Offensive security specialist based in La Línea de la Concepción, available remotely across Spain.
Over four years of IT and security experience before specializing in offensive security. That background in support and systems administration gives me an uncommon edge: I understand both how a system breaks and how one is actually kept running day-to-day in a real business.
I'm an active vulnerability hunter on HackerOne and Bugcrowd. That's not a decorative line on my profile: it means I analyze systems with the same mindset as a real attacker, not just the automated tools a generic audit would use.
That same technical rigor is what I bring to every report: a conclusion is only worth something if the methodology behind it is solid and reproducible.
Windows systems administration, Active Directory and user support — the foundation that today lets me understand how a business actually works on the inside, not just how to attack it.
Formal transition into offensive security, with internationally recognized certifications as the technical foundation.
Deep dive into pentesting, digital forensics, offensive Active Directory, and web application and API security.
Vulnerability reward programs at international companies — continuous research with the same mindset as a real attacker.
Building a cybersecurity community in the Campo de Gibraltar area, connecting professionals in the field.
Completed expert witness training and became a chartered member of AEPEJU, extending my practice to party-appointed IT expert reports valid in judicial and extrajudicial proceedings.
Continuous training and hands-on practice in labs (DockerLabs and similar environments) to stay current with the latest attack techniques.
I don't just run an automated scanner. I analyze every system with the same curiosity and persistence I'd apply to a real bug bounty program.
Every finding and every step of the analysis is backed by traceable evidence, not opinion.
A perfect technical report that no one in management understands is useless. I always deliver a version that can be read in five minutes too.
My commitment is to technical truth, not to making the report look good. That's the only way conclusions are actually useful.
You know what you'll pay before starting. No hidden extra hours, no surprises on the final invoice.
NDA, chain of custody and GDPR protocols applied systematically, not as a box-ticking exercise.
First consultation free, by video call or email, no obligation.