You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Andrés R.AR

Andrés R.

Senior Pentester in Critical Vulnerabilities

€520/day
Huelva, ES
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Andrés

Andrex Red Team Services
Offensive Security Consultant | Pentester specializing in RCE, LPE, and Binary Exploitation
Huelva, Spain

I am an offensive security consultant with an advanced focus on identifying, analyzing, and exploiting critical vulnerabilities in web applications, APIs, Linux infrastructures, and compiled software. My specialization centers on high-impact flaws such as Remote Code Execution (RCE), Local Privilege Escalation (LPE), and binary exploitation, where technical depth, manual research, and internal system understanding are key to achieving real results.

I work beyond automated or superficial pentesting. I conduct thorough manual audits, code analysis, internal flow analysis, logical control reviews, reverse engineering, and detailed assessment of non-obvious attack surfaces. This approach allows me to discover complex vulnerabilities that often go unnoticed: poorly secured internal paths, privilege abuses, design flaws, memory errors, vulnerability chaining, and rare conditions requiring minimal interaction or deep environment knowledge.

I have experience in scenarios where public exploits or obvious vectors are absent, approaching analysis with a realistic, impact-oriented offensive mindset. My goal is not just to demonstrate a weakness, but to validate its practical exploitability and its real risk to the business.

Areas of specialization:
• Remote Code Execution (RCE) in web environments, administrative panels, and infrastructure
• Local Privilege Escalation (LPE) in Linux systems
• Binary exploitation: stack, heap, UAF, and bypass of modern mitigations
• Advanced analysis of APIs, authentication, and business logic
• Logical vulnerabilities, complex bypasses, and vulnerability chaining,
  • Spanish

    Native or bilingual

  • English

    Fluent

  • French

    Fluent

  • German

    Fluent

Remote only
Primarily works remotely

Experience

  • Andrex Red Team Services
    Offensive Security Consultant | Pentester specializing in RCE, LPE, and Binary Exploitation
    January 2022 - Today (4 years and 7 months)
    Huelva, Spain
    I am an advanced offensive security specialist, focused on identifying and exploiting high-impact vulnerabilities in web applications, APIs, Linux infrastructures, and compiled software. My work combines deep pentesting with analysis focused on critical flaws like RCE, LPE, and binary exploitation, where technical complexity demands detailed research and internal system knowledge.

    My approach goes beyond conventional pentesting: I perform thorough manual audits, reverse engineering, internal flow analysis, logical control reviews, and meticulous validation of less obvious surfaces. This allows me to discover rare conditions, poorly secured internal paths, memory issues, privilege abuses, and flaws requiring an approach close to minimal interaction vulnerabilities.

    Specialties:
    • Remote Code Execution (RCE) in web environments and infrastructure
    • Local Privilege Escalation (LPE) in Linux systems
    • Binary exploitation (stack, heap, UAF, modern mitigations)
    • Advanced API and administrative panel analysis
    • Logical vulnerabilities, chaining, and complex bypasses

    Methodology:

    Deep attack surface mapping

    Exhaustive manual enumeration

    Technical validation with real offensive thinking

    Reproducible and secure PoCs

    Clear and actionable technical report

    I bring a professional approach focused on real impact, technical accuracy, and maximum confidentiality. If you need an audit capable of finding critical vulnerabilities that go unnoticed in traditional reviews, I can help you elevate your security to the highest level.

    I also advise on hardening strategies, architecture review, and attack surface reduction. I specialize in detecting subtle vectors and transforming complex findings into clear solutions, helping to comprehensively strengthen critical systems.
  • Imprenta real
    Offensive Security Consultant | Pentester specializing in RCE, LPE, and Binary Exploitation
    RETAIL (LARGE RETAILERS)
    July 2021 - August 2025 (4 years and 1 month)
    Huelva, Spain
    During my experience at the Royal Printing Office, I was responsible for the comprehensive protection of the company's systems, applications, and digital environments, ensuring the confidentiality, integrity, and availability of critical information. My work focused on the evaluation, reinforcement, and maintenance of the security of all internal software, infrastructures, and technological workflows used within the organization.

    I conducted security audits on internal applications, web services, management systems, and Linux environments, identifying technical and logical vulnerabilities that could compromise business operations. I implemented hardening measures at the system and application level, configuring access controls, permissions, user policies, and protection mechanisms against unauthorized access.

    I also carried out preventive analyses and security tests to detect flaws before they could be exploited, as well as monitoring and incident response tasks. I collaborated with internal teams to correct vulnerabilities, improve security architecture, and reduce the attack surface of existing systems.
    Infrastructure Security Web & APIs Pentesting Zero days RCE Exploit developer

Recommendations

Be the first to recommend Andrés

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • OSCP – Offensive Security Certified Professional
    Offensive Security
    2014
    Pentesting real, no teórico Capacidad práctica bajo presión Credibilidad inmediata ante clientes no técnicos
  • OSEP – Offensive Security Experienced Penetration Tester
    Offensive Security
    2014
    Evasión, bypasses, AD avanzado Mentalidad de red team real Perfil senior

Certifications

  • OSEE
    Offsec
    2023
    Vulnerability Exploitation Malware Analysis and Evasion Techniques Attacks on Network Services and Protocols Security Testing Automation Sensitive Information Management and Reporting Offensive Security in Windows and Linux Environments Critical Thinking and Real-Time Problem Solving Post-Exploitation and Privilege Escalation Web Application, Binary, and API Pentesting Advanced Reconnaissance and Network Mapping

Skill set

Categories