Building secure systems, cybersecurity tooling, AI-powered defensive solutions, and cloud-native applications.
πͺπ¨ Quito, Ecuador
I'm a Computer Science Engineer focused on Cybersecurity, AI Security, DevSecOps, and Full-Stack Engineering.
- π‘οΈ Building offensive & defensive security tooling with the goal of becoming a Purple Team Engineer
- π€ Exploring AI-powered cybersecurity, deception technologies, honeypots, attack detection, and threat intelligence
- π Interested in ethical hacking, application security, network security, detection engineering, and secure software architecture
- βοΈ Experience deploying and securing applications using Docker, AWS, Azure, Linux, reverse proxies, and cloud infrastructure
- π» Building production-oriented applications with TypeScript, React, Next.js, Node.js, PostgreSQL, and REST APIs
- π Computer Science Engineer from Universidad San Francisco de Quito (USFQ), Dean's List, with a focus on Data Science
- π Collaborating with BethaLabs on cybersecurity, software engineering, infrastructure, hosting, and secure deployments
- π― Long-term goal: work at the intersection of Red Team + Blue Team + AI Security
I like breaking systems to understand how they work β and rebuilding them stronger.
A distributed cybersecurity research platform designed to capture, analyze, correlate, and classify malicious activity across multiple protocols.
The platform combines traditional honeypots with AI-assisted deception and centralized threat analysis.
- Captures malicious SSH, HTTP, FTP, MySQL, SMB, MSSQL, MQTT, TFTP and port-scanning activity
- Uses customized Cowrie environments to emulate realistic Linux targets
- Integrates Galah, an LLM-powered HTTP honeypot capable of dynamically generating realistic responses
- Uses Dionaea for multi-protocol attack collection
- Performs cross-protocol attack correlation
- Calculates risk scores per attacker/IP
- Detects automated/bot activity
- Performs automated AI-assisted session classification
- Sends high-risk threat alerts through Discord webhooks
- Tracks distributed sensors using heartbeat/beacon services
- Provides attacker, campaign, sensor and threat visualization through a central dashboard
Attackers
β
βββ SSH ββββββ> Cowrie
βββ HTTP βββββ> Web Honeypot / Galah AI
βββ FTP ββββββ> FTP Honeypot
βββ MySQL ββββ> MySQL Honeypot
βββ Scans ββββ> Port Sensors
βββ Network ββ> Dionaea
β
βΌ
Vector / Shippers
β
βΌ
Central Ingest API
β
βββββββββββ΄ββββββββββ
β β
Threat Analysis PostgreSQL
Risk Scoring β
Bot Detection βΌ
AI Classification Dashboard
β
βββββββββββ> Discord Alerts
TypeScript Β· Next.js Β· Fastify Β· PostgreSQL Β· Prisma Β· Docker Β· Cowrie Β· Galah Β· Dionaea Β· Vector Β· Python Β· Linux Β· Caddy
Honeypots Β· Threat Intelligence Β· Deception Technology Β· Network Security Β· Detection Engineering Β· Attack Correlation Β· Risk Scoring Β· AI Security Β· SOC Automation
A production-oriented personal finance platform developed to manage expenses, recurring payments, budgets, and financial analytics.
- Multi-user authentication
- Monthly category-based budgeting
- Automated recurring expenses
- Daily and monthly scheduled jobs
- Expense analytics and visualization
- Responsive application architecture
- PostgreSQL-backed persistence
Next.js 15 Β· TypeScript Β· Supabase Β· PostgreSQL Β· NextAuth.js Β· Tailwind CSS Β· shadcn/ui Β· Vercel Cron
Full-stack hotel management platform designed with a separated frontend/backend architecture and containerized deployment.
Worked on areas including:
- API architecture
- Authentication and authorization
- Secure deployment
- Containerization
- Cloud infrastructure
- Frontend/backend integration
- Production hosting and environment configuration
Built as part of my work and experimentation with BethaLabs.
I also experiment with AI-powered productivity and automation tools, including:
Content generation and automation platform built with TypeScript.
AI-assisted notes and knowledge workflow experimentation.
Automation experiments around programmatic video workflows.
Platform focused on CV/resume workflows and modern web application architecture.
- Purple Teaming
- Penetration Testing
- Detection Engineering
- Threat Intelligence
- AI Security
- Honeypots & Deception Technology
- Network Security
- Web Application Security
- Cloud Security
- DevSecOps
- Security Automation
Cowrie Β· Dionaea Β· Galah Β· Vector Β· Nmap Β· Metasploit Β· Burp Suite Β· Wireshark
- βοΈ Microsoft Certified: Azure Fundamentals β AZ-900
- π Microsoft Certified: Security, Compliance & Identity Fundamentals β SC-900
- π‘οΈ Palo Alto Networks β Security Operations Fundamentals
- βοΈ Metasploit Penetration Testing
- π Cisco β Cyber Threat Management
Red Team ββββββββββ Offensive Security
Blue Team ββββββββββ Detection & Defense
AI Security ββββββββββ AI-assisted security tooling
DevSecOps ββββββββββ Secure infrastructure & deployments
Cloud ββββββββββ AWS / Azure / Containers
I'm currently especially interested in:
Purple Teaming Β· AI Security Β· Threat Detection Β· Honeypots Β· Security Automation Β· Cloud Security
Open to cybersecurity, Purple Team, AI Security, DevSecOps and security engineering opportunities.

