host up · new york city, usa · 6 services exposed

Export (PDF) Book a call

jp@nyc:~$

Illustrated portrait of J. Perez Duerto

J. Perez Duerto

Cybersecurity ∩ AI leading security teams

I work where cybersecurity meets artificial intelligence. Large banks hire me to keep attackers out of the firewalls, detection, and access controls their whole business runs on. Smaller companies hire me to build a security practice from nothing. I started out as a network security engineer, building and defending enterprise networks end to end. Somewhere in there a network stopped being plumbing and became a puzzle: learn how a thing really works, then find the way around it. That became the job. Sixteen years later I am still doing it, now on the technologies too new to be safe, and extending the reach with AI.

Where to find me

jp@nyc:~$

PortStateService
443/workopen LinkedInCareer, banking security, and the professional record
22/codeopen GitHubOpen-source tooling I write and share
80/companyopen Red Hound InfoSecPenetration testing, vCISO, and security strategy
8080/writingopen The Red Hound blogEssays on offensive security and defending real estates
1337/ctfopen Hack The BoxMachines and challenges, solved for practice
53/signalopen XShorter thoughts, mostly security

6 services scanned · all open

How I work

jp@nyc:~$

What I do

  • Build and lead cybersecurity teams
  • Design, implement, and run security tooling and infrastructure
  • Bring an offensive mindset to red and purple team exercises
  • Automate security operations and incident response
  • Create and teach cybersecurity training

How I do it

  • I solve problems under pressure
  • I learn fast, with little instruction
  • I explain complex technical things simply
  • I go looking for new challenges
  • I keep developing, deliberately
  • I work in English and Spanish

executive presence, hands still on the keyboard

Certifications

jp@nyc:~$

Verified on GIAC ↗ · Credly ↗

17 records

The route here

jp@nyc:~$

  1. 2024 → now1 yr 10 mos

    Director of Network Security

    Santander Bank, N.A. · New York, USA

    I lead network security across every US entity as part of the US CISO team — setting the technical direction, staying close enough to the controls to argue about their configuration, and pushing the bank's posture past what audit and regulation ask for.

    • Firewalls, IPS, and Web Application Firewalls across the estate.
    • Network Access Control, VPN, and web proxy platforms.
    • Anti-DDoS controls protecting service availability.
    • Cloud network security with the cloud security teams.
    • Cross-functional response to emerging threats.
  2. 2018 → now7 yrs 11 mos

    Founder

    Red Hound Information Security · Remote

    My own consultancy, helping small and mid-sized businesses stay secure — penetration testing, virtual CISO engagements, and security strategy. redhound.us

  3. 2022 → 20242 yrs 5 mos

    Global Cyber Defend Service Manager

    Santander Digital Services · Boston, USA

    Led global cyber defence delivery for Santander worldwide, and mentored the cybersecurity leaders running it region by region. Worked directly with each entity's CISO to keep local engineering aligned with the global picture.

    • Network security, identity and access management, and anti-malware technologies.
    • The Security Operations Center, incident response, and threat detection.
    • Vulnerability management across the group.
    • Brought every new global entity onto the same technical standard.
  4. 2020 → 20221 yr 11 mos

    Head of Protect for North America

    Santander Digital Services · Boston, USA

    Directed a team of 120 across multiple disciplines, covering network security, identity and access management, anti-malware, and end-user protection for Santander in the US, Mexico, and Latin America.

    • Merged 80 engineers from Mexico into one cross-border team.
    • Stood up cybersecurity services for the entities in Mexico, Uruguay, Peru, and Colombia.
    • Kept end-to-end ownership of the security technology stack.
    • Grew engineers into leads, across borders and languages.
  5. 2019 → 20201 yr

    Director of Cyber Security Infrastructure

    Santander Digital Services · Boston, USA

    Built and led a team of 25 engineers across the US, and extended the service to every Santander affiliate in the country.

    • Owned firewalls, proxies, IPS, WAF, NAC, and VPN end to end.
    • Anti-malware, EDR, anti-phishing, web and email security, endpoint DLP, and virtual patching.
    • Hired, trained, and mentored the engineers who ran it.
  6. 201910 mos

    Chief Information Security Officer

    Advoqt Cybersecurity · Boston, USA

    Founded the cybersecurity practice and grew it past 20 new clients a year, hiring and mentoring 15 engineers — while staying on the tools myself for the engagements that needed it.

    • Ran penetration tests and maturity assessments, including one across a large educational system.
    • Designed and executed a cloud migration.
    • Rebuilt a Splunk deployment: lower cost, more detection use cases.
    • Wrote the method for finding and killing superfluous firewall rules at a major financial institution.
    • Deployed an open-source cloud SIEM across 30,000+ endpoints.
    • Applied machine learning to SIEM data for anomaly detection.
  7. 2017 → 20191 yr 3 mos

    Lead Security Engineer

    Advoqt Cybersecurity · Boston, USA

    Hands-on across finance, retail, and telecommunications: ran the web application penetration tests myself, designed and built a Security Operations Center end to end, and set the cloud security direction. Lead instructor and curriculum designer for CyberWarrior Academy alongside it.

  8. 2017 → 20192 yrs

    Co-founder & instructor

    CyberWarrior Academy · Boston, USA

    Master instructor and curriculum designer — EC-Council certifications, hands-on hacking skills, programming for hackers, and professional development.

  9. 2015 → 20172 yrs 7 mos

    Cyber Security Consultant

    Produban · Boston, USA

    Technical lead for the cybersecurity services delivered to Santander Bank in the US, embedded in the IT Risk department.

    • Implemented Tenable Security Center for vulnerability scanning and Splunk Enterprise as the SIEM.
    • Led a review and rebuild of the configuration on every network security device in the estate.
    • Ran SSL certificate management, vulnerability management, and firewall management.
    • Automated the security tooling and the performance and compliance reporting around it.
    • Second-level response on security incidents.
  10. 2014 → 20151 yr 3 mos

    Senior IT Security Consultant

    C.G.S.I. · Caracas, Venezuela

    Technical lead across financial and retail clients — I designed the solutions, built them, and then operated them.

    • Implemented and managed FortiGate and McAfee firewalls and IPS, Arbor anti-DDoS, McAfee web and mail gateways, FortiMail, FortiWeb, FortiBalancer, and FortiAnalyzer.
    • Technical lead on big data, SIEM, and credential management with Splunk, LogRhythm, and the ELK stack.
    • Vulnerability detection with McAfee Vulnerability Manager, Nessus, Metasploit Pro, Qualys, and GFI LANguard.
    • Penetration testing across wireless, Windows, Linux, and web applications.
    • Technical lead on social engineering assessments for large banking and insurance clients.
    • Automated the vulnerability scanning process through the Qualys API.
  11. 2013 → 20149 mos

    Network and Security Specialist III

    Dayco Telecom · Caracas, Venezuela

    Security architect for the core infrastructure and the biggest clients — I drew the designs and then implemented them myself.

    • Designed the network and perimeter security for the new datacenter in Valencia, Venezuela.
    • Built the proof-of-concept labs for Cisco, Corero, Sourcefire, Palo Alto, and Fortinet, and took the recommendation to the executive team.
    • Optimised the core security platform; ran McAfee IPS, FortiGate, and FortiAnalyzer.
    • Vulnerability scans with Nessus, Acunetix, OpenVAS, and w3af, plus manual work in Kali — Metasploit, sqlmap, nmap, cisco-torch.
    • Built open-source monitoring with Cacti and network weathermaps; third-level incident response; trained the internal staff.
  12. 2012 → 20131 yr 6 mos

    Network and Security Specialist II

    Dayco Telecom · Caracas, Venezuela

    Second-level response for the most important clients — banks, supermarkets, lottery, and insurance.

    • Managed Cisco routers and switches, BlueCoat PacketShaper, 3Com switches, Cisco ASA, and Fortinet firewalls.
    • Fault detection with packet capture and protocol analysis, including Wireshark.
    • BGP, OSPF, EIGRP, STP, EtherChannel, VTP, HSRP, switch stacks, firewall clusters, site-to-site IPsec and SSL VPNs.
    • WAN technologies — Frame Relay, Metro Ethernet, MPLS — and QoS.
    • Platform documentation, licensing, procedure manuals, and internal training.
  13. 2011 → 20132 yrs 6 mos

    Cisco Network Instructor

    Cisco Networking Academy · Caracas, Venezuela

    Instructor for modules I through IV of the CCNA program, as a CCAI-certified instructor.

  14. 2011 → 20121 yr

    Telecommunications Specialist III

    Banco Agrícola de Venezuela · Caracas, Venezuela

    Security architect for the bank's new main datacenter — I designed every security control in it and implemented them end to end.

    • Firewalls, IPS, email security, and Cisco Access Control.
    • Ran the nationwide telecommunications platform, optimised EIGRP, and stood up OpenNMS monitoring.
    • Cisco Call Manager IP telephony and voice E1 circuits.
    • Encrypted connections to other banks and service providers; VPNs for remote access.
    • Layer 2 security — port security, dynamic ARP inspection, DHCP snooping, IP source guard, spanning tree optimisation — and QoS across WAN links.
  15. 2010 → 201111 mos

    Telecommunications Analyst

    Ministerio de Agricultura y Tierras · Caracas, Venezuela

    My first job out of university, and the one where I learned the stack from the wire up.

    • Ran the switches and access points, and chased WAN faults across Frame Relay and Metro Ethernet.
    • Administered Cisco Call Manager and rolled VoIP out to the remote offices, including voice controllers on the routers and QoS policy to carry it.
    • Managed FortiGate firewalls and FortiAnalyzer.
    • Analysed internal and external network security with Nessus, Nmap, and Metasploit.
    • Implemented layer 2 LAN security, ran the OpenNMS monitoring server, configured Linux DNS, and inspected the remote office networks in person.
  16. 2006 → 20104 yrs

    Telecommunications engineering

    UNEFA · Caracas, Venezuela

    Universidad Nacional Experimental Politécnica de la Fuerza Armada Nacional, Caracas. Telecommunications engineer.

    • Third place with team Rapid-one in the OPEN category at the 8th Latin American Robotics Competition, Valparaíso, Chile, 2009 — the run is on YouTube.
    • Second place, Municipal Prize for Science, Technology and Innovation "Dr. Humberto Fernández Morán", higher education category, Caracas, 2011.

16 hops · trace complete

Get in touch

jp@nyc:~$

Ask a cybersecurity practitioner anything

Thirty minutes with someone who does this daily — bring the problem you are actually stuck on.

Book a call