Juan Manuel Cuestas BeltranSecurity Engineer
Cybersecurity professional. Cloud Security (monitoring, reviews, improvements, best practices, well architecting). Knowledge and experience in security standards implementations and audits, including ISO, NIST, HIPAA, GDPR, FedRAMP, and PCI DSS. Infrastructure as Code security implementations and integration with third-party security tools with Terraform, Puppet, and Cloud Formation. Education, experience, and leadership in ethical hacking, vulnerability analysis and vulnerability management, forensic computing, data recovery, network security, risk management and management of multiple cybersecurity tools (CrowdStrike, Splunk, Sumo Logic, Trend Micro, Tenable). Proficient in teamwork, leadership, and decision-making. Looking forward to contributing expertise in cybersecurity to dynamic and challenging cloud environments
Tech stack
Cyber Security (7)
Security (7)
CrowdStrike (4)
Azure (3)
Infrastructure monitoring (3)
Cloud Computing (3)
Computer Security (3)
Splunk (3)
AWS Cloud Architecture (2)
Linux (2)
Docker (2)
IT Security (2)
Security Testing (2)
Application security (1)
Experience
Cloud Security EngineerCharger Logistics
04/2024 - Currently

Cloud Security Architecting, Zero Trust architecture Management, ZTNA (Zero Trust Network Access), DLP ((Data Loss Prevention), CASB (Cloud Access Security Broker), Cloudflare. AWS & Azure security. Datadog for cloud security monitoring. CrowdStrike for EDR and CSPM management. Firewall & Network security architecting and monitoring. Security scanning and Incident Response.

Security
Cyber Security
Computer Security
Security Testing
IT Security
CrowdStrike
Information Security EngineerLivevox
07/2021 - 04/2024

Cloud security management, monitoring and Improvement of AWS infrastructure for Dev and Production multi- region and multi-account environments. AWS tools security management and improvement, management and integration of security tools with the cloud environment of the company (CrowdStrike -Mantaining and monitoring more than 5k Falcon Crowstrike sensors gobally deployed-, Sumo Logic, Trend Micro, Tenable and others). Use of Puppet and CloudFormation for integrations and infrastructure security improvement deploys and for specific accounts on AWS uniquely for security management. Security architecting reviews and improvements. Vulnerability management lead, security third-party relationships, FedRAMP, PCI DSS & SOC implementations and audits management. Incidents and alert monitoring, forensics.

CrowdStrike
Security
Infrastructure monitoring
Cloud Computing
Cyber Security
Information Security OfficerMO Technologies
06/2020 - 06/2021

Management of ISO 27001 and PCI DSS certifications and standards in the company, leader in information security, incident and risk management, infrastructure penetration testing, cloud security management of AWS environment for the company, providing improvements on cloud security and leading gathering of evidence from AWS for PCI DSS audits. Infrastructure as Code security improvements with Terraform. AWS IAM. AWS integration with open source security tools for improvements (Prowler, AWS Network Access Analyzer, Terraform AWS Secure Baseline and others).

Computer Security
Application security
Cyber Security
Splunk
Security
Information Security AnalystBizagi
06/2019 - 06/2020

General information security management, vulnerability analysis and management, internal security monitoring (SIEM - Splunk), pen-testing to infrastructure and web / mobile applications (iOS & Android), general management of security standards applied in the company (ISO 27001, HIPAA, GDPR, NIST), successful implementation to achieve FedRAMP authorization (Federal Risk Management and Authorization Program, a United States government program that provides a standardized approach to security assessment, authorization and continuous monitoring of cloud products and services). Process management leader with IT security providers (Tenable, Etek, Hackerone, among others). Security management with Azure, Tenable.sc (Nessus), AppSpider, Burp Suite, Kali Linux.

Azure
Splunk
Security
Cyber Security
SOC Analyst (Security Operation Center) and Ethical HackerInvotecsa
05/2019 - 08/2019

(Short Freelance Project) IT security outsourcing company for multiple companies and projects (2019): Ethical hacking to ICBF (Instituto Colombiano de Bienestar Familiar), Ethical Hacking to SIM (Servicios Integrales para la Movilidad), Information Security Manager - HOCOL.

Splunk
Security
Computer Security
Cyber Security
IT Security
Security EngineerExsis Digital Angels
06/2017 - 05/2019

Security engineer performing ethical hacking, vulnerability analysis, event correlation, computer audits, implementation and monitoring of security policies, information security awareness, Cloud security in GCP and AWS. Risk management, firewall management, antivirus, update of software patches, investigation and disclosure of new threats and social engineering threats. ISO 20071 Internal Auditor.

Azure
Linux
Docker
AWS Cloud Architecture
Education
Ethical Hacking CourseDistrict University Alumni Foundation
06/2019 - 11/2019
Cybersecurity in Industry 4.0 Course National University of Colombia
07/2018 - 11/2018
Information Security & ISO 27001:2013 Extension CourseNational University of Colombia
06/2017 - 11/2017
Systems and Computing Engineering National University of Colombia
08/2012 - 08/2018