Profile
Security engineer who turns process into platforms: tested software, CI/CD, and human gates on the risky steps. MSc thesis: an OpenAI-compatible AI Security Gateway (inbound threat detection, DLP, routing). At Swisscom I run DevSecOps for 1000+ developers and high-assurance Vault operations. CAISP; MSc Cybersecurity; MSc Artificial Intelligence (thesis deposited, pending defense). CISSP in preparation.
Experience
DevSecOps Engineer & Scrum Master
10.2022 – Present
Swisscom · Rotterdam
- Designed an OpenAI-compatible AI Security Gateway (MSc thesis, deposited): reverse proxy with inbound threat pipeline (sanitisation, OWASP-style filters, LLM-as-judge ∥ DistilBERT), reversible DLP, routing and outbound checks. Evaluation 17/17 PASS; ~175 pytest. github.com/r4fik1/ai-security-gateway
- Built an LLM-assisted threat-modeling pipeline (diagrams → STRIDE threats and mitigations with mandatory human review), combining CTMP practice with CAISP labs on prompt injection, RAG and agent/tool risks.
- Integrated SAST, DAST, SCA, secrets detection and IaC scanning (Trivy, Checkov) into GitLab CI/CD used by 1000+ developers; policy-as-code with OPA; findings fan-in to a system of record (SBOM / CycloneDX).
- Led enterprise HashiCorp Vault: Kubernetes + Terraform, dynamic secrets in CI/CD, least privilege. Wrote a Go CLI that turns rekey / generate-root key ceremonies into a tested, cross-platform workflow with GPG/YubiKey human gates (coverage gate ~95%).
- Delivered security-transparency products in Python (metrics, maturity, scheduled BI) so leadership sees training, assessments and vulnerability posture without spreadsheet archaeology.
- Scrum Master: servant leadership, flow and capacity for security-platform work.
Application Security Engineer
07.2021 – 09.2022
Aegon Insurance · Madrid
- Owned AppSec services across platforms: secure code review, SAST/DAST (Kiuwan), vulnerability and pentest remediation, security requirements with architecture and business, IT security metrics.
Cyber Security Analyst
01.2021 – 07.2021
Between Technology · Barcelona
- Security in delivery projects: vulnerability testing of applications and infrastructure (C++, .NET, PHP), data-protection and encryption controls, risk reports.
Test Manager
02.2019 – 01.2021
Giesecke+Devrient Mobile Security · Barcelona
- Test design and automation (C++), environment setup, defect analysis, Scrum with Jira/Confluence — in a mobile-security product context.
Education
Master’s Degree in Artificial Intelligence (Data Engineering track)
2025 – Present
UNIR — Universidad Internacional de La Rioja · Thesis deposited, pending defense: AI Security Gateway
Postgraduate Certificate in Data Engineering
2025 – Present
UNIR — Universidad Internacional de La Rioja
Master’s Degree in Cybersecurity
2019 – 2021
UNIR — Universidad Internacional de La Rioja
Bachelor’s in Telecommunications Engineering (Electronic Systems)
2013 – 2019
University of Valladolid (UVa)
Certifications
- CAISP — Certified AI Security Professional
- CTMP — Certified Threat Modeling Professional
- CASP — Certified API Security Professional
- CCNSE / CCSE — Cloud Native & Container Security
- CDP — Certified DevSecOps Professional
- Internal Auditor ISO 27001:2013 (TÜV Rheinland), 2021 – expired 06.2024
- CISSP — in preparation (not yet certified)
Skills
AI security: OWASP LLM Top 10, prompt injection, guardrails, DLP, STRIDE, LLM-as-judge, evals
AppSec / SSDLC: SAST, DAST, SCA, SBOM, Semgrep, Trivy, ZAP, DefectDojo, Dependency-Track
Platform: Kubernetes, Terraform, OPA, HashiCorp Vault, GitLab CI, Docker
Engineering: Python, Go, Bash · pandas/Parquet for security metrics
Languages
Spanish C2 (native) · English C1 · German A2 (in progress toward B1)
Selected recognition
Telefónica ElevenPaths wireless-security study · Spanish IP filings (sensor data logger + companion app) · Santander Explorer 2019 · PROMETEO awards 2019 (×2). References available upon request.