Professional Profile
Specialist with over 5 years of experience in vulnerability management in medium and large enterprises, covering the full lifecycle: detection, analysis and prioritization, through to communication and remediation tracking, reducing false positives and improving process traceability.
Experience in process automation for vulnerability management using Python, Bash and PowerShell, leveraging APIs for data extraction and correlation, and generating technical and executive reports, including Power BI dashboards for risk tracking and decision-making.
Knowledge of security standards and frameworks such as UNE-EN ISO/IEC 27001:2023 and the Spanish National Security Framework (ENS) at HIGH category level, applied to corporate environments.
Professional use of tools such as CrowdStrike Falcon (Cloud), Netskope, Palo Alto Networks, Check Point, F5 (Big-IP / Distributed Cloud) and Greenbone (OpenVAS), integrated into vulnerability management processes.
Work Experience
(November 2024 – Present) — SERVINFORM S.A.
Vulnerability Management. End-to-end management of the vulnerability lifecycle in corporate environments, using OpenVAS/Greenbone as the main tool.
Achievements: Design, deployment and consolidation of the corporate vulnerability management system, with distributed on-prem and cloud infrastructure, full-cycle automation and >70% reduction in detection, analysis and remediation times. ENS and ISO 27001 alignment and executive reporting with full traceability.
Responsibilities:
- Greenfield deployment and configuration of the central vulnerability management infrastructure, including distributed sensors (on-prem and cloud) and integration with customer corporate environments.
- Advanced administration of OpenVAS/Greenbone (GVMD, GSA, OSPD): target configuration, scan policies, scheduling, and troubleshooting of communication, feeds, certificates or performance.
- Vulnerability extraction and correlation via APIs, building processes that combine data from CrowdStrike and OpenVAS to create enriched inventories and prioritize risk by CVSS, asset context and real exposure.
- Process automation in Python and Bash: API connection, bulk results download, XML/CSV/JSON normalization and automatic generation of technical and executive reports.
- Bidirectional integration with ticketing (Redmine) to log, assign and close vulnerabilities in line with SLAs, ENS and ISO 27001.
- Vulnerability analysis and prioritization by CVSS, asset criticality and exposure in Falcon, enabling risk management.
- Advanced platform troubleshooting: PostgreSQL DB, gvmd/ospd services, resource usage on sensors and network/distribution issues.
- Drafting of technical and executive reports, improving traceability and cross-team communication.
(April 2023 – November 2024) — WESTCON EUROPE
Perimeter Security Analyst (NIAE technical office) — SSPA (SAS)
Achievements: Optimization of perimeter security and load balancing of critical SSPA services through advanced administration of Check Point, Palo Alto, F5 Big-IP (LTM/GTM/APM), F5 Distributed Cloud, Symantec (Bluecoat), Netskope and Arcsight.
Policy, BGP, PBFs, NATs and routing optimizations improved overall performance and adapted the infrastructure to SAS operational needs, strengthening availability and stability of Andalusia’s healthcare network.
Led the large-scale migration of SAS publications to F5 cloud after Bluecoat proxy licenses ended.
During the transition, custom iRules and policies were configured in F5 to solve web rendering issues, HTTP/HTTPS redirections, header handling and element blocking in browsers, ensuring service continuity and correct display of corporate portals.
Responsibilities:
End-to-end administration of:
- SASE: Netskope
- Proxy: Symantec Bluecoat
- Firewalls: Check Point, Palo Alto, Fortinet
- Load Balancer/DNS: F5 Big-IP (GTM/LTM)
- SSL-VPN: F5 Big-IP (APM)
- F5 Distributed Cloud & F5 Big-IP: load balancing and reverse proxy for SAS domains and agencies. Custom iRules for traffic control, headers, redirections and application hardening. Postman for testing and API integration (F5 Big-IP / Distributed Cloud) in publishing workflows.
- SIEM: Arcsight
- Network intelligence: ALLOT
- Bandwidth management, unified network access control, log management and sandboxing.
- Specialized support and incident resolution, vendor escalations, technical reporting.
(November 2021 – April 2023) — EUIGS (ADMIRAL SEGUROS)
SOC Analyst. Member of the SOC team
Achievements: Security technical reviews (TSR) on new projects deployed both in AWS and on-prem, assessing the robustness of infrastructures, applications and APIs prior to production.
Through the analysis of new features, tools and services, vulnerabilities and security deviations were identified, implementing mitigations that improved the organization’s overall security posture.
Development of testing and controlled pentesting on critical components, ensuring compliance with internal standards and cloud best practices.
Proactive security monitoring across all corporate systems (SIEM, firewalls, DNS, WAF, EDRs, Google Admin alerts and Libra Esva email filtering) plus review of external threat-intel feeds, enabling early threat detection and a significant reduction of unmanaged incidents.
Responsibilities:
- Management of security incidents, threats and vulnerabilities.
- Event and vulnerability monitoring via SIEM, firewalls, IDS/IPS.
- Ticket handling for security reviews of apps, services and infrastructure (cloud and on-prem).
- Risk assessments of environments and applications (TSR — technical security reviews).
- Pentesting.
- Use and administration of security and VM tools: WAF (Imperva), firewalls (Check Point), proxy (Netskope), SIEM (Elastic, Wazuh), IDS/IPS, DNS (Cisco Umbrella), VM (Qualys, Nessus, Acunetix), EDR (Tanium, Harmony), Threat Intel (IntSights), email security (Libra Esva).
- AWS security tools: Amazon GuardDuty, Cloud9, Amazon Inspector, CloudTrail, CloudWatch.
- Project/ticket management and workflows with Jira.
(September 2020 – November 2021) — PERITACIONES TECNOLÓGICAS E INFORMÁTICAS (Tecnoperitaciones)
Cybersecurity Team Lead
Achievements: Consolidation of a fully operational ethical hacking and security auditing area, able to comprehensively assess web infrastructures, corporate networks, Active Directory and cloud (AWS & Azure). Standardization of pentesting and audit methodologies tailored to each client, enabling the discovery of critical vulnerabilities and a significant reduction of exposure risks.
Deployment of hardening measures that strengthened system protection and improved the overall security posture of audited organizations.
Forensic analysis and expert reports in cases of ransomware or data tampering/deletion, ensuring evidence integrity and traceability for legal use.
Responsibilities:
- Ethical Hacking / Pentesting. Web audits, Active Directory, Wi-Fi, cloud (AWS, Azure).
- Hardening. Deployment of improvements and solutions for end customers.
- Forensics (ransomware, malware, data deletion or manipulation).
- Cloning and analysis of digital devices before a notary (phones, tablets, HDDs, recorders, etc.).
- Investigation and expert reports for legal proceedings.
- Analysis and authenticity assessment of conversations (WhatsApp, Telegram, Instagram, etc.) and digital files (images, video, audio, metadata…).
- OSINT.
(February 2008 – September 2020) — SITEL IBÉRICA TELESERVICES
TECHNICAL SUPPORT department for Yacom and Orange
Achievements: Optimization of support and incident resolution processes for Yacom and Orange services, improving response times and user satisfaction.
Participation in documentation and standardization of technical procedures, facilitating onboarding of new agents and reducing operational errors.
Built a solid technical foundation in network troubleshooting and customer support, which became the basis for later specialization in several cybersecurity and perimeter-security domains.
Responsibilities:
- Back-office tasks and handling/resolution of technical incidents.
Technical Skills
SIEM, monitoring & detection
ArcSightElastic SIEMWazuh
Amazon GuardDutyCloudWatch/CloudTrail
Microsoft Sentinel (basic)Splunk (basic)
Vulnerability Management & EDR
OpenVAS/Greenbone (GVMD, GSA, OSPD)CrowdStrike Falcon
QualysNessusAcunetixSecurityScoreCard
PanoraysTaniumHarmony
Perimeter security, SASE & firewalling
Netskope (SASE/CASB/SWG/ZTNA)Palo Alto
Check PointFortinet
Symantec Bluecoat
F5 Big-IP (GTM/LTM/APM)
F5 Distributed CloudAllot
WAF, IDS/IPS & advanced protection
Imperva WAFSnortSuricata
Cisco Umbrella DNSAWS Inspector
Automation, scripting & development
PythonBashPowerShell
REST APIs (CrowdStrike, OpenVAS, Redmine, EasyVista)
JSON/CSV/XMLVM Workflows
Reporting & Integration
Incident management, ITSM & GRC
RedmineEasyVistaJira
ENSISO 27001NISTSLA
Auditing, pentesting & forensics
Network & AD auditsForensics
OSINTExpert reports