ruben@secops:~$ whoami
I break things on purpose so they don't break for real. CEHv11-certified, with 3+ years spent moving between the attacker's seat and the defender's — pentesting web, mobile and network targets by day, and picking apart how AI systems fail by night. I like the moment a "secure" system turns out not to be, and I like explaining why in a way a developer can actually act on. Off the clock, I'm usually organizing something for IEEE or arguing that the internet needs more cyber hygiene awareness, not less.
ruben@secops:~$ cat focus.log
Web, API, mobile and network penetration testing end to end — plus secure code review, IAST, DAST and SCA across the SDLC so findings get fixed, not just filed.
Probing LLM-backed apps and AI pipelines for prompt injection, data leakage and the new class of failure modes that traditional AppSec testing misses.
Cloud configuration reviews and cloud security testing to catch misconfigurations and excess privilege before attackers do.
Embedding security operations and compliance checks into CI/CD pipelines, so secure practices scale with the team instead of bottlenecking it.
Digging into emerging attack techniques, writing up findings, and contributing to the wider community through IEEE and Cyberdome.
ruben@secops:~$ cat experience.log
ruben@secops:~$ ls skills/
ruben@secops:~$ cat education.log volunteering.log
ruben@secops:~$ mail --contact
ruben@secops:~$