Cybersecurity Strategist | Cyber Intelligence | Offensive Security | Cyberfraud Prevention | Framework Creator
Software Engineer, MSc in Cybercrime and MBA-Tech, with 10+ years of experience across offensive security, cyber intelligence, OSINT/SOCMINT/CYBINT, DevSecOps, cloud security, cyberfraud prevention and risk governance.
I create models, frameworks and defensive capabilities that help transform dispersed security signals into evidence, contextual risk and executive decisions.
- Cyber Intelligence & Risk: CTI, exposure analysis, threat profiling, scenario building and decision support.
- Offensive Security Governance: Red Team, Purple Team, adversary emulation, pentesting, bug bounty and control validation.
- Cyberfraud Prevention: OSINT/SOCMINT/CYBINT, digital footprint, human risk, fraud signals and strategic analysis.
- Framework Creation: models, catalogs, controls, evidence chains, scoring logic and executive reporting.
- Emerging Technology Security: AI, cloud, Web3, cryptoassets, quantum security and post-quantum readiness.
My work is shaped by systemic and neurodivergent-informed thinking: pattern recognition, non-linear reasoning, weak-signal integration and the ability to connect technical, human, fraud, business and risk dimensions.
That perspective is reflected in the Systemic Dimensional Model for Cyberprofiling (MSDC/SDMC), created to support SOCMINT, cyberprofiling and human-risk analysis with ethics, traceability, data minimization and human review.
| Project | Contribution |
|---|---|
| P-CIDER | Cyber intelligence decision, evidence and risk model for turning claims, evidence, limitations and controls into defensible decisions. |
| CyberDecisionEngine | Reference implementation of P-CIDER for defensive cyber intelligence, evidence handling, dashboards and executive/technical reporting. |
| Q-SECAT | Framework for evaluating post-quantum, quantum and quantum-enabled security with controls, tests, assurance levels and explicit uncertainty. |
| CSPTF | Crypto Security Penetration Testing Framework for authorized assessment of blockchain, Web3, DeFi, CeFi and digital-asset ecosystems. |
| SDMC | Systemic Dimensional Model for Cyberprofiling applied to SOCMINT, observable digital behavior and human-risk analysis. |
Additional security tools and prototypes: DISC LinkedIn Risk Analysis, Cyberprofile, WebVulnScan and AWS Lambda Security Check.
- Define and evolve enterprise cybersecurity strategies aligned with business risk, fraud prevention, resilience and executive decision-making.
- Build or mature cyber intelligence functions aligned with risk, fraud, compliance and business priorities.
- Design Red Team / Purple Team programs based on real exposure, threat behavior and control validation.
- Support cyberfraud prevention through OSINT/SOCMINT/CYBINT, exposure analysis and strategic risk interpretation.
- Create frameworks, playbooks, scoring models, dashboards, KPIs/OKRs and remediation roadmaps.
- Apply AI to enrichment, entity extraction, semantic analysis, prioritization and reporting with human validation.
- MBA-Tech - Master's Degree in Business Administration and Management
- MSc in Cybercrime
- Software Engineering
- Systems Technology
Cyber Threat Intelligence · Risk Intelligence · Fraud Intelligence · Offensive Security · Red Team · Purple Team · OSINT · SOCMINT · CYBINT · Cyberprofiling · Human-Risk Analysis · DevSecOps · Cloud Security · Vulnerability Management · Executive Risk Communication · Emerging Technology Security
- Technology Camp - Universidad Militar Nueva Granada (2017): cybersecurity and virtual reality.
- XI Fraud Prevention and Security Congress - Asobancaria (2017): social engineering and cyberfraud prevention.
- ISecurity Summit BAQ / CAT / Bogota (2018, 2019, 2022, 2023): OSINT/SOCMINT, neurohacking, MSDC, Red Teaming and Threat Hunting.
- Tactical Edge (2019): OSINT/SOCMINT, Silent War, APT Hunting and cyberprofiling.
- IntelCon Spain (2022): Systemic Dimensional Model for Cyberprofiling applied to SOCMINT.
MITRE ATT&CK · D3FEND · DISARM · MITRE ATLAS · Cyber Kill Chain · Diamond Model · NIST CSF · ISO 27001 · PCI-DSS · CIS Controls · OWASP · CTEM · CNAPP · DevSecOps · AWS · Azure · GCP · Python · FastAPI · Docker · Postgres · YAML/JSON Schema
