Group - Main
- Automated AWS security vulnerabilities mitigation using AWS Lambda function with Python 3 and Boto 3.
- Tracked and fixed requests using Jira for issues, escalations, incidents, software review requests, and security vulnerabilities.
- Automated and Integrated the mitigation of vulnerabilities from the Rapid 7 suite with Jira.
- Created multiple wikis of management and procedures daily.
- Automated and integrated vulnerability mitigation from AWS Guard Duty and AWS Inspector with Jira.
- Improved the automation of the Threat Intel channel, adding more sources, translating on the way, and passing filtered to the main channel.
- Integrated AWS, Atlassian, and Okta within the entire infrastructure.
- Designed, implemented, and managed Okta-based IAM solutions for enterprise customers. Integrated Okta with other systems to create secure and efficient authentication infrastructure.
- Conducted security assessments and audits to identify and mitigate risks associated with Okta and implemented security best practices and industry standards.
DevSecOps Consultant
Palo IT
- Centralized identity management and assigned permissions transversally.
- Configured VPN to segregate access individually and gather traffic logs.
- Automated CI/CD pipelines to deploy QA and ephemeral staging environments.
- Identified customer transactions that used more infrastructure and reduced the DevSecOps workload.
- Deployed a CDN and high availability in specific zones.
- Automated vulnerability analysis for infrastructure and applications and prevented a sensitive data leak.
- Recommended code reviews and automated testing solutions. Led cross-functional teams through the entire SDLC.
- Created vulnerability management solutions (VMs) capable of integrating with any 3rd party in the industry to provide an all-in-one solution with a unique dashboard.
- Designed, implemented, and managed secure IAM solutions, including SSO, MFA, and strong authentication. Integrated Okta with Active Directory, GitHub, and more to create a unified authentication infrastructure.
- Integrated Azure Active Directory, SonarQube with Okta, and certificates within the entire infrastructure.
Chief Information Security Officer
Zaga Labs
- Implemented a secure data center with IP security while serving as a freelance external advisor.
- Installed pfSense firewall security, OpenVPN, and site-to-site VPN.
- Ensured that security measures protected perimeters and rejected attackers.
- Led cross-functional teams through the entire SDLC.
System Security Engineer and Architect
University of Arizona
- Worked for Arizona State University (Asu.edu) on compliance (PCI, FISMA, HIPAA, etc.), authentication and authorization, DIDs, entities IDs, identities, credentials, and meta-credentials.
- Performed cryptography, data protection, Sovrin Governance Framework, Hyperledger Indy decentralized key management, trustee set up protocol, wallet storage design, permissions and rules, CORS and source code, SAST, DAST, and AutoDevSecOps.
- Handled mobile device security enforcement, prevented reverse engineering of the Pocket app, and worked on data source encryption and data transfer encryption in transit, PeopleSoft, databases, and APIs.
- Affected and managed PII masking in real time, OTP, QR codes, and Libindy while working with reports access and endpoints, servers, and mail servers.
IT Operations and Security Supervisor
Visa
- Provided the knowledge required to follow and adhere to PCI DSS compliance frameworks and helped to obtain the SOC Level 2 certification, following the security requirements and standards.
- Used a wide range of tools, including SumLogic, Qualys, Mandiant, SolarWinds, Falco, mobile financial banking; PCI RoC/SOC2 Type II; CloudFlare, Sumo Logic; Mandiant, Qualys, DefectDojo, Check Point, Check Point CloudGuard, Dome9, and SilverSky.
- Identified systemic security issues based on the analysis of vulnerability and configuration data. Enabled the organization to reduce risks and achieve regulatory and statutory compliance.
- Implemented security measures to resolve vulnerabilities, mitigate risks, and recommend security changes to systems or system components as needed.
- Collaborated with functional and cross-functional teams and stakeholders to identify and/or develop appropriate solution designs, implementation, and required mitigation strategies.
- Managed multiple technologies for mobile financial banking and chaos engineering with the Chaos toolkit and Istio. Led cross-functional teams through the entire SDLC.
- Used a wide range of technologies: Snyck, Dependabot, Sonatype DepShield; Trend Micro, Symantec, Sophos; Google Cloud GCP; K8S and Falco as a Daemon; and Sonarqube (dependency checks).
- Utilized Splunk; Jira and Trello; Veracode, Trustwave, Detectify, Mesh7, and Qualys; ProGuard, DexGuard, iXGuard; Bitbucket and Concourse; and DigiCert Central.
- Used Grafana Loki and Data Studio; MongoDB and MySQL; HAProxy and APIs; Gauntlt and Ruby for Vulnerability; and vulnerability management systems (VMS).
- Integrated BambooHR, Cloudflare, Udemy, Azure, Office 365, DefectDojo, Atlassian, ELK, Nagios, New Relic, SolarWinds, Slack, and external apps within Okta.
Chief Information Security Officer
Vycton
- Protected the University Foundation of the Andean Area while working as an external, freelance advisor.
- Implemented several Kaspersky Cybersecurity solutions.
- Implemented IBM Tivoli Storage Manager with data loss protection (DLP).
- Implemented Lenovo XClarity to protect the storage.
- Led cross-functional teams through the entire SDLC.
Senior DevSecOps
FortifID
- Played a key role (as a contractor) in a DevSecOps and CloudUnit project for a US Silicon Valley-based customer. This involved working with SSN data providers, Equifax, Neustar, and Grain.
- Conducted black-box penetration testing and achieved SOC 2 certification.
- Implemented AutoDevOps CI/CD, using GitLab Gold and Kubernetes.
- Developed solutions for managing personally identifiable information (PII) and sensitive data protection. The technologies used included AWS, Rapid7, Qualys, OpenVAS, Maltego, Burp Suite, and other penetration testing tools.
- Led cross-functional teams through the entire SDLC.
- Migrated OneLogin to Okta, keeping all the existing integrations.
Cloud Senior Engineer
Globant
- Designed and deployed futurist projects related to information security for a wide range of companies (shown below). Prioritized and assigned tasks to a group of cybersecurity leaders.
- Implemented the Great Minds eLearning platform for Core Digital Systems (CDS), using Terraform, Ansible, and GitHub Actions over AWS.
- Developed a digital banking mobile app for iOS and Android for GNB Sudameris Bank.
- Co-developed solutions as a member of the EY core platform squad. These included the EY Blockchain Analyzer, Axiomatics, and others related to common capabilities and tax transparency.
- Designed the architecture and deployed, supported, maintained, protected, and secured the environments.
- Served as a cybersecurity advisor to C-level executives, stakeholders, and product owners who made decisions about solutions that addressed business goals and risks.
- Advised leadership, management, and less experienced cybersecurity leaders on solutions deployed in the environment for incidence responses related to threats, vulnerabilities, and compliance. Used Agile, Scrum, and Jira to address and track issues.
- Led cross-functional teams through the entire SDLC.
Virtualization and Migration Engineer
Claro Colombia
- Led discovery and the RFP process to migrate VMware to Huawei Private Cloud FusionSphere for Global HITSS.
- Migrated HP ServiceManager Cloud BMC Remedy (Apache Tomcat), protected by security baselines, Qualys, Dynatrace, and SIEM.
- Implemented a chatbot offered by the Inbenta company.
- Managed operating systems: Oracle Solaris, Oracle RACDB, Red Hat, and Windows Server.
- Led cross-functional teams through the entire SDLC.
Cloud Architect
BITS Americas S.A.S
- Migrated a 100% on-premise infrastructure to Azure for Flores Funza, while serving as the CISO at BITS Americas.
- Migrated to Office 365 for Flores Funza and Tannus, a legal services company.
- Set up an AWS ETL for Tigo Latam, a Millicom telecom company.
- Managed operating systems: Windows Server and Linux.
- Led cross-functional teams through the entire SDLC.
Chief Information Security Officer
Bull Marketing
- Implemented a secure data center while working as a freelancer.
- Supported VPN, site-to-site VPN, IP security, and VoIP using Asterisk.
- Protected a secure website and email communication to prevent virus infections by bad actors.
- Led cross-functional teams through the entire SDLC.
Security and Systems Administrator SME
Hewlett Packard Enterprise
- Served as a capability administrator L4 for Pfizer, overseeing the ITO project delivery team, application hosting services (AHS) reporting group, and Intel on physical and virtual environments with VMware and Hyper-V.
- Owned responsibility for building and securing existing and new systems according to lifecycle capacity, always focusing on business continuity with an emphasis on finding the root cause and proper solutions for each daily case.
- Oversaw premium support for 400 servers, aligned with the overall infrastructure, ensuring that IT assets met the needs of corporate policies and continuously building strong professional relationships with key IT and LOB executives.
- Served as a subject matter expert for a Latin American internal assessment review (ITAM), corrective action and preventive action (CAPA), and problem and root cause analysis (RCA).
- Led ITSM change management 401 RFCs; conducted 12 pre-approved template reviews; and provided service incident management with response 2755 resolved and 1863 requested. Served as a configuration item owner and QA of 400 CIs under CMDB.
- Set up monthly BTI and daily infrastructure operations and amp reports for regional operative meetings with the global command center (GCC).
- Managed hardware self-sparing and product support case management. As an HPE Saba learner and HPE support case manager, I completed Power 2 Learn (126 courses) and learned manager and admin rooster roles.
- Experienced in Cisco ASA, Meraki, and VoIP. Troubleshot and configured security as SPI, DPI, app identification, URL filter, IDS/IPS, threat intel, cloud, network, DLP, remote access, web application, malware, Umbrella, etc.
- Performed security monitoring and analytics using HPE Service Center, Qualys, Nessus, MSB, SCCM, McAfee ePolicy Orchestrator 5.3 Intel Security, EMC Watch4Net, CA SysEdge, and eHealth. Merged three data centers into one.
- Managed the infrastructure: HPE servers, storage, Cisco switches, networking, blades, and backup solutions, HP Data Protector, and CA BrightStor ARCserve. The technologies were VMware, Linux ESx, Aix, HP-UX, Red Hat, and Windows Server.
Chief Information Security Officer
InTacto Comunicaciones
- Served as an external freelance advisor to InTacto Comunicaciones.
- Implemented a secure communication channel for the whole company using Microsoft Exchange.
- Deployed Symantec cybersecurity solutions to protect the network and devices.
- Led cross-functional teams through the entire SDLC.
Chief Information Security Officer
Construcciones Obycon SAS
- Protected the network and devices with Kaspersky cybersecurity solutions.
- Enforced policies to prevent unauthorized access to the company's applications.
- Implemented Active Directory with GPO, using a Microsoft Windows Server.
- Led cross-functional teams through the entire SDLC.
SysAdmin
SONDA
- Supported servers for 3M: HP ProLiant G7; HP EVA4400; HP MSL6000; Dell PowerEdge; AD; DHCP; DNS; GPO, SQL, Visual Studio Foundation; file, SharePoint, and IIS Servers; and SCCM.
- Implemented a new data center and DRP, covering VMWare, Lotus Domino 8, CA ARCserve, and HP Data Protector.
- Managed service requests from IBM TEC and the Remedy Helpdesk; supervised the dashboard server and PC support.
- Provided specialized support to VIP users, covering MOC Apple and BlackBerry.
- Supported deployment (Swimage) and McAfee Encryption. Provided regional level-one support, both onsite and remote.
- Led cross-functional teams through the entire SDLC.
Chief Information Security Officer
Geosintéticos
- Implemented a secure way to manage all the IT devices while working as an external freelance advisor.
- Deployed a secure PHP web portal with a MySQL database.
- Implemented a secure communication channel for the whole company.
- Led cross-functional teams through the entire SDLC.
SysAdmin
IBM
- Provided cybersecurity services for Avianca and Allianz.
- Served as a command center engineer, working with VMware, HP Data Protector, and BrightStor ARCserve, as well as change management.
- Provided tech support for Active Directory, Forefront, File Server, IIS, WSUS Updates and Cirats, Exchange 2007, Blackberry BES, Citrix high availability in multiple data centers, and accounting close.
- Ensured enforcement and control of interfaces in SAP, IIS, SQL, Adabas, SIS, Sharepoint, Test Director and ESM, Oracle, AIX, Hp-Ux, Tivoli TEC, HP Data Protector and Tivoli TSM, VIP, and the company's CNCs. Provided 7x24 second-level support.
- Managed operating systems: HP-UX- Aix, Oracle Solaris, Red Hat, and Windows Server.
- Led cross-functional teams through the entire SDLC.
IT Specialist
Getronics
- Worked in the IT department at Movistar (Movistar.co/).
- Monitored data centers, Citrix clusters, and applications.
- Provided VIP support at a national level for Gtran devices and cellular data services.
- Led cross-functional teams through the entire SDLC.
IT Analyst
Sitel Group
- Completed work for internal clients: Microsoft, Telecom, and HP.
- Supported network and communication solutions at a national level.
- Provided support and training for services such as VSAT, Clear Channel, and satellite connections.
- Created the intranet in PHP for internal management of those client companies.
- Led cross-functional teams through the entire SDLC.
Experience
Cyber Range | Author of Training at SkyVirt
https://synergysystemsindia.com/Basic modules:
• DevSecOps
• AutoDevSecOps, WSL2, SIEM, Kubernetes, and Docker
• OSINT and Enumeration
• BugBounty
• Capture the Flag Competitions (CTFs)
• SQL Injection
• Cross-site Scripting (XSS)
• DDoS
Spyder Analytics
The proof of concept included the following functions:
• Comprehensive operating system guesses.
• Uptime, ports, and service device types per host detection based on fingerprint matches.
• Vulnerabilities discovery based on network traceroutes and service versions on each port.
• Host footprinting based on TCP/IP sequence prediction and thumbprint over IPv4 and IPv6.
• Firewall and IDS evasion and spoofing with accurate miscellaneous options.
Startup Founder
Education
Bachelor's Degree in Computer Science
ECCI University - Bogotá, Colombia
Certifications
Certificate of Appreciation
Verizon
Recorded Future Intelligence Fundamentals
Recorded Future
Web Security: Same-Origin Policies
Web Security: OAuth and OpenID Connect
Transitioning to a Career in Cybersecurity
Sophos Certified Sales Consultant
Sophos
Project 2019 and Project Online Professional Essential Training
Penetration Testing: Advanced Web Testing
Penetration Testing: Advanced Enumeration
OWASP Top 10: #9 Components with Known Vulnerabilities and #10 Insufficient Logging and Monitoring
Microsoft Cybersecurity Stack: Advanced Identity and Endpoint Protection
Learning Tor and the Dark Web
Learning Cyber Incident Response and Digital Forensics
Introduction to Quantum Computing
Insights from a Cybersecurity Professional
Extending, Securing, and Dockerizing Spring Boot Microservices
Ethical Hacking: The Complete Malware Analysis Process
Ethical Hacking: Penetration Testing
CompTIA PenTest+ (PT0-001): 5 Selecting Pen Testing Tools
CompTIA IT Fundamentals (FC0-U61) Cert Prep 3
CompTIA IT Fundamentals (FC0-U61) Cert Prep 2: Files and Applications, Networking, and Security
CompTIA CySA+ (CS0-002) Cert Prep: 7 Compliance and Assessment
CompTIA CySA+ (CS0-002) Cert Prep: 4 Software and Systems Security
CompTIA CySA+ (CS0-002) Cert Prep: 3 Identity and Access Management
CompTIA CySA+ (CS0-002) Cert Prep: 2 Vulnerability Management
CompTIA CySA+ (CS0-002) Cert Prep: 1 Threat Management
CompTIA A+ (220-1002) Cert Prep 6: Networking, Security, and More
CompTIA A+ (220-1002) Cert Prep 4: Command-Line Interface and Scripting Languages
CISSP Review Course Completion Certificate ISC²
ISC2
CISSP Cert Prep: 8 Software Development Security
CISA Cert Prep: The Basics
CISA Cert Prep: 1 Auditing Information Systems for IS Auditors
CASP+ Cert Prep: 4 Technical Integration of Enterprise Security
CASP+ Cert Prep: 3 Enterprise Security Operations
Android App Penetration Testing
AWS for DevOps: Security, Governance, and Validation
AWS for Architects: Advanced Security
AWS Security Best Practices for Developers
Aviatrix Certified Engineer (ACE): Multi-Cloud Network Associate Course
Aviatrix
Google Cloud Platform Fundamentals: Core Infrastructure
Coursera
Senior Cyber Security Engineer
Udemy
Level BBB | CEFR LEVEL B2
Language Market
Advanced Computer Security | Strategic Decision and Risk Management
Stanford University Online
Level BBB | CEFR LEVEL B1
Berlitz Languages Inc.
MCSA: Windows Server 2012 R2
Microsoft
IT Professional
Microsoft
MCITP | Windows Server 2008 R2 (70-640)
Microsoft
Network Analyst
Sitel University
English Intermediate
KOE Corporation
Skills
Libraries/APIs
CyberSource, AES
Tools
Splunk, Phabricator, AWS IAM, Sumo Logic, DefectDojo, Dome9, Maltego
Paradigms
DevSecOps, Penetration Testing, Inversion of Control (IoC), HIPAA Compliance
Platforms
Blockchain, Azure, Amazon Web Services (AWS), Windows Server, Kubernetes, QualysGuard, Check Point CloudGuard, Rapid7, Burp Suite, Malware Information Sharing Platform (MISP), Intel
Industry Expertise
Banking & Finance, Cybersecurity
Storage
Database Security
Languages
Python
Frameworks
OpenVAS
Other
Software Development Lifecycle (SDLC), Growth Hacking, Culture Hacking, Threat Intelligence, System-on-a-Chip (SoC), SIEM, IDS/IPS, Zero-day Vulnerabilities, Incident Response, English, Indicators of Compromise (IoCs), VSAT, Channels, Peer-to-peer Networking, Architecture, Innovation, FERPA Compliance, Self-sovereign Identity (SSI), SecOps, Personally Identifiable Information (PII), SOX, SOX Compliance, Identity & Access Management (IAM), Cryptography, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Encryption, Languages, Palo Alto Networks, Security Audits, Security, IT Security, Cloudflare, Amazon Bedrock, AWS IAM Identity Center, Artificial Intelligence (AI), Red Teaming, CI/CD Pipelines, Data Governance, Data Privacy, Ethical Hacking, APIs, Serverless, IOTA, Bug Triage, Networking, Quantum Computing, Digital Forensics, IT Project Management, PCI, SOC 2, Mandiant, Troubleshooting, Programming, Security Architecture, Distributed Ledgers, Cyberlaw, Network Security, Cisco, Fortinet Firewall Configuration, Okta, Threat Modeling, Open-source Intelligence (OSINT), Malware Analysis, Malware Removal, Cyber Ranges, Prompt Engineering, AI Modeling, Vulnerability Assessment, Large Language Models (LLMs), Machine Learning Operations (MLOps), Data Cleaning, Retrieval-augmented Generation (RAG), Machine Learning, Adversarial Testing, AI Ethics, Cyber Threat Intelligence (CTI), Certified Ethical Hacker (CEH), 3D Secure, Securities, Cyber Defense, Cyber Kill Chain, Microsoft Entra, InCode, CyberArk, Cyberattacks, Cyber Forensics, Cyber Threat Hunting, Cyberpsychology, Cyber Defamation, Enterprise Cybersecurity, Cybersecurity Operations, Advanced Encryption Standard (AES), Cybersecurity Maturity Model Certification (CMMC), Cybersecurity Automation, ZeroTrust, SuperCluster
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring