Security Consultant - VAPT at RedLegg Managed Cybersecurity Services (2024-10 – Present)
- Conducted black-box and grey-box assessments against external web apps and network infrastructure for US enterprise clients, leveraging a combination of proprietary and open source tools such as Burpsuite Pro and the entire Kali Linux suite.
- Manually validated exploit chains beyond automated scanner output, delivering CVSS-scored reports with prioritized remediation guidance tailored to each client's risk tolerance using Plextrac.
Adjunct Faculty - Part Time at University of Santo Tomas - CICS (2023-10 – Present)
- Facilitated advanced cybersecurity coursework through Canvas to an average of 80+ students per semester, translating complex concepts in ethical hacking and vulnerability assessment into actionable skills for the next generation of security professionals as well as achieving a constant passing rate of >50% on entry-level security certification exams.
Information Security - Red Team at Citco International Support Services (2023-04 – 2024-09)
- Executed comprehensive penetration tests on internal applications and infrastructure using Burpsuite Pro; neutralized high-impact threats by providing actionable remediation guidance to cross-functional engineering teams.
Penetration Testing Lead at Secuna Software Technologies (2022-10 – 2023-04)
- Spearheaded penetration testing operations for a team of five, streamlining project workflows and ensuring 100% compliance with organizational standards across diverse industry sectors and acting as the interface between management and external client.
Penetration Tester at Secuna Software Technologies (2022-03 – 2022-10)
- Identified and documented high-priority security flaws for a diverse portfolio of clients, contributing to the production of technical reports that mitigated significant cyber risks.
Cyber Defense Analyst at Australia New Zealand Banking Group (2021-05 – 2022-03)
- Performed continuous security monitoring, threat detection, and incident investigation and utilized threat intelligence to analyze and mitigate threats affecting the organization's banking system.
Intermediate Security Analyst at Ceva Logistics/CMA-CGM Group (2020-09 – 2021-04)
- Collaborated with SIEM onboarding and integration activities for enterprise applications, servers, network devices, and cloud services to support incident investigations, and strengthen the organization's cybersecurity posture.
SOC Analyst at Red Rock IT Security (2019-04 – 2020-09)
- Leveraged SIEM, EDR, and threat intelligence tools to detect and respond to cyber threats, while providing timely escalation and remediation recommendations across multiple client environments.
Information Security Analyst at Voyager Innovations/Maya PH (2017-09 – 2019-03)
- Conducted security monitoring and incident response across the fintech infrastructure. Ensured compliance with financial security standards (PCI DSS) while strengthening detection rules, alerting mechanisms, and overall cybersecurity resilience.