EN ES

Senior Security Engineer · LATAM

Detection engineering at the speed of attack.

Six years cutting noise, response time, and manual ops in 24/7 MSSP environments. Splunk, CrowdStrike, AWS — and a 25-analyst SOC that triages itself.

About

Building detection that scales — not noise.

Senior Security Engineer with 6+ years designing, optimizing, and scaling detection and response in MSSP environments across Latin America.

I've shipped SIEM architecture (Splunk, Exabeam), EDR integrations (CrowdStrike, Defender), AWS/Azure security posture, and Python/Terraform/SOAR automation that runs in production every day.

Today I lead 25 analysts across Panama and Colombia. 24/7 coverage for 50+ enterprise clients. 30,000+ alerts triaged every month.

30%
False-positive reduction
80%
Cloud assessment efficiency gain
25
SOC analysts led
50+
Enterprise clients covered

Experience

From inspector to leading a 25-analyst SOC.

A non-linear path. Each role compounded into the next.

  1. SOC Team Leader

    Sofistic Cybersecurity (a Cuatroochenta company)

    • Lead 25 SOC analysts across Panama and Colombia, 24/7 coverage for 50+ enterprise clients.
    • Process 30,000+ alerts monthly. Designed agentic AI SOC: noise –30%, triage time –20%.
    • Led 10+ DFIR investigations for enterprise clients.
    • Owns SLAs, false-positive reduction, MTTR improvement, and Tier-1/Tier-2 capability building.
  2. Tech Leader

    Sofistic Cybersecurity

    • Led 8-person technical team for managed security services across 30+ clients.
    • Optimized NDR / EDR / SIEM tooling — improved client detection and response posture.
    • Defined certification roadmap and technical training plan.
  3. Cyber Security Analyst

    Sofistic Cybersecurity

    • Pentested web apps, network infrastructure and Wi-Fi for enterprise clients.
    • Designed and executed 30+ phishing and social engineering simulations.
    • Identified critical vulnerabilities; applied OWASP, PTES and NIST.
    • SOC Tier-1/Tier-2 monitoring and initial incident response.
  4. Intern

    Sofistic Cybersecurity

    • Splunk fundamentals and onboarding to MSSP detection workflows.
  5. Inspector

    Ministerio de Trabajo y Desarrollo Laboral

    • Pre-cybersecurity track. Government inspection role.

Tooling & capabilities

Stack — battle-tested in MSSP at scale.

SIEM & Detection

  • Splunk
  • Exabeam
  • Microsoft Sentinel
  • Detection Engineering
  • MITRE ATT&CK

EDR / NDR / Threat Hunting

  • CrowdStrike Falcon
  • Microsoft Defender
  • Darktrace
  • Threat Hunting
  • CTI

Cloud Security

  • AWS Security
  • Azure Security
  • IAM hardening
  • Cloud posture management

Automation & Engineering

  • Python
  • Terraform
  • SOAR (Tines / FlexSOAR)
  • Agentic AI workflows
  • Webhooks / API integration

Incident Response

  • DFIR
  • Playbook design
  • Forensic analysis
  • Post-incident review

Offensive (foundational)

  • Web pentesting (OWASP)
  • Network pentesting (PTES, NIST)
  • Phishing simulation
  • Wi-Fi security

Certifications · 43+

Forty-five and counting.

Cloud, detection, offensive — vendors that ship the tools I run in production every day.

  • AWS
    AWS Certified AI Practitioner
    2026
  • AWS
    AWS Certified Cloud Practitioner
    2022
  • CrowdStrike
    CCSE — CrowdStrike SIEM Engineer
    2026
  • CrowdStrike
    CCFH — Falcon Hunter
    2024
  • CrowdStrike
    CCFA — Falcon Administrator
    2023
  • Splunk
    Splunk Enterprise Certified Admin
    2024
  • Splunk
    Splunk Core Certified Power User
    2021
  • TryHackMe
    Cyber Security 101 (SEC1)
    2026
  • ISC2
    Certified in Cybersecurity (CC)
    2023
  • Hack The Box
    HTB Certified Junior Cybersecurity Associate
    2025
  • Hack The Box
    HTB Certified Defensive Security Analyst
    2025
  • INE
    Web Application Penetration Tester
    2025
  • CompTIA
    CompTIA Cloud+
    2025
  • CompTIA
    CompTIA CSCP Stackable
    2025
  • Darktrace
    Darktrace Threat Visualizer Essentials
    2025
  • TCM Security
    Practical Junior Penetration Tester
    2025
  • INE
    INE Certified Cloud Associate
    2025
  • INE
    Junior Penetration Tester
    2025
  • Mastermind
    ISO/IEC 27001:2022 Lead Auditor
    2025
  • CyberWarFare Labs
    Certified Red Team Analyst (CRTA)
    2025
  • CompTIA
    CompTIA Cloud Essentials+
    2025
  • arcX
    Foundation Threat Intelligence Analyst
    2025
  • CompTIA
    CompTIA CySA+
    2025
  • CompTIA
    CompTIA CSAP Stackable
    2025
  • CompTIA
    CompTIA CNSP Stackable
    2025
  • CompTIA
    CompTIA CNVP Stackable
    2025
  • CompTIA
    CompTIA PenTest+
    2025
  • CertiProf
    Cybersecurity Awareness Learner
    2024
  • CompTIA
    CompTIA Security+
    2024
  • INE
    Certified Incident Responder
    2024
  • EC-Council
    Certified SOC Analyst
    2023
  • Microsoft
    Microsoft 365 Fundamentals
    2023
  • Microsoft
    Azure AI Fundamentals
    2023
  • INE
    eCPPT
    2023
  • Microsoft
    Azure Fundamentals
    2021
  • Microsoft
    Microsoft SC-900
    2022
  • Darktrace
    Darktrace Cyber Engineer
    2024
  • EC-Council
    CEH Master
    2021
  • EC-Council
    CEH (Practical)
    2021
  • EC-Council
    Certified Ethical Hacker
    2024
  • INE Security
    eJPT
    2020
  • CertiProf
    Scrum Foundations (SFPC)
    2020
  • Exabeam
    Exabeam Community CTF Winner
    2024

Education

Foundations.

  • 2014 — 2018

    Engineering — Information & Systems Security

    Universidad del Istmo, Panama

  • 2018 — 2019

    Teaching Diploma — Diversified Secondary Education, Cybersecurity emphasis

    Universidad Autónoma de Chiriquí

Speaking

On stage.

  • 802.11 Surface Attacks and WPA2 Automation

    Jan 2021

    BSides Panama

    Wi-Fi attack surface, automated WPA2 cracking, AI-assisted handshake analysis. Volunteer talk.

Contact

Hire me, talk, or trade attack chains.

Open to senior detection engineering, cloud security, and security automation roles in remote global teams.

© 2026 Julio Espinosa · darkreitor

cv.darkreitor.xyz