02

Where I have worked and where I have trained, kept apart.

Professional experience

  1. MAR 2025JUN 2025España
    Kyndryl

    MultiCloud Administrator

    Kyndryl

    Administration of infrastructure spread across three cloud providers.

    • End-to-end management of environments across AWS, OCI and Azure.
    • Infrastructure provisioning and control as code with Terraform.
    • Maintenance of the team repositories on GitHub.
    • AWS
    • OCI
    • Azure
    • Terraform
    • GitHub

Hands-on practice

  1. 2024PresentBlue Team
    LetsDefend

    Security operations

    LetsDefend · Top 3 in Spain

    View profile

    Simulated real-world cases end to end, from alert to report.

    • SOC analysis and tier 1 and 2 alert response with SIEM (Wazuh and Splunk).
    • Incident handling and threat hunting correlated with simulated investigations.
    • Web attack detection and analysis.
    • Digital forensics on the affected machines.
    • Static and dynamic malware analysis in FlareVM, including reverse engineering.
    • FTK Imager
    • PhishTool
    • MITRE ATT&CK
    • Wazuh
    • Splunk
    • Wireshark
    • Autopsy
    • Volatility
    • Ghidra
    • CyberChef
    • ANY.RUN
    • Hybrid Analysis
    • VirusTotal
    • DeepBlueCLI
    • FlareVM
    • Procmon
    • Regshot
    • Sysmon
    • TheHive
  2. 2024PresentRed Team
    Hack The Box

    Offensive security

    Hack The Box · Professional rank

    View profile

    Real vulnerable machines, compromised end to end. Understanding the attack is what makes defending it possible.

    • Reconnaissance and enumeration of systems, services and vulnerabilities.
    • Exploitation with Metasploit Framework and Burp Suite.
    • Persistence techniques on compromised machines.
    • Command and control with netcat and self-hosted HTTP servers.
    • Privilege escalation and lateral movement.
    • Nmap
    • Nessus
    • Gobuster
    • Ffuf
    • Hashcat
    • Metasploit
    • Burp Suite
    • SQLmap
    • Netcat
    • Hydra
    • winPEAS
    • linPEAS
    • WPScan

Alerts closed, investigations opened and machines compromised in the lab. What has actually been done, counted rather than described.

  • +100

    SIEM alerts triaged

  • +30

    Threat hunting investigations

  • +30

    Machines compromised

  • +5

    Years studying the field

I correlate SIEM alerts, system and network logs, forensic findings, IOCs pulled from threat hunting and cyber intelligence context. Crossing those sources is what turns a lone alert into an investigation with a name, a scope and a response that holds up.