Offensive security isn't about finding bugs — it's about proving what's actually exploitable. With 10+ years of experience spanning software development and security, I work across web, API, mobile, and cloud environments, helping teams identify real attack paths and turn findings into stronger security controls.
My focus is application security and penetration testing: exploiting business logic flaws, authentication and authorization weaknesses, and validating high-risk flows — then translating findings into remediation that engineering teams actually implement. I hold an MSc in Cyber Security with Distinction from the University of Birmingham and previously worked as a Security Engineer (Penetration Testing) at CERN.
Outside of work, I share what I learn with the community: speaking at well-known security conferences including DEF CON 34 (Las Vegas), BSides Colombia, and PWN or DIE (Ecuador), publishing research, and creating open security testing resources.
Conferences where I've presented original research:
DEF CON 34 — Las Vegas, USA (2026): Your APP Thinks I'm You: A Complete Kill Chain Against Mobile App Security — talk info BSides Colombia (2026): Your Brain > Your Toolkit: Real Bugs, Zero Code, Zero Tools PWN OR DIE — Ecuador (2025): When Your Mind Becomes the Exploit: No Code, No Tools