Network and communications engineer, security architect. My day job is designing controls inside one of Chile's largest insurers: a regulated environment, with sensitive data and formal audit processes. PIMX ArcSec is the practice through which I bring that same judgement to other organisations.
A background in networks and communications shapes how I approach security: from the infrastructure upwards. Understanding how traffic moves, where the control points are and what each platform actually does is what separates a useful assessment from a list of generic recommendations.
I have sat on both sides of the table: building the controls and also putting them through external audit. That experience shapes how I write a report, because it tells apart a finding that changes the risk profile from one that only adds volume to the document.
What I offer is what I practise daily: architecture and control design, technology obsolescence governance, technical security guidelines, vulnerability management and Ley 21.719 implementation, including consent and data subject rights in a large-scale organisation.
For delivery I work with a network of certified professionals across different specialities and technical profiles. That makes it possible to staff each engagement with the skills it actually needs, without carrying a fixed structure or inflating the cost of small pieces of work.
The assessment and the presentation of results always stay with the same professional. What scales is the supporting team, not the distance from the client.
Certifications and roles
ISO 27001Information security management
ISO 27032Cybersecurity
GDPR — DPOData Protection Officer
CC — ISC2Certified in Cybersecurity
NIST CSFCybersecurity framework
Education
Network and Communications EngineeringProfessional degree
Postgraduate diploma in CybersecurityUniversidad de Chile
Postgraduate diploma in Software ArchitectureUniversidad Autónoma de Chile · in progress
CIS Controls v8.1Technical controls
Audit experience
Internal auditPreparation, evidence and remediation
External auditSupport and response to findings
Regulatory auditRequirements from supervisory bodies
Third-party auditSuppliers and client requirements
SOXControls over financial reporting
PCI DSSCard production · payment means
Supporting team
Certified professionalsBrought in according to the scope of the engagement
Diverse technical profilesNetworks, infrastructure, development and compliance
Professional collaborationFlexibility without a fixed structure
Chilean regulation
Ley 21.663Cybersecurity framework · ANCI
Ley 21.719Personal data protection