🇪🇸 Español X-Men '97

Hi, I'm Xavier Riofrío,

WhoAmI

Offensive security isn't about finding bugs — it's about proving what's actually exploitable. With 10+ years of experience spanning software development and security, I work across web, API, mobile, and cloud environments, helping teams identify real attack paths and turn findings into stronger security controls.

My focus is application security and penetration testing: exploiting business logic flaws, authentication and authorization weaknesses, and validating high-risk flows — then translating findings into remediation that engineering teams actually implement. I hold an MSc in Cyber Security with Distinction from the University of Birmingham and previously worked as a Security Engineer (Penetration Testing) at CERN.

Outside of work, I share what I learn with the community: speaking at well-known security conferences including DEF CON 34 (Las Vegas), BSides Colombia, and PWN or DIE (Ecuador), publishing research, and creating open security testing resources.

Education & Experience

  • Deuna December 2023 - Present
    Offensive Security Expert
    Mobile Ethical Hacker API Pentesting Biometric Security Research KYC Security
  • DEF CON 34 August 2026
    Speaker — Your APP Thinks I'm You: A Complete Kill Chain Against Mobile App Security
    Biometric Bypass KYC Security Research
  • Speaker — When Your Mind Becomes the Exploit: No Code, No Tools
    Logic Flaw Exploitation No Code, No Tools
  • Certified API Penetration Tester — The SecOps Group
    Credential ID 11585074
  • Speaker — Your Brain > Your Toolkit: Real Bugs, Zero Code, Zero Tools
    Logic Flaw Exploitation Zero Code, Zero Tools
  • eJPT October 2024
    eJPT — INE (Exp. Oct 2027)
    Penetration Testing
  • Unicomer Group January 2023 - November 2023
    Cyber Security Specialist
    Ethical Hacking Microsoft Defender Cloud Security
  • CERN April 2021 - June 2022
    Security Engineer (Penetration Testing)
    Web penetration testing CI/CD Security Vulnerability Analysis
  • Independent Security Consultant December 2017 - Present
    Security Consultant & Bug Bounty Researcher
    Security researcher Trainer Bug bounty hunter
  • UTPL October 2017 - June 2023
    Administration and Public Management
  • Universidad de Cuenca May 2018 - March 2021
    Cyber Security Researcher
    White-Black box hacking Zero-day attacks
  • Universidad Nacional de Loja October 2018 - April 2019
    Professor
    Teaching Research experience
  • University of Birmingham September 2016 - December 2017
    MSc Cyber Security with Distinction
  • Universidad de Cuenca August 2014 - August 2016
    Software Developer
    Frontend - Angular JS Backend - Java Spring Boot
  • BSc in Computer Science and Engineering

For more information, have a look at my curriculum vitae .

Speaking

Conferences where I've presented original research:

DEF CON 34 — Las Vegas, USA (2026): Your APP Thinks I'm You: A Complete Kill Chain Against Mobile App Securitytalk info
BSides Colombia (2026): Your Brain > Your Toolkit: Real Bugs, Zero Code, Zero Tools
PWN OR DIE — Ecuador (2025): When Your Mind Becomes the Exploit: No Code, No Tools

Skills

Penetration Testing
Web Application Security
API Security
Mobile Application Security
Cloud Security
Business Logic Testing
KYC / Biometric Security
Reverse Engineering
Network Security
Burp Suite
Python
Frida
Nmap
Nuclei
SQLmap
MobSF
JADX
Metasploit
AWS CLI
OWASP Top 10
MITRE ATT&CK
Threat Modeling
PTES
OWASP MASVS

Personal posts

Contact

Open to research collaborations, conference speaking, and security consulting - feel free to reach out through any of the channels below.

CEH
CEH
eJPT (INE)
eJPT (INE)
CAPIPEN (SecOps Group)
CAPIPEN (SecOps Group)