About Andrés
Spanish
Native or bilingual
English
Fluent
French
Fluent
German
Fluent
Experience
- Andrex Red Team ServicesOffensive Security Consultant | Pentester specializing in RCE, LPE, and Binary ExploitationJanuary 2022 - Today (4 years and 7 months)Huelva, SpainI am an advanced offensive security specialist, focused on identifying and exploiting high-impact vulnerabilities in web applications, APIs, Linux infrastructures, and compiled software. My work combines deep pentesting with analysis focused on critical flaws like RCE, LPE, and binary exploitation, where technical complexity demands detailed research and internal system knowledge.My approach goes beyond conventional pentesting: I perform thorough manual audits, reverse engineering, internal flow analysis, logical control reviews, and meticulous validation of less obvious surfaces. This allows me to discover rare conditions, poorly secured internal paths, memory issues, privilege abuses, and flaws requiring an approach close to minimal interaction vulnerabilities.Specialties:• Remote Code Execution (RCE) in web environments and infrastructure• Local Privilege Escalation (LPE) in Linux systems• Binary exploitation (stack, heap, UAF, modern mitigations)• Advanced API and administrative panel analysis• Logical vulnerabilities, chaining, and complex bypassesMethodology:Deep attack surface mappingExhaustive manual enumerationTechnical validation with real offensive thinkingReproducible and secure PoCsClear and actionable technical reportI bring a professional approach focused on real impact, technical accuracy, and maximum confidentiality. If you need an audit capable of finding critical vulnerabilities that go unnoticed in traditional reviews, I can help you elevate your security to the highest level.I also advise on hardening strategies, architecture review, and attack surface reduction. I specialize in detecting subtle vectors and transforming complex findings into clear solutions, helping to comprehensively strengthen critical systems.
- Imprenta realOffensive Security Consultant | Pentester specializing in RCE, LPE, and Binary ExploitationRETAIL (LARGE RETAILERS)July 2021 - August 2025 (4 years and 1 month)Huelva, SpainDuring my experience at the Royal Printing Office, I was responsible for the comprehensive protection of the company's systems, applications, and digital environments, ensuring the confidentiality, integrity, and availability of critical information. My work focused on the evaluation, reinforcement, and maintenance of the security of all internal software, infrastructures, and technological workflows used within the organization.I conducted security audits on internal applications, web services, management systems, and Linux environments, identifying technical and logical vulnerabilities that could compromise business operations. I implemented hardening measures at the system and application level, configuring access controls, permissions, user policies, and protection mechanisms against unauthorized access.I also carried out preventive analyses and security tests to detect flaws before they could be exploited, as well as monitoring and incident response tasks. I collaborated with internal teams to correct vulnerabilities, improve security architecture, and reduce the attack surface of existing systems.
Recommendations
Be the first to recommend Andrés
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- OSCP – Offensive Security Certified ProfessionalOffensive Security2014Pentesting real, no teórico Capacidad práctica bajo presión Credibilidad inmediata ante clientes no técnicos
- OSEP – Offensive Security Experienced Penetration TesterOffensive Security2014Evasión, bypasses, AD avanzado Mentalidad de red team real Perfil senior
Certifications
- OSEEOffsec2023