About
DevSecOps Engineer @ Swisscom · Rotterdam · Relocating to Switzerland
Profile
DevSecOps engineer who turns security process into platforms: CI/CD guardrails for 1000+ developers, policy-as-code, SBOM-backed vulnerability management, and HashiCorp Vault at high assurance. Application Security background in insurance. MSc Cybersecurity (completed); MSc Artificial Intelligence thesis deposited, pending defense. CISSP in preparation. Spanish EU/EFTA citizen — eligible for Swiss Permit B.
Thesis: an OpenAI-compatible AI Security Gateway (inbound threat detection, reversible DLP, routing). Evaluation 17/17 PASS; ~175 pytest. github.com/r4fik1/ai-security-gateway.
Experience
-
Swisscom – DevSecOps Engineer & Scrum Master (Rotterdam) · 10.2022 – Present
- SAST, DAST, SCA, secrets detection and IaC scanning (Trivy, Checkov) in GitLab CI/CD for 1000+ developers; findings into DefectDojo / CycloneDX / Dependency-Track.
- Policy-as-code with OPA; Kubernetes hardening (RBAC, PSS, NetworkPolicies, Falco).
- Enterprise HashiCorp Vault (Kubernetes + Terraform, dynamic secrets) and a Go CLI for rekey / generate-root ceremonies (GPG, YubiKey, coverage ~95%).
- Security-transparency data products: Streamlit → scheduled ETL → BI (Parquet, S3, Glue, Athena; fail-closed; OIDC).
- LLM-assisted threat-modeling pipeline (diagrams → STRIDE + human review). Scrum Master for the security-platform team.
-
Aegon Insurance – Application Security Engineer (Madrid) · 07.2021 – 09.2022
Secure code review, SAST/DAST (Kiuwan), vulnerability and pentest remediation, security requirements with architecture and business. -
Between Technology – Cyber Security Analyst (Barcelona) · 01.2021 – 07.2021
Vulnerability testing of applications and infrastructure (C++, .NET, PHP); data protection and encryption; risk reports. -
Giesecke+Devrient Mobile Security – Test Manager (Barcelona) · 02.2019 – 01.2021
Test design and C++ automation in a mobile-security product organisation.
Education
-
Master’s Degree in Artificial Intelligence – UNIR (2025–present)
Thesis deposited, pending defense: OpenAI-compatible AI Security Gateway. - Postgraduate Certificate in Data Engineering – UNIR (2025–present)
- Master’s Degree in Cybersecurity – UNIR (2019–2021), completed
- Bachelor’s in Telecommunications Engineering (Electronic Systems) – University of Valladolid (2013–2019)
Certifications
- CAISP — Certified AI Security Professional
- CTMP — Certified Threat Modeling Professional
- CASP — Certified API Security Professional
- CCNSE — Certified Cloud Native Security Expert
- CCSE — Certified Container Security Expert
- CDP — Certified DevSecOps Professional
- Internal Auditor ISO 27001:2013 (TÜV Rheinland), 2021 — expired 06.2024
CISSP — in preparation (not certified).
Skills
- CI/CD & cloud native: GitLab CI · Jenkins · Kubernetes · Docker · Terraform · OPA/Styra · Checkov · Falco · Vault Enterprise
- AppSec / SSDLC: Semgrep · Trivy · ZAP · Gitleaks · Dependency-Track · DefectDojo · CycloneDX · STRIDE · OWASP
- Engineering: Python · Go · Bash · C++ · Streamlit · pandas · Parquet · S3/Athena
Languages
- Spanish — C2 (native)
- English — C1
- German — A1 (in progress toward B1)
Selected recognition
- Telefónica ElevenPaths wireless-security study
- Spanish IP filings (sensor data logger + companion app)
- Santander Explorer 2019 · PROMETEO awards 2019 (×2)
Contact
Rotterdam, NL · Relocating to Switzerland
marcosmartingutierrez89@gmail.com
linkedin.com/in/marcos-martin-gutierrez
github.com/r4fik1
