Jesus Vazquez

Security Engineer focused on product security engineering, secure software design, and developer-first security automation.

Features

What I Build

Security tooling, cloud hardening workflows, and practical automations that help teams ship faster without weakening security.

What I Audit

Web apps, APIs, and systems for vulnerabilities, configuration risk, and privacy-impacting design gaps.

What I Value

Clear communication, measurable risk reduction, and security guidance that is actually implementable.

Placeholder content (draft examples)

Placeholder Case Studies

1) Secure SDLC Guardrails for a Product Team

  • Role: Product Security Engineer (placeholder)
  • Problem: Engineering teams were shipping quickly, but security checks were inconsistent across repositories.
  • What I built: Added security-by-design checkpoints to planning, PR templates, and CI policy checks for common web/API risks.
  • Threats addressed: Injection paths, authentication gaps, insecure defaults, and secrets exposure.
  • Impact (placeholder):
    • 35% reduction in repeat security findings across two release cycles
    • 50% faster triage by standardizing severity and ownership
    • 90% of new services launched with baseline security controls enabled

2) Cloud Hardening + Identity Control Baseline

  • Role: Cloud/Network Security Contributor (placeholder)
  • Problem: Cloud resources had drift in IAM permissions, network segmentation, and logging coverage.
  • What I audited and improved: Reviewed IAM roles, tightened security groups/network paths, and expanded centralized logging/alerting.
  • Framework alignment: CIS-style hardening controls and least-privilege access patterns.
  • Impact (placeholder):
    • Reduced high-risk IAM bindings by 60%
    • Closed public exposure paths on internal-only services
    • Improved investigation readiness with consistent audit trails

3) Practical Offensive Testing for Defensive Fixes

  • Role: Security Tester / AppSec Partner (placeholder)
  • Problem: Teams needed realistic attack simulation tied directly to actionable remediation.
  • What I tested: Web app and API auth flows, input handling, session controls, and configuration weaknesses.
  • What I delivered: Reproducible findings with proof-of-concept steps, fix guidance, and retest validation.
  • Impact (placeholder):
    • Identified and remediated critical auth and access-control issues before release
    • Improved developer secure-coding confidence through fix walkthroughs
    • Established a repeatable pre-release security testing checklist

Placeholder Writing & Playbook Roadmap

  • Secure Code Review Playbook (Draft): How I prioritize findings for developer adoption and risk reduction.
  • Threat Modeling in Practice (Draft): Lightweight model for fast-moving product teams.
  • API Security Testing Checklist (Draft): Practical tests for auth, authorization, and input trust boundaries.
  • Cloud Hardening Notes (Draft): IAM, segmentation, and logging controls I validate first.
  • Security Automation Snippets (Draft): Small scripts/workflows that reduce repetitive AppSec toil.

Core Focus Areas

Features

Product Security & Secure Design

Security-by-design patterns, threat modeling, architecture reviews, and practical guidance embedded across the SDLC.

Cloud & Network Security

Defensive architecture, segmentation, identity controls, and continuous hardening.

Security Automation

Scripts and workflows that reduce manual security toil and increase consistency.

Education & Credentials

  • B.S. in Computer Science — University of Wisconsin–Madison
  • CCNA — Cisco Networking Academy
  • CyberOps Associate — Cisco Networking Academy
  • Cisco Emerging Talent Mentorship Program (2022)

Organizations

  • ColorStack
  • CyberSecurity UW (CSEC)
  • Google Developer Student Club (GDSC)

This site is actively being refreshed.

How This Portfolio Is Evolving

Features

Security Case Studies with Measurable Outcomes

Each project write-up will include the problem, threat model, implementation details, and impact metrics (for example: issue classes eliminated, MTTR reduction, or coverage gains).

Public Security Notes and Playbooks

Ongoing notes will document practical workflows for secure code review, cloud hardening, API testing, and automation so teams can reuse proven patterns.

Builder + Auditor Perspective

Content will increasingly highlight both sides of security work: building secure systems and evaluating systems under realistic offensive pressure.