Web Pentesting
Offensive assessments following OWASP Top 10 and PTES: SQL injection, XSS, SSRF, RCE, broken access control and business logic flaws.
Red Team Operator
Freelance penetration tester specializing in web application, API and infrastructure security testing. Hands-on experience in security assessments, bug bounty programs and test automation. Methodical, impact-driven approach with a strong focus on identifying high-risk vulnerabilities and delivering clear technical and executive-level reporting.
I am a freelance offensive penetration tester specializing in web applications, APIs and infrastructure, with hands-on experience in security assessments, bug bounty programs and test automation. My methodology is based on OWASP Top 10, PTES and MITRE ATT&CK, focused on identifying and exploiting critical vulnerabilities such as SQL Injection, XSS, SSRF, RCE and business logic flaws.
I have executed 27+ security assessments with an average of 8+ vulnerabilities per engagement, including high and critical severity findings, and hold a 75% report acceptance rate in bug bounty. I deliver clear technical reports and executive summaries focused on business impact and risk exposure.
// CV updated: August 2026
Offensive assessments following OWASP Top 10 and PTES: SQL injection, XSS, SSRF, RCE, broken access control and business logic flaws.
In-depth manual testing combined with automation: access control, insufficient validation and insecure configurations.
Mobile platform assessments following OWASP methodology, focused on high and critical severity findings.
Automated reconnaissance with Python and Bash, attack surface enumeration and controlled DoS simulations.
Attack surface mapping with Amass, Nmap and FFUF.
Vulnerability discovery with Burp Suite, Nuclei and manual testing.
Real impact validation with controlled, reproducible PoCs.
Technical report with evidence plus a business-focused executive summary.
Havana, Cuba. Focus on cybersecurity, software development and data analysis.
Yes. I work remotely as a freelance penetration tester for companies and security teams, and I am also open to full-time positions. Since 2023 I have worked on professional security assessments and bug bounty programs.
Web application, API, mobile and infrastructure pentesting, following OWASP Top 10, PTES and MITRE ATT&CK. I combine in-depth manual testing with tools such as Burp Suite, Nuclei, SQLMap and Nmap.
A detailed technical report with findings, severity and evidence, plus an executive summary focused on risk exposure and business impact.
Yes, I work 100% remotely from Havana, Cuba. I am a native Spanish speaker with B1 English, enough for technical reading and report writing.
By email at astroreal031@gmail.com, via LinkedIn or on WhatsApp at +53 59805123. I reply within 24 hours.
Looking for a freelance penetration tester for your team, or need a security assessment of your web application, API or infrastructure? I am available for remote positions and one-off projects.