host up · new york city, usa · 6 services exposed

Export (PDF) Book a call

jp@nyc:~$

Illustrated portrait of J. Perez Duerto

J. Perez Duerto

Cybersecurity Engineering Leader Security Transformation · Offensive + Defensive · AI + Automation

I build and transform cybersecurity engineering organizations that protect complex, highly regulated enterprises. Across U.S., North American, and global leadership roles, I have led multinational teams, standardized security services and governance, modernized control portfolios, and partnered with CISOs and business leaders to improve resilience, efficiency, and risk management. My roots span network and security engineering, penetration testing, red teaming, enterprise defense, and security architecture. Today I use that depth to make better leadership decisions and to apply automation and AI responsibly to real security problems.

Where to find me

jp@nyc:~$

PortStateService
443/workopen LinkedInCareer, banking security, and the professional record
22/codeopen GitHubOpen-source tooling I write and share
80/companyopen Red Hound InfoSecPenetration testing, vCISO, and security strategy
8080/writingopen Research & writingRed Hound field notes on offensive security, defensive engineering, AI, and leadership
1337/ctfopen Hack The Box · WalkthroughsMachines and challenges, solved for practice
53/signalopen XShorter thoughts, mostly security

6 services scanned · all open

How I work

jp@nyc:~$

What I lead

  • Build and transform cybersecurity engineering teams
  • Set strategy for enterprise security controls and platforms
  • Connect architecture, operations, risk, and business priorities
  • Apply offensive insight to defensive engineering and validation
  • Use automation and AI to improve control effectiveness

How I do it

  • Stay technically close enough to challenge assumptions
  • Translate complex security risk into clear decisions
  • Build accountable, collaborative teams across regions
  • Modernize services without losing operational resilience
  • Keep learning, experimenting, and teaching
  • Work in English and Spanish

leadership at scale, engineering depth intact

The route here

jp@nyc:~$

  1. 2024 → now1 yr 10 mos

    Director of Network Security

    Santander Bank, N.A. · New York, USA

    Member of the U.S. CISO team leading the implementation and management of network security controls across Santander’s U.S. entities. Responsible for the strategy, engineering, operations, resilience, and regulatory alignment of critical network-security capabilities.

    • Lead cross-functional teams in strengthening network-security controls and responding to emerging threats.
    • Guide architecture and control decisions across firewalls, IPS, WAF, DDoS protection, NAC, VPN, web proxy, and cloud-network security.
    • Partner with cloud, infrastructure, application, risk, audit, and business teams to align security controls with enterprise priorities.
    • Drive standardization, continuous improvement, and operational resilience while balancing regulatory expectations and established budgets.
    • Protect critical systems and customer data across the U.S. enterprise.
  2. 2018 → now7 yrs 11 mos

    Founder

    Red Hound Information Security · Remote

    My own consultancy, helping small and mid-sized businesses stay secure — penetration testing, virtual CISO engagements, and security strategy. redhound.us

  3. 2022 → 20242 yrs 5 mos

    Global Cyber Defend Service Manager

    Santander Digital Services · Boston, USA

    Promoted from North American leadership into a global cybersecurity service role responsible for aligning delivery across Santander entities and partnering with CISOs worldwide.

    • Partnered with CISOs across global entities to align local cybersecurity needs with enterprise strategy and governance.
    • Standardized service-management materials and governance models across regions, improving consistency, transparency, and operational discipline.
    • Modernized the global service catalog and pricing methodology to strengthen cost visibility, planning, and client alignment.
    • Rebalanced delivery capacity toward cost-effective regions, reducing operating costs without compromising service quality.
    • Established repeatable onboarding practices for new entities and strengthened trusted relationships with internal clients worldwide.
  4. 2020 → 20221 yr 11 mos

    Head of Protect for North America

    Santander Digital Services · Boston, USA

    Expanded from U.S. leadership into responsibility for North America, integrating 80 additional Mexico-based professionals into a cohesive multinational cybersecurity organization.

    • Led cross-border cybersecurity delivery and extended services to Santander entities in Mexico, Uruguay, Peru, and Colombia.
    • Directed end-to-end delivery across a broad portfolio of cybersecurity controls and services.
    • Established a collaborative operating model across countries while maintaining service quality, accountability, and local alignment.
    • Led talent acquisition, training, mentoring, and professional development across the multinational organization.
    • Partnered across finance, HR, compliance, and technology to address the operational requirements of a geographically distributed team.
  5. 2019 → 20201 yr

    Director of Cyber Security Infrastructure

    Santander Digital Services · Boston, USA

    Built and led a 25-person U.S. cybersecurity team responsible for enterprise defensive controls and services across Santander affiliates.

    • Directed the end-to-end lifecycle of a broad security portfolio spanning network security, endpoint protection, EDR, email and web security, DLP, anti-phishing, and virtual patching.
    • Transformed the Protect operating model to improve service quality and cross-functional collaboration, earning recognition from senior leadership.
    • Expanded cybersecurity services across Santander’s U.S. affiliates, strengthening consistency and enterprise coverage.
    • Led talent acquisition, training, and mentoring while managing financial operations, HR requirements, and compliance obligations.
    • Combined strategic leadership with technical oversight to improve the reliability and effectiveness of enterprise security services.
  6. 201910 mos

    Chief Information Security Officer

    Advoqt Cybersecurity · Boston, USA

    Founded the cybersecurity practice and grew it past 20 new clients a year, hiring and mentoring 15 engineers — while staying on the tools myself for the engagements that needed it.

    • Ran penetration tests and maturity assessments, including one across a large educational system.
    • Designed and executed a cloud migration.
    • Rebuilt a Splunk deployment: lower cost, more detection use cases.
    • Wrote the method for finding and killing superfluous firewall rules at a major financial institution.
    • Deployed an open-source cloud SIEM across 30,000+ endpoints.
    • Applied machine learning to SIEM data for anomaly detection.
  7. 2017 → 20191 yr 3 mos

    Lead Security Engineer

    Advoqt Cybersecurity · Boston, USA

    Hands-on across finance, retail, and telecommunications: ran the web application penetration tests myself, designed and built a Security Operations Center end to end, and set the cloud security direction. Lead instructor and curriculum designer for CyberWarrior Academy alongside it.

  8. 2017 → 20192 yrs

    Co-founder & instructor

    CyberWarrior Academy · Boston, USA

    Master instructor and curriculum designer — EC-Council certifications, hands-on hacking skills, programming for hackers, and professional development.

  9. 2015 → 20172 yrs 7 mos

    Cyber Security Consultant

    Produban · Boston, USA

    Technical lead for the cybersecurity services delivered to Santander Bank in the US, embedded in the IT Risk department.

    • Implemented Tenable Security Center for vulnerability scanning and Splunk Enterprise as the SIEM.
    • Led a review and rebuild of the configuration on every network security device in the estate.
    • Ran SSL certificate management, vulnerability management, and firewall management.
    • Automated the security tooling and the performance and compliance reporting around it.
    • Second-level response on security incidents.
  10. 2014 → 20151 yr 3 mos

    Senior IT Security Consultant

    C.G.S.I. · Caracas, Venezuela

    Technical lead across financial and retail clients — I designed the solutions, built them, and then operated them.

    • Implemented and managed FortiGate and McAfee firewalls and IPS, Arbor anti-DDoS, McAfee web and mail gateways, FortiMail, FortiWeb, FortiBalancer, and FortiAnalyzer.
    • Technical lead on big data, SIEM, and credential management with Splunk, LogRhythm, and the ELK stack.
    • Vulnerability detection with McAfee Vulnerability Manager, Nessus, Metasploit Pro, Qualys, and GFI LANguard.
    • Penetration testing across wireless, Windows, Linux, and web applications.
    • Technical lead on social engineering assessments for large banking and insurance clients.
    • Automated the vulnerability scanning process through the Qualys API.
  11. 2013 → 20149 mos

    Network and Security Specialist III

    Dayco Telecom · Caracas, Venezuela

    Security architect for the core infrastructure and the biggest clients — I drew the designs and then implemented them myself.

    • Designed the network and perimeter security for the new datacenter in Valencia, Venezuela.
    • Built the proof-of-concept labs for Cisco, Corero, Sourcefire, Palo Alto, and Fortinet, and took the recommendation to the executive team.
    • Optimised the core security platform; ran McAfee IPS, FortiGate, and FortiAnalyzer.
    • Vulnerability scans with Nessus, Acunetix, OpenVAS, and w3af, plus manual work in Kali — Metasploit, sqlmap, nmap, cisco-torch.
    • Built open-source monitoring with Cacti and network weathermaps; third-level incident response; trained the internal staff.
  12. 2012 → 20131 yr 6 mos

    Network and Security Specialist II

    Dayco Telecom · Caracas, Venezuela

    Second-level response for the most important clients — banks, supermarkets, lottery, and insurance.

    • Managed Cisco routers and switches, BlueCoat PacketShaper, 3Com switches, Cisco ASA, and Fortinet firewalls.
    • Fault detection with packet capture and protocol analysis, including Wireshark.
    • BGP, OSPF, EIGRP, STP, EtherChannel, VTP, HSRP, switch stacks, firewall clusters, site-to-site IPsec and SSL VPNs.
    • WAN technologies — Frame Relay, Metro Ethernet, MPLS — and QoS.
    • Platform documentation, licensing, procedure manuals, and internal training.
  13. 2011 → 20132 yrs 6 mos

    Cisco Network Instructor

    Cisco Networking Academy · Caracas, Venezuela

    Instructor for modules I through IV of the CCNA program, as a CCAI-certified instructor.

  14. 2011 → 20121 yr

    Telecommunications Specialist III

    Banco Agrícola de Venezuela · Caracas, Venezuela

    Security architect for the bank's new main datacenter — I designed every security control in it and implemented them end to end.

    • Firewalls, IPS, email security, and Cisco Access Control.
    • Ran the nationwide telecommunications platform, optimised EIGRP, and stood up OpenNMS monitoring.
    • Cisco Call Manager IP telephony and voice E1 circuits.
    • Encrypted connections to other banks and service providers; VPNs for remote access.
    • Layer 2 security — port security, dynamic ARP inspection, DHCP snooping, IP source guard, spanning tree optimisation — and QoS across WAN links.
  15. 2010 → 201111 mos

    Telecommunications Analyst

    Ministerio de Agricultura y Tierras · Caracas, Venezuela

    My first job out of university, and the one where I learned the stack from the wire up.

    • Ran the switches and access points, and chased WAN faults across Frame Relay and Metro Ethernet.
    • Administered Cisco Call Manager and rolled VoIP out to the remote offices, including voice controllers on the routers and QoS policy to carry it.
    • Managed FortiGate firewalls and FortiAnalyzer.
    • Analysed internal and external network security with Nessus, Nmap, and Metasploit.
    • Implemented layer 2 LAN security, ran the OpenNMS monitoring server, configured Linux DNS, and inspected the remote office networks in person.
  16. 2006 → 20104 yrs

    Telecommunications engineering

    UNEFA · Caracas, Venezuela

    Universidad Nacional Experimental Politécnica de la Fuerza Armada Nacional, Caracas. Telecommunications engineer.

    • Third place with team Rapid-one in the OPEN category at the 8th Latin American Robotics Competition, Valparaíso, Chile, 2009 — the run is on YouTube.
    • Second place, Municipal Prize for Science, Technology and Innovation "Dr. Humberto Fernández Morán", higher education category, Caracas, 2011.

16 hops · trace complete

Certifications

jp@nyc:~$

Verified on GIAC ↗ · Credly ↗

17 records

Get in touch

jp@nyc:~$

Discuss cybersecurity engineering, transformation, or research

Thirty minutes to compare notes on security leadership, technical strategy, offensive and defensive engineering, or AI-enabled security.

Book a call