whoami

Open to opportunitiesAbierto a oportunidades

Carlos Cabrera

Information Security Specialist

Cyber Incident Response Specialist & Information Security Specialist — finding, documenting, and neutralizing threats across industrial, legal, medical, educational, and banking environments across the United States.Especialista en Respuesta a Incidentes y Especialista en Seguridad de la Información — detecto, documento y neutralizo amenazas en entornos industriales, legales, médicos, educativos y bancarios en los Estados Unidos.

  • Fully bilingual — EN / ESTotalmente bilingüe — EN / ES
  • Open to hands-on security rolesAbierto a roles técnicos de seguridad
Carlos Cabrera

# Professional SummaryResumen Profesional

Information Security Specialist with deep experience across cybersecurity and information-systems management & administration. I've been trusted to secure clients in the industrial, legal, medical, educational, and banking industries throughout Puerto Rico and the United States — finding, documenting, analyzing, and delivering technical solutions while building secure, trusted business relationships.Especialista en Seguridad de la Información con amplia experiencia en ciberseguridad y en la gestión y administración de sistemas de información. He sido la persona de confianza para proteger a clientes de las industrias industrial, legal, médica, educativa y bancaria en todo Puerto Rico y los Estados Unidos — detectando, documentando, analizando y entregando soluciones técnicas mientras construyo relaciones de negocio seguras y de confianza.

I help clients respond to incidents by discovering, reinforcing, and eliminating security risk, and I deliver clear, actionable remediation plans. Increasingly, I augment incident response and threat hunting with local LLMs and agentic automation — Ollama, the Claude API, and n8n — building private tooling that speeds up triage, enrichment, and reporting. I'm currently looking for a challenging, hands-on cybersecurity role to complement my career path.Ayudo a los clientes a responder ante incidentes descubriendo, reforzando y eliminando el riesgo de seguridad, y entrego planes de remediación claros y accionables. Cada vez más complemento la respuesta a incidentes y la caza de amenazas con LLMs locales y automatización con agentes — Ollama, la API de Claude y n8n — construyendo herramientas propias que aceleran el triaje, el enriquecimiento y la reportería. Actualmente busco un rol técnico y retador en ciberseguridad que complemente mi trayectoria profesional.

10+Years in security & ITAños en seguridad e IT
5Industries securedIndustrias protegidas
7Industry certificationsCertificaciones

# Technical SkillsHabilidades Técnicas

LanguagesLenguajes

BashPythonPowerShellPHPHTML

Security & DetectionSeguridad y Detección

Incident ResponseThreat HuntingSOC / NOCPenetration TestingVulnerability MgmtMalware SandboxingPhishing Analysis

AI & Security AutomationIA y Automatización de Seguridad

OllamaLocal LLMsClaude / Anthropic APIRAGMCPn8nopencodeOpenClawObsidian

Frameworks & StandardsMarcos y Estándares

MITRE ATT&CKNISTFINRAHIPAASOC 2

Firewalls

Palo AltoFortiGateCisco MerakipfSense

Endpoint / AVEndpoint / Antivirus

Trellix ePO (ex-McAfee)Sophos CentralPalo Alto TRAPSMicrosoft DefenderESET

SIEM & LoggingSIEM y Registros

Elastic (ELK Stack)ElasticsearchLogstashKibanaWazuhGraylogNX-LogTenable.ioSecurity CenterKnowBe4ProofPoint

PlatformsPlataformas

WindowsLinuxUnixFreeBSD

Virtualization & CloudVirtualización y Nube

VMware ESXiProxmoxHyper-VCitrixXenAzureAWSDigitalOcean

Infrastructure & DataInfraestructura y Datos

Active DirectorySystem CenterWSUSTSQLMySQLSQLiteIISApacheNGINX

Backup / DRRespaldo / DR

VeeamIperiusDruvaEaseUS

# Work ExperienceExperiencia Laboral

Cyber Incident Response SpecialistEspecialista en Respuesta a Incidentes Cibernéticos

Evertec · HybridHíbrido

Jun 2024 — PresentPresente
  • Receive and investigate incident reports from internal stakeholders; conduct root-cause analysis.Recibo e investigo reportes de incidentes de las partes internas; realizo análisis de causa raíz.
  • Develop and execute containment, eradication, and recovery strategies across cross-functional teams.Desarrollo y ejecuto estrategias de contención, erradicación y recuperación junto a equipos multidisciplinarios.
  • Threat hunting with threat-intelligence and advanced analytics to proactively surface emerging threats and attack vectors.Caza de amenazas con inteligencia de amenazas y analítica avanzada para descubrir proactivamente amenazas emergentes y vectores de ataque.
  • Run vulnerability assessments and penetration testing to identify weaknesses.Ejecuto evaluaciones de vulnerabilidades y pruebas de penetración para identificar debilidades.
  • Ensure adherence to industry standards and regulatory requirements (NIST, FINRA); maintain detailed incident records.Aseguro el cumplimiento de estándares de la industria y requisitos regulatorios (NIST, FINRA); mantengo registros detallados de incidentes.

Information Security SpecialistEspecialista en Seguridad de la Información

TeleMedik · HybridHíbrido

Jun 2021 — Jul 2024
  • Own and maintain the organization's information-security framework — policies, procedures, standards, and guidelines — alongside the IT Director.Mantengo el marco de seguridad de la información de la organización — políticas, procedimientos, estándares y guías — junto al Director de TI.
  • Lead the information-security strategy and report security gaps, strategies, and results to the Compliance Committee.Lidero la estrategia de seguridad de la información y reporto brechas, estrategias y resultados al Comité de Cumplimiento.
  • Ensure administrative, physical, and technical safeguards protect security assets from internal and external threats; test them regularly.Aseguro que las salvaguardas administrativas, físicas y técnicas protejan los activos de seguridad ante amenazas internas y externas; las pruebo regularmente.
  • Own the security-incident and vulnerability-management processes end to end; run security monitoring and annual audits.Gestiono de extremo a extremo los procesos de incidentes de seguridad y de gestión de vulnerabilidades; ejecuto monitoreo de seguridad y auditorías anuales.
  • Ensure compliance with state and federal healthcare regulations, including HIPAA.Aseguro el cumplimiento de regulaciones de salud estatales y federales, incluyendo HIPAA.

Information Security Analyst IIAnalista de Seguridad de la Información II

Cortelco Systems

Jul 2018 — Jun 2021
  • Delivered managed security services (MSP) across industries — SOC/NOC development, provisioning, and log analytics.Brindé servicios de seguridad administrados (MSP) en múltiples industrias — desarrollo de SOC/NOC, aprovisionamiento y analítica de registros.
  • Firewall management: rule creation, hardening, reporting, and Python API development for custom reports.Gestión de firewalls: creación de reglas, hardening, reportería y desarrollo de APIs en Python para reportes personalizados.
  • Trellix ePO (formerly McAfee ePO), EndPoint, and SIEM management; ProofPoint Secure Email Gateway, phishing, and malware analysis.Gestión de Trellix ePO (antes McAfee ePO), EndPoint y SIEM; ProofPoint Secure Email Gateway, análisis de phishing y malware.
  • Built Graylog / NX-Log collectors and regex-driven dashboards to correlate events and identify threats.Construí colectores Graylog / NX-Log y dashboards basados en regex para correlacionar eventos e identificar amenazas.
  • Vulnerability scanning via Tenable.io and Security Center; phishing-awareness training with KnowBe4.Escaneo de vulnerabilidades con Tenable.io y Security Center; capacitación de concientización sobre phishing con KnowBe4.
  • Performed scheduled penetration testing and delivered remediation reports on misconfigurations, risk, and data exposure.Realicé pruebas de penetración programadas y entregué reportes de remediación sobre configuraciones erróneas, riesgo y exposición de datos.

Information Security TechnicianTécnico de Seguridad de la Información

Computer Pro

Jun 2017 — Jun 2018
  • Supported the CISO and security team on access provisioning, log analysis, and network security.Apoyé al CISO y al equipo de seguridad en aprovisionamiento de accesos, análisis de registros y seguridad de red.
  • Reviewed IDS logs for intrusions — brute-forcing, email phishing, malware spread, and more.Revisé registros de IDS en busca de intrusiones — ataques de fuerza bruta, phishing por correo, propagación de malware y más.
  • Provided proactive malware analysis through sandboxing to block and attribute threats.Realicé análisis proactivo de malware mediante sandboxing para bloquear y atribuir amenazas.
  • Managed the MobileIron MDM platform, building secure device profiles to company security metrics.Administré la plataforma MDM MobileIron, creando perfiles de dispositivos seguros según las métricas de seguridad de la empresa.

Director of ITDirector de TI

Umeco

Feb 2014 — Jun 2017
  • Maintained continuity, confidentiality, integrity, and availability of UMECO's information systems.Mantuve la continuidad, confidencialidad, integridad y disponibilidad de los sistemas de información de UMECO.
  • Led network-security design, troubleshooting, and incident debugging.Lideré el diseño de seguridad de red, la resolución de problemas y la depuración de incidentes.
  • Developed and maintained the ERP system plus the company's web presence and online sales portal.Desarrollé y mantuve el sistema ERP junto con la presencia web de la empresa y el portal de ventas en línea.
  • Configured assistive communicator systems for ALS patients; oversaw backup and recovery strategy.Configuré sistemas de comunicación asistida para pacientes de ELA; supervisé la estrategia de respaldo y recuperación.

# Projects & PortfolioProyectos y Portafolio

android-call-audio-injection

mobile / AI security researchinvestigación seguridad móvil / IA

Security research on a rooted Moto G 2023: demonstrated that Android's app ↔ call-audio isolation can be bypassed via an undocumented Qualcomm routing path, letting software inject audio (e.g. AI TTS) into a live cellular call's uplink — confirmed by a remote listener. Published as a defensive write-up: threat model, blue-team analysis, and responsible-disclosure rationale — the weaponizable PoC is withheld by design. Grew from a benign use case (an assistant placing spoken alert/reminder calls to my own phone) into a finding about the mobile attack surface for AI voice agents.Investigación de seguridad en un Moto G 2023 con root: demostré que el aislamiento entre audio de apps y audio de llamada en Android puede eludirse mediante una ruta no documentada de Qualcomm, permitiendo inyectar audio (p. ej. TTS de IA) en el enlace de subida de una llamada celular activa — confirmado por un oyente remoto. Publicado como análisis defensivo: modelo de amenazas, análisis blue-team y justificación de divulgación responsable — el PoC explotable se omite a propósito. Surgió de un uso benigno (un asistente que coloca llamadas de alerta/recordatorio a mi propio teléfono) hacia un hallazgo sobre la superficie de ataque móvil de los agentes de voz con IA.

Android internalsQualcomm audio / ADSPreverse engineeringAI / TTSmobile securityresponsible disclosure
View on GitHub ↗Ver en GitHub ↗

stingray-detector

RF securityseguridad RF

A passive, receive-only toolkit for detecting IMSI catchers / cell-site simulators ("Stingrays") with an SDR — combining cell-topology heuristics (duplicate coverage, power & appearance anomalies) with GSM physical-layer analysis of recorded IQ to flag rogue base stations.Un kit pasivo, de solo recepción, para detectar IMSI-catchers / simuladores de celdas («Stingrays») con un SDR — combinando heurísticas de topología celular (cobertura duplicada, anomalías de potencia y de aparición) con análisis de capa física GSM sobre IQ grabado para señalar estaciones base maliciosas.

PythonNumPySDR / HackRFLTE / GSMsrsRAN
View on GitHub ↗Ver en GitHub ↗

yaris-xp90-repair

automotive / CANautomotriz / CAN
Yaris web dashboard — live gauges and fuel-trim / MAF charts from a sample drive log

A repair knowledge base + read-only Python OBD-II / CAN-bus diagnostics toolkit for the Toyota Yaris over a cheap ELM327 — ISO-TP frame reassembly, manufacturer enhanced-mode (service 0x21) discovery, live data, and fuel-trim/MAF analysis. Includes a from-scratch guide so others can build diagnostics for their own vehicle.Una base de conocimiento de reparación + un kit de diagnóstico OBD-II / CAN-bus en Python (solo lectura) para el Toyota Yaris con un ELM327 económico — reensamblaje de tramas ISO-TP, descubrimiento del modo extendido del fabricante (servicio 0x21), datos en vivo y análisis de fuel-trim/MAF. Incluye una guía desde cero para que otros construyan diagnósticos para su propio vehículo.

PythonOBD-IICAN busELM327pyserialreverse engineering
View on GitHub ↗Ver en GitHub ↗

choicemmed-md300cn358r

BLE / healthBLE / salud
oxi dashboard — SpO₂, heart-rate and perfusion-index tiles with a recent-sessions table

A passive Bluetooth Low Energy toolkit for the Choicemmed MD300CN358R fingertip pulse oximeter — reverse-engineered the GATT protocol to stream SpO₂, heart rate, perfusion index and the raw PPG waveform with no vendor app, plus a local Flask dashboard and an offline HRV analysis pipeline (RMSSD / SDNN / pNN50). Ships synthetic sample data so it runs with no hardware.Un kit Bluetooth Low Energy pasivo para el oxímetro de pulso de dedo Choicemmed MD300CN358R — ingeniería inversa del protocolo GATT para transmitir SpO₂, frecuencia cardíaca, índice de perfusión y la onda PPG cruda sin la app del fabricante, con un panel local en Flask y un pipeline offline de análisis de HRV (RMSSD / SDNN / pNN50). Incluye datos sintéticos para correr sin hardware.

PythonBLE / bleakNumPy / SciPyFlaskHRV / DSPreverse engineering
View on GitHub ↗Ver en GitHub ↗

Self-Hosted Security LabLaboratorio de Seguridad Autohospedado

home lablaboratorio

A production-style lab I built and run to sharpen blue-team skills: hypervisor virtualization, a segmented firewall with VLANs, a SIEM for log collection and alerting, self-hosted internal services, and an isolated sandbox for safe malware detonation and analysis.Un laboratorio estilo producción que construí y opero para afinar habilidades de blue team: virtualización con hipervisor, un firewall segmentado con VLANs, un SIEM para recolección de registros y alertas, servicios internos autohospedados y un sandbox aislado para detonar y analizar malware de forma segura.

ProxmoxpfSense / OPNsenseWazuh SIEMELK StackVLAN segmentationFlareVMDocker

SecurityScripts

open sourcecódigo abierto

A small open-source repo of Windows incident-response utilities — e.g., extracting the SAM credential hive for offline analysis.Un pequeño repositorio de código abierto con utilidades de respuesta a incidentes en Windows — p. ej., extracción del registro de credenciales SAM para análisis offline.

BatchWindows IR
View on GitHub ↗Ver en GitHub ↗

Exam-Prep Study AppsApps de Estudio para Certificaciones

toolingherramientas

Self-built, offline, dependency-free study applications for security certifications (Security+, AI-security) — weighted practice exams, flashcards, and notes. Demonstrates curriculum design and front-end build skills.Aplicaciones de estudio propias, sin conexión y sin dependencias, para certificaciones de seguridad (Security+, seguridad de IA) — exámenes de práctica ponderados, tarjetas de memoria y notas. Demuestran diseño curricular y habilidades de desarrollo front-end.

JavaScriptHTML / CSSPython

This Résumé SiteEste Sitio de Currículum

web

A self-contained, dependency-free single-page site (no framework, no build step) deployed on GitHub Pages — the page you're reading.Un sitio de una sola página, autocontenido y sin dependencias (sin framework ni paso de build), desplegado en GitHub Pages — la página que estás leyendo.

Vanilla JSResponsiveGitHub Pages
View source ↗Ver código ↗

# Education & CertificationsEducación y Certificaciones

Bachelor of Business Administration — Information SystemsBachillerato en Administración de Empresas — Sistemas de Información

Universidad Ana G. Méndez (SUAGM)

2020

CertificationsCertificaciones

  • CompTIA Security+ (ce)Verified ✓Verificado ✓
  • MITRE ATT&CK Fundamentals — MAD20Verified ✓Verificado ✓
  • Recorded Future Certified Analyst2025
  • CompTIA PenTest+2021 · expiredexpirada
  • Tenable Certified Sales Associate (TCSA)2021
  • Palo Alto Networks PSE: Endpoint Associate
  • CompTIA A+ · good for lifevigente de por vida2004

> Verified badgesInsignias verificadas

# ContactContacto