Skip to content

I like saying that I'm some kind of detective

(don't ask about the goat)

Málaga, Spain Remote · EU
A goat wearing black sunglasses and a hoodie, its neck stretching down the page

Two years inside one of Europe’s largest cybersecurity operations, promoted twice in under two. Collection tuned for enterprise organizations across Europe, USA and LATAM, and a dedicated intelligence project embedded with a Tier-1 global bank

What I actually do

Intelligence is only worth what the stakeholder can do with it. I define collection around each stakeholder’s PIRs and deliver products that end in a decision.

Intelligence production

Daily, weekly and monthly threat and vulnerability reporting for both defenders and executives. Structured Analytic Techniques keep facts and analytical judgement clearly separated.

PIRs · Executive reporting · SATs · Vulnerability intel

OSINT & dark-web investigation

Collection across open, deep and dark sources: Tor forums, paste sites, marketplaces and social platforms - with source evaluation and grading applied to everything that ships.

OSINT · SOCMINT · Tor collection · Source grading

Digital risk protection & anti-fraud

Detection of phishing, fraud campaigns, brand abuse and credential exposure. End-to-end takedown coordination with registrars, ISPs and platforms.

Brand abuse · Credential exposure · Takedowns · Advisories

Automation & tooling

Custom Python tooling for collection, keyword alerting and structured reporting pipelines, cutting manual effort and shortening the path from signal to stakeholder.

Python · Git · Linux · LLM-assisted analysis

If it does not end in a decision, it was just news.

Experience

Telefónica Tech

One of Europe’s largest cybersecurity operations. Promoted twice in under two years.

Feb 2026 - Present

Threat Intelligence Analyst II

Digital Risk Protection

Intelligence point of contact for enterprise organizations: elicit requirements and PIRs, tune collection to their threat landscape, advise on how to act on what is delivered.

Produce tailored daily, weekly and monthly threat and vulnerability reports for defenders and executive stakeholders.

Own service operations: onboard new intelligence modules and proactively detect, escalate and close capability gaps in the platform.

Jan 2025 - Jan 2026

Digital Risk Protection & Anti-Fraud Analyst I

Enterprise client portfolio

Ran OSINT and dark-web collection across open, deep and dark sources to detect phishing, fraud campaigns, brand abuse and credential exposure.

Administered TIP and monitoring platforms; built custom Python tooling to automate collection, keyword alerting and structured reporting.

Coordinated domain and social-media takedowns end-to-end with registrars, ISPs and platforms.

May 2024 - Dec 2024

Threat Intelligence Analyst I

Dedicated CTI project · Tier-1 global bank

Embedded analyst supporting the bank’s SOC and threat-hunting workflows: triaged IPs, hashes, domains and CVEs, mapping adversary TTPs to MITRE ATT&CK.

Delivered daily threat bulletins and situational-awareness reporting on financial-sector threats to client security stakeholders.

Applied Structured Analytic Techniques across all intelligence products.

OpenCTI MITRE ATT&CK OSINT Cybersixgill Python PIRs & requirements Dark-web monitoring Diamond Model SOCMINT Cyber Kill Chain TIP administration Structured Analytic Techniques Tor forums & paste sites Source evaluation & grading Executive reporting Vulnerability reporting Threat-hunting use cases SIEM / ticketing Talkwalker Git Linux LLM-assisted analysis Prompt engineering Spanish (native) English (full professional)

I also design and build for the web

Graphic design and front-end are the other half of how I think. Same instinct as intelligence work: strip it down until only the signal is left.

Visual & brand design

Type-led layouts, monochrome palettes, editorial composition. The kind of design that gets out of the way of the message.

  • Art direction
  • Typography
  • Identity

Front-end development

Fast, animated, hand-built sites. Static-first architecture, real accessibility, and motion that has a reason to exist, like this page.

  • Astro
  • Tailwind
  • GSAP
  • TypeScript

Security-minded builds

Hardened headers, no third-party tracking, minimal attack surface. Knowing how sites get abused is a design constraint, not an afterthought.

  • CSP
  • Zero trackers
  • Static hosting

Certifications

Falcon Intelligence Specialist

CrowdStrike University · 2026

Introduction to SecOps

Palo Alto Networks · 2026

Six further cybersecurity certifications

Available on request

Education

Cursus, Computer Programming

42 Málaga · 2023-2025

Game Development (Programming)

American University of Malta · 2022-2023

Contact

Let’s talk intelligence

Open to CTI roles. Based in Málaga, working remote across the EU.

contact@phi618.cloud