Elieser Hernandez

Red Team Operator

Open to work Remote · Freelance or full-time OWASP · PTES · MITRE ATT&CK

Freelance penetration tester specializing in web application, API and infrastructure security testing. Hands-on experience in security assessments, bug bounty programs and test automation. Methodical, impact-driven approach with a strong focus on identifying high-risk vulnerabilities and delivering clear technical and executive-level reporting.

27+
Assessments
8+
Vulns / engagement
75%
BB acceptance
40+
Reports
Scroll

01.About Me

10110010nmap -sV0x7f3a9cSELECT *

Offensive Penetration Tester | Web, APIs & Infrastructure

I am a freelance offensive penetration tester specializing in web applications, APIs and infrastructure, with hands-on experience in security assessments, bug bounty programs and test automation. My methodology is based on OWASP Top 10, PTES and MITRE ATT&CK, focused on identifying and exploiting critical vulnerabilities such as SQL Injection, XSS, SSRF, RCE and business logic flaws.

I have executed 27+ security assessments with an average of 8+ vulnerabilities per engagement, including high and critical severity findings, and hold a 75% report acceptance rate in bug bounty. I deliver clear technical reports and executive summaries focused on business impact and risk exposure.

LocationHavana, Cuba
Work modeRemote
Emailastroreal031@gmail.com
GitHubgithub.com/K2uci
Phone+53 59805123
AvailabilityOpen to work

// CV updated: August 2026

02.Pentesting Services

Web Pentesting

Offensive assessments following OWASP Top 10 and PTES: SQL injection, XSS, SSRF, RCE, broken access control and business logic flaws.

API Security

In-depth manual testing combined with automation: access control, insufficient validation and insecure configurations.

Mobile Security

Mobile platform assessments following OWASP methodology, focused on high and critical severity findings.

Infrastructure & Recon

Automated reconnaissance with Python and Bash, attack surface enumeration and controlled DoS simulations.

// How I work

  1. 01

    Reconnaissance

    Attack surface mapping with Amass, Nmap and FFUF.

  2. 02

    Analysis

    Vulnerability discovery with Burp Suite, Nuclei and manual testing.

  3. 03

    Exploitation

    Real impact validation with controlled, reproducible PoCs.

  4. 04

    Reporting

    Technical report with evidence plus a business-focused executive summary.

03.My Experience

Professional Experience

Aug 2025 — Mar 2026

Penetration Tester (Mid-Level)

INTRUST SECURITY — Remote

  • Performed offensive security assessments following OWASP and PTES methodologies across web applications, APIs and mobile platforms.
  • Executed 27+ security assessments, identifying an average of 8+ vulnerabilities per engagement, including high and critical severity findings.
  • Actively exploited SQL Injection, XSS, SSRF, RCE and business logic flaws.
  • Automated reconnaissance and exploitation workflows using Python and Bash scripting.
  • Produced detailed technical reports and executive summaries focused on risk exposure and business impact.
  • Burp Suite
  • Nuclei
  • SQLMap
  • Python
  • Bash
Dec 2023 — Aug 2025

Freelancer / Bug Bounty

Independent Security Researcher — Remote

  • Actively participated in multiple Bug Bounty programs targeting web applications and infrastructure.
  • Achieved a 75% report acceptance rate (6 out of 8 submissions validated).
  • Combined in-depth manual testing with automated tooling to uncover complex vulnerabilities.
  • Identified access control weaknesses, insufficient validation and insecure configurations.
  • Burp Suite
  • FFUF
  • Amass
  • Nuclei
May 2023 — Dec 2023

Systems Monitoring & Security Specialist

XETID DEVELOPMENT COMPANY — Havana, Cuba

  • Monitored system availability, integrity and security using the Elastic Stack (Elasticsearch and Kibana).
  • Conducted controlled Denial of Service (DoS) simulations to evaluate infrastructure resilience.
  • Generated 40+ security incident reports, including post-incident analysis and documentation.
  • Elasticsearch
  • Kibana

Education & Certifications

2022 — 2026

Bachelor of Science in Computer Science

University of Informatics Sciences (UCI)

Havana, Cuba. Focus on cybersecurity, software development and data analysis.

Feb 2026
Verified

EF SET Certificate — B1 Intermediate

EF Standard English Test — 41/100

Verify certificate
ICIP
Certified

ICIP Certificate

Institution: ICIP

View certificate
Languages

Languages

SpanishNative
EnglishB1 — Technical reading & reporting

04.My Skills

Methodologies

  • OWASP Top 10
  • PTES
  • MITRE ATT&CK
  • Bug Bounty
  • Threat Modeling

Tools

  • Burp Suite
  • Nmap
  • Metasploit
  • SQLMap
  • Nuclei
  • FFUF
  • Amass
  • Hashcat
  • John the Ripper

Languages

  • Python
  • Bash
  • JavaScript
  • SQL

Specializations

  • Web Pentesting
  • API Security
  • Mobile Security
  • Reconnaissance
  • Exploitation
$ grep -i "exploited" findings.log
  • SQL Injection
  • XSS
  • SSRF
  • RCE
  • Broken Access Control
  • Business Logic
  • Misconfiguration

// Tech Arsenal

Burp
Nmap
Metasploit
SQLMap
Nuclei
FFUF
Amass
Hashcat
Python
Bash
JavaScript
Elastic

05.Frequently Asked Questions

>

Do you work as a freelance penetration tester?

Yes. I work remotely as a freelance penetration tester for companies and security teams, and I am also open to full-time positions. Since 2023 I have worked on professional security assessments and bug bounty programs.

>

What kind of penetration testing do you perform?

Web application, API, mobile and infrastructure pentesting, following OWASP Top 10, PTES and MITRE ATT&CK. I combine in-depth manual testing with tools such as Burp Suite, Nuclei, SQLMap and Nmap.

>

What do you deliver at the end of an assessment?

A detailed technical report with findings, severity and evidence, plus an executive summary focused on risk exposure and business impact.

>

Do you work remotely, and in which languages?

Yes, I work 100% remotely from Havana, Cuba. I am a native Spanish speaker with B1 English, enough for technical reading and report writing.

>

How can I contact you?

By email at astroreal031@gmail.com, via LinkedIn or on WhatsApp at +53 59805123. I reply within 24 hours.

06.Contact

// Let's talk

Looking for a freelance penetration tester for your team, or need a security assessment of your web application, API or infrastructure? I am available for remote positions and one-off projects.

$ echo "I reply within 24h"