Cybersecurity Engineer · ISO/IEC 27001:2022 Internal Auditor

Your company is already exposed.

What matters is who finds out first.

Cybersecurity, ISO 27001 audits, secure development and cloud for companies that cannot afford a breach. A certified engineer, not a template.

30+sites and systems delivered
4countries with projects executed
ISO 27001certified internal auditor
OWASPsecure development certified
What I do for you

Services that protect and build

Every engagement starts with an assessment and ends with a deliverable your team can actually act on. No technical smoke.

Enterprise cybersecurity

Risk analysis, hardening, policy and incident response for companies that can no longer afford to improvise.

From $350 USD View details

ISO/IEC 27001 audits & consulting

From gap analysis to the pre-certification internal audit, with an ISMS that is documented and actually working.

From $3,000 USD View details

Pentesting & web security audit

Ethical penetration testing on web apps, APIs and infrastructure, with reproducible evidence and CVSS scoring.

From $1,000 USD View details

Websites & landing pages that sell

From a conversion landing page to a multilingual corporate site — with technical SEO, performance and security headers from day one.

From $250 USD View details

Custom-built applications

Internal platforms, portals and management systems built secure by design: encrypted data, roles, audit trails and backups.

From $900 USD View details

Cloud infrastructure & security

I build, migrate and secure your cloud infrastructure: IAM, VPC, firewalls, VPN, encryption and monitoring — with costs under control.

From $120 USD View details
Why work with me

The one who audits and the one who operates

Most consultants only audit. I also run servers, networks and production systems every day — which is why my recommendations can be applied on Monday.

Verifiable credentials

Cybersecurity Engineering degree with Highest Distinction, recognised in Colombia, plus a current ISO/IEC 27001:2022 Internal Auditor certification.

Experience across four countries

Projects delivered for companies in Colombia, Chile, Spain and the United States, across sectors from logistics to education.

Applied security, not theory

I administer production infrastructure daily. I know what a badly implemented control breaks because I have had to keep it running.

Deliverables people use

An executive report for leadership, a technical report for IT, and a remediation sheet with owners and dates. No 200-page PDF nobody reads.

Your data stays yours

The systems I build can be deployed on your own infrastructure. If you do not want your information living in someone else’s cloud, it will not.

You talk to me

No account executive in between. The person who quotes the project is the person who delivers it.

How I work

Four steps, zero surprises

01

Initial assessment

A 30-minute call to understand your operation, your real risks and how far the scope goes. At no cost.

02

Analysis and proposal

Technical evaluation, vulnerability identification and a proposal with fixed scope, timeline and price.

03

Execution

Audit, pentest, implementation or development, with progress reports and no surprises on the invoice.

04

Delivery and follow-up

Reports, team training and post-project support to verify the remediation actually holds.

Professional profile

Backed by verifiable credentials

Cybersecurity Engineer, graduated with Highest Distinction, and a certified ISO/IEC 27001:2022 Internal Auditor. I work in information security inside an ISO 27001-certified logistics and BPO company, and in parallel I administer IT infrastructure for a school network in Chile. That double role — the one who audits and the one who operates — is what makes my recommendations applicable rather than theoretical.

Cybersecurity Engineer

Instituto Profesional AIEP · Universidad Andrés Bello · 2023

Approved unanimously with Highest Distinction

ISO/IEC 27001:2022 Internal Auditor

Global Colombia Certificación · August 2026

ISO 27001ISO 19011SGSI

Secure application development — OWASP

Rheoli University, Chile · July – August 2026

OWASP Top 10ASVSSecure coding
InnDiTec Academy

Learn what I actually apply

Hands-on courses built from real projects, not from a copied syllabus.

Intensive course

Centralised monitoring with Grafana and Prometheus from scratch

Learn to build it — then learn to sell it as a premium service.

  • Deploy a professional monitoring system from scratch
  • Master Prometheus for metric collection
  • Build dashboards that actually impress
  • Configure smart, proactive alerting
8 modules 2 – 3 hours of content Certificate included Lifetime access
Launch price
$27 USD
$115.000 COP
$49 USD −45%
Enrol now
7-day guarantee
Secure payment
Direct support
Own product

Software for automotive upholstery shops

A management system that quotes, schedules, invoices and answers customers on WhatsApp 24 hours a day. It installs on the workshop computer and the data never leaves it.

Cotizador Agenda Cartera Contabilidad CRM de WhatsApp
Control panel of the InnDiTec management system for automotive upholstery workshops
Delivered work

Projects already live

La
Digital marketing

Latina Leads

Lead generation and digital marketing platform focused on the Latin American market. Professional design optimised for conversion.

MarketingLead Generation
Visit site
SI
Corporate

SIP — Red de Colegios

A recognised school network in Chile and a Google partner. IT infrastructure administration, Google Cloud servers, IP telephony and WordPress hosting.

InstitucionalGoogle Cloud
Visit site
In
Corporate

InnDiTec

Corporate cybersecurity portal with a web audit management system (SISE) and an integrated course academy.

CiberseguridadCloud
Visit site

Frequently asked questions

How much does an audit cost?
A web audit starts at USD 350 and a full pentest at USD 1,000. The final price depends on the size of your infrastructure and the agreed scope. The initial 30-minute assessment is always free.
Do you work with companies outside Colombia?
Yes. I have delivered projects for companies in Chile, Spain and the United States. Work is remote unless the scope requires physical presence, and I invoice in USD or COP as suits you.
Do you sign a confidentiality agreement?
Always. Before accessing any system we sign an NDA and a scope authorisation document. It is part of the method, not an extra.
How long does an ISO 27001 implementation take?
Between 3 and 6 months depending on the size of the organisation and the ISMS scope. It can be narrowed to a single critical process if that is what your clients require you to certify.
Do you offer maintenance after the project?
Yes, with monthly support and monitoring plans. I can also train your team to run it in-house, which usually works out cheaper long term.
Free assessment

What if the problem is already inside?

The first review is free: 30 minutes, no commitment, and you leave with at least three concrete findings about your operation.

No cost · No commitment · Reply within 24 business hours