Badges
Certifications
Work Experience
Security Consultant
IBM•  April 2024 - Present•  Chile
Lead Cyber Threat Intelligence (CTI), Threat Hunting (TH) and Brand Protection services for a major client in the travel and transportation sector, with a focus on brand protection, vulnerability monitoring and incident response. Development of Adversary Modeling using MITRE ATT&CK, Lockheed Martin Kill Chain and Diamond Model to improve Red Team and SecOps team initiatives. Generate multi-level CTI reports (tactical, operational, and strategic) on threat actors, malware, events, incidents, and APT campaigns using open, public, and private sources. Interaction with customer stakeholders to align service capabilities and operations with business and security objectives, address risks, and propose improvements using GenAI, LLM, and security platforms. Tools and technologies: OpenCTI, QRadar, CrowdStrike, Qualys, Recorded Future, IBM WatsonX, OpenAI, Feedly, X-Force Exchange.
Senior Security Consultant
Deloitte•  February 2021 - March 2024•  Chile
Led a cyber threat intelligence (CTI) initiative for a multinational client, including dark web monitoring, profiling, and threat actor modeling, and provided actionable insights to improve threat detection and hunting. Served as lead tester for vendor security tools (ESET, VirusTotal, Dataminr), run proofs of concept, and provide insights for solution adoption. Involved in incident response, alert enhancement, DFIR, and continuous improvement of threat detection in SIEM and EDR tools, including QRadar, CrowdStrike, and Microsoft Defender. Development and improvement of SecOps playbooks, OSINT-based analytics and mentoring to junior analysts, ensuring knowledge transfer and operational excellence. ISO 27001 and PCI-DSS compliance, and integration of frameworks such as MITRE ATT&CK into threat detection and response workflows.
IT Product Specialist
WiseVision de Chile•  November 2017 - February 2021•  Santiago, Chile
Perform SAST/DAST vulnerability assessments for a telecom customer using HCL AppScan, providing PoC and quarterly remediation plans to maintain PCI-DSS compliance. Support IAM operations for a banking client following its merger, managing access controls and streamlining user migration workflows using IBM Security Identity Manager. Promote secure coding practices through training and vulnerability mitigation, aligned with OWASP standards and ITIL methodologies.
Education
Instituto Profesional IACC
Cybersecurity, Higher Education Diploma•  August 2021 - November 2021
Universidad Simón Bolivar
Electronic Engineering, BE•  September 2006 - July 2016
Elective Subjects: - Microcomputers I - Genetic Algorithms - Network Interconnections - Telemedicine - Introduction to Management - Enterprise Economy