Pablo SalinasSecurity Engineer
Pablo is a Professional Cybersecurity Consultant with more than 7 years of experience in cybersecurity and information technology (Offensive Security). At KPMG, Pablo occupied the Senior Cybersecurity Consultant role for the Penetration Testing Services offered to an important Argentinian Petrol & Gas company (YPF) and Tenaris. In this role, he was in charge of operating the Penetration Testing Service, based in Buenos Aires, Argentina. Before joining KPMG, Pablo worked for several years for different organisations of the public sector of the country, where he performed the role of Forensic Technical Auxiliary and participated in many forensic investigation cases. In the last years, he held the position of Application Security Engineer at a well-known FinTech company of Galicia Group in Argentina named Naranja X and also, he held the position of Service Leader Social Engineering Pentester in DreamLab Technologies. He also worked in Kavak (Automotive Company which also provides financial services), and Pomelo SAS, a Fintech company which provides Banking as a Services, and he worked as a DevSecOps Engineer Sr. at Zivver B.V, a Secure Email Provider. He also worked as an Application Security Engineer Sr. at Payconiq Services in The Netherlands managing the DevSecOps and Security Champions program, and he worked in Amsterdam for ABN AMRO Clearing Bank as a Technical Leader in Application Security and Applied Cryptography. Nowadays, he is working for Cryptograhy Research Centre in UAE. Also, he has performed freelance projects for important clients (Government of Argentina and Costa Rica, Police Departments, ARSAT, Revela Retreats, Pacifica Resort, Rizobacter, vMetrix, WhiteJaguars, and many financial companies, PYME’s, etc.) as Cybersecurity Consultant and Instructor. It is important to highlight that he has developed an important skill set building security culture from the scratch thanks to his professional experience in startup companies and in freelance projects. Pablo is skilled and have knowledge in some computer programming (python, java, ruby, bash, powershell, scala, kotlin, golang, typescript, C#, C++, php, javascript frameworks - nodeJs, GraphQL.), SIEM tools (Q-Radar, CORTEX XDR, FortiSIEM, Wazuh, Microsoft Security Center, Azure Sentinel, Insight EDR/VM, OSSIM), and hacking tools, methodologies, compliances and best practices over different environments (mobile - webapps, Infrastructure, Docker, Kubernetes, Cloud), as well a manual code review. His most professional relevant experience includes: Execution of short and long Penetration Testing Projects providing technical advice through reports (Time Boxed and working under the flow of a working process - S-SDLC). Additionally, he worked over important approaches from the scratch such as secret management, image hardening, improvement of processes, continuous Security pipelines, threat modelling, cloud security, red teaming and making key decisions in new projects from the scratch. Design and implementation of a company-wide Penetration Testing concept for small and large companies, following the most recognised worldwide security standards (OSSTMM, OWASP, PTES, OWISSAM, NIST 800-15, MSTG, WSTG, ASVS, SAST, DAST, RASP, IAST, OAST). Execution of more than 300+ Penetration Testing over different environments (Mobile / IVR systems / Physical Intrusion / Web Applications / Networks / Wireless / Systems / API / SAP / Salesforce / Containers / Cloud / IoT) and Open-Source Intelligence (OSINT) projects including automated scanning & manual testing, social engineering attacks, session handling (AAA), business logic and code review, ethical hacking techniques, reporting and presentation of results to the target audience (C-Level, Risk Board, Developers’ Team), as well as related tracking issues, re-testing and follow-up activities. Experience with Visitor Management Solutions, CRMs, Websites, Banking Mobile Apps, Automotive Systems, IVRs Systems, Smart Card technologies, Wireless Enterprise Systems, Cards, E-Commerce apps (Gift cards, coupons, vouchers, etc.), Petrol Management Systems, HHRR & Marketing solutions, Payment systems, Identity providers apps, etc. He also generated training and guidelines about security awareness connected to OWASP Top 10, SAP Security, Smart Contract Hacking, Social Engineering and Secure Development for different companies (Naranja X, KAVAK, Zivver B.V., Education IT, HackingMode). Additionally, he was an instructor of the "Empleate" cybersecurity education program of the Costa Rican government sponsored by compTIA. He has contributed to perform controls of Security Compliance and Best Security Software Practises about different security standards and regulations (NIST 800-53, Magerit, SOC type 2, NTA 7516, CAMM, OWASP, ASVS, CCM, BSIMM, SAMM, Octave Allegro, ISO 31000, NIST-800-30, 800-15, 800-63, 800-57, 800-52 R1, OWASP, SANS, PCI-DSS, HIPAA, BCRA 4609, GDPR). Fields of Specialisation: Financial Services, Telecommunication, Petrol & Gas, Public Bodies (Governments), HealthCare Sector, Aerospace, Retail, Agriculture, Software Factories, Logistic, and Education. #CYBERSECURITY CERTIFICATIONS: CEH MASTER, OSWE, OSWP, CompTIA Pentest +, CASP+ eWPTX, eWPT, eJPT, ISO 27001 Internal Auditor, AWS CP, DevSecOps Professional Certified, BlockChain Security Expert. Also, I have other certifications about other cybersecurity fields (blockchain security, Linux, Networking, Malware Development, Secure Development, etc.) ON TRACK > PNPT, CASP +, AWS SAA and Security, CASE JAVA, API Security. Additional info: I am part of the CompTIA Partnership program and EC-Council mentorship. I partipate actively in BugBounty programs and Hacker competitions.
Certifications
C1 Advanced
C1 Advanced, B2 Upper Intermediate, B1 Intermediate
10/07/2021
Tech stack
B2 Upper Intermediate
C1 Advanced
B1 Intermediate
Testing (8)
Mobile (3)
Web (3)
Security (3)
SQL (2)
Application security (2)
Security Testing (1)
Management (1)
IT Security (1)
Apps (1)
APIs (1)
Angular (1)
Kubernetes (1)
Docker (1)
Amazon (1)
Jenkins (1)
HTML (1)
Continuous Integration (CI) (1)
Bootstrap (1)
Java (1)
CSS (1)
AWS Cloud Architecture (1)
Cyber Security (1)
DevOps (1)
PHP (1)
API Development (1)
Django REST Framework (1)
Experience
Security and Digital Forensics SpecialistFreelance
05/2017 - Currently

Security: Vulnerability Assessment and Penetration Testing (VAPT -- MASPT) across different environments (mobile, web, API, microservices, cloud, infrastructure, wifi, social engineering, etc.). Ethical Phishing Campaigns Human Hacking Devices/Gadgets (Physical Red Teaming) OSINT - Public Exposure Reports on the web (including dark web and deep web) Denial of Services (Stress Testing) Ethical Hacking Technical Collaboration in Criminal Investigations Training / Webinars Digital Forensics: Participate as an Assistant to the Expert Witness/Complainant in expert evidence. Audit the expert examination processes with the court-appointed experts. Ensure proper handling of digital evidence. Extraction of evidence from powered-off and powered-on electronic devices (cold and hot data). Physical and logical copies of digital information stored on different equipment and electronic devices.

Testing
Application Security Engineer Technical LeadABN AMRO CLEARING BANK
01/2024 - Currently

Implementation of a Secure Software Development framework based on CMMI and NIST CSF, best security practices and methodologies. Perform Design and Code Reviews, perform security audits, Threat Models, and advise on the implementation of security testing in CI/CD pipelines (shift-left security). Create and manage the Security Champions Program. Manage security projects globally. Create and maintain security guidelines, procedures and protocols. Collaborate with monitoring networks and systems for intrusions.

Application security
Security Testing
Continuous Integration (CI)
Management
Sr. Application Security EngineerPayconiq International
01/2023 - 08/2023

Leading security champion program across engineering teams. Conducting various security assessments and threat modeling. Collaborating with compliance for audit automation. Guiding DevSecOps strategy and Security Champions. Establishing and maintaining security protocols. Monitoring networks for intrusions, investigating incidents. Performing regular penetration testing. Fostering Zero Trust culture. Enhancing security in CI/CD pipelines. Integrating app security tools. Creating awareness content, conducting workshops. Addressing vulnerabilities, vendor engagement. Identifying threats through modeling and assessment.

Management
Security
Sr. DevSecOps EngineerZivver
08/2022 - 01/2023

Develops security processes and solutions for production and non-production environments. Collaborates with compliance for automated audit evidence collection and maintains security protocols. Identifies/responds to incidents, conducts pre-production tests, and reviews code for best practices. Cultivates a culture of security and zero trust in engineering. Enhances CI/CD pipeline security with open-source tools, integrates security workflows. Leads workshops, aids security decisions, manages HackerOne program. Supports audit evidence collection, outsourcing audits, and evaluates tools. Utilizes threat modeling and STRIDE framework effectively.

Application security
DevOps
AWS Cloud Architecture
Cyber Security
Sr. Cybersecurity EngineerPomelo
01/2022 - 08/2022

Penetration testing on Web Applications, Mobile, Infrastructure, Containers, API, and Cloud (different scopes - external and internal) (DAST - SAST - RASP - IAST). Security code review (WhiteBox, GreyBox and BlackBox assessments) Implementation of Shift Left Security, and Bottom-to-Top concepts Threat modelling (STRIDE & VAST) Technical participation in RFCs, and briefings Vulnerability management and risk analysis Definition of security requirements (MASVS - ASVS) Documentation of processes, and definition of best practice guidelines. Vulnerability management Network team operations (social engineering - insider threat simulator - OSINT - malware outbreak) Reporting and report writing Security awareness (security pills and workshops) MicroManagement

Web
Mobile
Security
Sr. Application Security EngineerKavak.com
09/2021 - 01/2022

Conduct penetration testing on web, mobile apps, infrastructure, containers, APIs, and cloud environments, covering various scopes (external and internal). Participate in technical aspects of RFCs and debriefings. Develop technical exams for cybersecurity position recruitment and engage in the selection process. Perform Security Code Review (WhiteBox & BlackBox assessments). Implement Shift Left Security and Bottom-to-Top concepts. Conduct Threat Modeling (STRIDE & VAST). Manage vulnerabilities and risk analysis. Define security requirements (MASVS - ASVS). Compose and draft reports. Promote Security Awareness (creating educational content based on the OWASP TOP 10).

Web
Mobile
Security
Technical Leader - Social Engineer PentesterDreamlab Technologies
05/2021 - 09/2021

Configure HID devices for physical intrusions. Analyze vulnerabilities associated with human vectors. Perform information gathering. Design awareness talks on social engineering-related topics. Craft campaigns (webpage creation and design, pretexts, scripts). Conduct open-source intelligence analysis (OSINT, GEOINT, SOCMINT). Execute large-scale phishing and smishing tests. Automate and design scripts (Python and Bash). Manage teams and propose improvements. Collaborate with other areas - forensics (Special Ops, RED TEAM).

API Development
Django REST Framework
Flask
Linux
Application security
Social Media
Application Security EngineerNaranja X
09/2020 - 04/2021

Penetration testing on Web and Mobile Applications and Infrastructure, Containers and Cloud. Documentation and vulnerability tracking. RFC analysis. Preparation and drafting of reports (metrics - security maturity test). DAST - SAST - RASP - IAST Cloud Security Infrastructure Reviews. CI/CD automation on IT security tools (Bitrise & Gitlab). Security Awareness (making videos on youtube and writing articles on Medium.com) and Workshops. Red Team Operations.

Amazon
Security
Mobile
Security Testing
Web
IT Security
Kubernetes
Docker
Consultor Senior - Seguridad InformaticaKPMG Argentina
02/2020 - 11/2020

Conduct penetration testing on Mobile Apps, Web Apps, Web Servers, APIs, and Infrastructure (SAST, DAST, IAST). Direct project management with clients. Document and compile technical reports following international cybersecurity standards (NIST 800-53, OWASP TOP 10, CERT C, ISO 27001, SANS TOP 25). Provide corporate training on cybersecurity topics and tools to client companies. Perform intrusion tests on OnPrem infrastructures, hybrid environments, and multicloud settings. Execute external and internal intrusion tests. Conduct intrusion tests on Web/Mobile applications. Develop scalable testing strategies. Create security tools to automate complex tasks.

Web
Mobile
APIs
Apps
Security AnalystANMaC Ex RENAR (Registro Nacional de Armas)
12/2019 - 03/2020

Conduct penetration testing on Mobile Apps, Web Apps, Web Servers, APIs, and Infrastructure (SAST, DAST, IAST). Direct project management with clients. Document and compile technical reports following international cybersecurity standards (NIST 800-53, OWASP TOP 10, CERT C, ISO 27001, SANS TOP 25). Provide corporate training on cybersecurity topics and tools to client companies. Perform intrusion tests on OnPrem infrastructures, hybrid environments, and multicloud settings. Execute external and internal intrusion tests. Conduct intrusion tests on Web/Mobile applications. Develop scalable testing strategies. Create security tools to automate complex tasks. Assist in secure web application development. Implement computer security and conduct vulnerability analyses. Survey assets and infrastructure. Design security policies. Conduct occasional penetration tests.

IT Security
Angular
Python
Consultor - Seguridad InformáticaSecretaría de Innovación Pública
08/2019 - 01/2020

Collaborate with the development team to establish standards. Ensure the production and development of secure software through the use of SAST and DAST tools (SonarQube, Jenkins, Snyk, AppScan, OWASP ZAP, etc.) and manual source code analysis. Contribute to the Secure-SDLC. Raise awareness and promote the SecDevOps culture. Technology stack: Java, JavaScript, PHP, SQL Server. HTML, CSS, JS (Angular), Bootstrap, SASS. Power BI. Open Source Ticketing & Remedy.

PHP
SQL
Java
HTML
Angular
CSS
Jenkins
Bootstrap
Internal AuditorGobierno de la Ciudad de Buenos Aires
01/2017 - 01/2018

In charge of police mobile support, and budget. Drafting and preparation of documents and administrative management processes. (ITIL + ISOS) Database administration.

SQL
Education
Diploma in Secure Software DevelopmentUniversidad del Norte 'Santo Tomás de Aquino'
08/2023 - 12/2023
Diploma in Industrial Cybersecurity (ICS/OT)Universidad del Norte 'Santo Tomás de Aquino'
02/2023 - 02/2023
Tecnicatura en Soporte de InfraestructurasISTEA
02/2021 - 02/1990
Master in Cybersecurity Management, Ethical Hacking and Offensive SecurityEIP International Business School
02/2021 - 02/2023
LINUX SYSTEM ENGINEER CLA Instituto Linux
02/2019 - 02/2020
Ethical Hacking ExpertCLA Instituto Linux
02/2019 - 02/2020
Diploma of Digital Crime and Forensic Digital.UAI - Universidad Abierta Interamericana
01/2017 - 01/2018
LawyerUADE
01/2017 - 01/2022
Cybersecurity ArchitectEducacionIT
02/2016 - 02/2018