Cybersecurity specialist — Available for work

Blue Team analyst with a Red Team foundation and operational threat intelligence. Behind every alert there is someone trusting that their money, their data and their work are still where they left them. Defending that is what I do.

I correlate SIEM alerts, system and network logs, forensic findings, IOCs pulled from threat hunting and cyber intelligence context. Crossing those sources is what turns a lone alert into an investigation with a name, a scope and a response that holds up.

Additional training, with verification where available.

  • CompTIA
  • Security Blue Team
  • Cambridge Assessment English

Where I have worked and where I have trained, kept apart.

Professional experience

  1. MAR 2025JUN 2025España
    Kyndryl

    MultiCloud Administrator

    Kyndryl

    Administration of infrastructure spread across three cloud providers.

    • End-to-end management of environments across AWS, OCI and Azure.
    • Infrastructure provisioning and control as code with Terraform.
    • Maintenance of the team repositories on GitHub.
    • AWS
    • OCI
    • Azure
    • Terraform
    • GitHub

Hands-on practice

  1. 2024PresentBlue Team
    LetsDefend

    Security operations

    LetsDefend · Top 3 in Spain

    View profile

    Simulated real-world cases end to end, from alert to report.

    • SOC analysis and tier 1 and 2 alert response with SIEM (Wazuh and Splunk).
    • Incident handling and threat hunting correlated with simulated investigations.
    • Web attack detection and analysis.
    • Digital forensics on the affected machines.
    • Static and dynamic malware analysis in FlareVM, including reverse engineering.
    • FTK Imager
    • PhishTool
    • MITRE ATT&CK
    • Wazuh
    • Splunk
    • Wireshark
    • Autopsy
    • Volatility
    • Ghidra
    • CyberChef
    • ANY.RUN
    • Hybrid Analysis
    • VirusTotal
    • DeepBlueCLI
    • FlareVM
    • Procmon
    • Regshot
    • Sysmon
    • TheHive
  2. 2024PresentRed Team
    Hack The Box

    Offensive security

    Hack The Box · Professional rank

    View profile

    Real vulnerable machines, compromised end to end. Understanding the attack is what makes defending it possible.

    • Reconnaissance and enumeration of systems, services and vulnerabilities.
    • Exploitation with Metasploit Framework and Burp Suite.
    • Persistence techniques on compromised machines.
    • Command and control with netcat and self-hosted HTTP servers.
    • Privilege escalation and lateral movement.
    • Nmap
    • Nessus
    • Gobuster
    • Ffuf
    • Hashcat
    • Metasploit
    • Burp Suite
    • SQLmap
    • Netcat
    • Hydra
    • winPEAS
    • linPEAS
    • WPScan

Where the foundations come from.

  1. OCT 2025OCT 2026España
    Campus Internacional de Ciberseguridad · UCAMCampus Internacional de Ciberseguridad · UCAM

    Master's in Cyber Intelligence

    Campus Internacional de Ciberseguridad · UCAM

    Threat intelligence, APT group analysis and operational cyber intelligence. Final thesis on the modelling and characterisation of the Lazarus group.

    • OSINT
    • SOCMINT
    • Threat Intelligence
    • MITRE ATT&CK
    • Deep and Dark Web
    • Anonymous networks
    • OPSEC
    • Counterintelligence
    • Attribution
    • Content verification
    • Intelligence reporting
  2. SEP 2023JUL 2025Granada, España
    IES Zaidín Vergeles

    Higher Diploma in Network Systems Administration

    IES Zaidín Vergeles

    Systems, networking and virtualisation: the foundation everything that came later in security rests on.

    • Systems administration
    • Network planning
    • Network services
    • Databases
    • Virtualisation
    • Web applications
    • Markup languages
    • Hardware
    • Security and high availability

Alerts closed, investigations opened and machines compromised in the lab. What has actually been done, counted rather than described.

  • +100

    SIEM alerts triaged

  • +30

    Threat hunting investigations

  • +30

    Machines compromised

  • +5

    Years studying the field

A sample of what I have been working on.

How I work

I use these tools at an advanced level, as an accelerator rather than a replacement for judgement. And so that privacy is not lost along the way, anything sensitive stays in house: I run local models with Ollama, one per task, so no data from an analysis ever leaves my machine.

  • Claude
  • ChatGPTChatGPT
  • Gemini
  • DeepSeek
  • Ollama
  • Vercel