Resume
Export PDFRafael Guevara Hernandez
Cybersecurity Engineer | Threat Intelligence & Incident Response
- (+52) 442 287 6755
- rafagh00@gmail.com
- GitHub
- Mexico City
Professional Summary
Cybersecurity Specialist with 3+ years in threat analysis, incident response, and SOC operations. Applied Mathematics background with strong analytical skills. Experienced in threat intelligence, automating security workflows with Python and AI-driven tools, and communicating findings to technical and executive stakeholders.
Technical Skills
| Security Tools | Cortex XDR/XSIAM (Palo Alto), Splunk, Panorama, Burp Suite, Metasploit, Nmap. |
|---|---|
| Network Protocols | TCP/IP, DNS, HTTP/S, DHCP, ARP, ICMP, SNMP; packet analysis and inspection. |
| Frameworks | MITRE ATT&CK, Cyber Kill Chain, OWASP Top 10, Zero Trust Architecture. |
| Programming | Python (Advanced), Bash, SQL, Java; REST API integration and workflow automation. |
| AI & Automation | LLM-powered threat analysis, RAG architectures, agentic security workflows. |
| Languages | Spanish (Native), English (IELTS 7/9 – Proficient). |
Professional Experience
Senior Cybersecurity Engineer (Security Services Analytics III) Active
- Lead end-to-end security incident analysis and response across enterprise environments, using Cortex XDR and other detection platforms to identify, contain, and remediate threats.
- Design and deploy AI-powered automation pipelines (Python, LLMs) to accelerate threat analysis, incident triage, and security reporting – reducing analyst workload and mean time to response.
- Develop Python scripts integrating security tools via APIs for automated alert correlation and enrichment.
- Collaborate cross-functionally with engineering teams to refine detection rules and firewall policies.
Cybersecurity Intrusion Specialist – Advanced Threats
- Analyzed threat event data and evaluated malicious activity across enterprise environments using Cortex XDR and SIEM platforms, triaging and responding to advanced security incidents.
- Used threat intelligence platforms to enrich investigations and support defensive decision-making.
- Conducted static and dynamic malware analysis to understand threat behavior and develop effective countermeasures and IOC extraction.
Jr. SOC Engineer
- Monitored and triaged security alerts via Splunk and FortiSIEM; ensured timely escalation and documentation.
Key Achievements & Projects
TryHackMe – #1 in Mexico
Ranked #1 in Mexico, Top 1% globally. Paths: Red Teaming, Offensive Pentesting, SOC L1/L2.
Open-Source Security Tooling
Built MCP server integrations for AbuseIPDB and VirusTotal (github.com/alephnan), enabling automated IOC reputation lookups and threat enrichment workflows.
AI-Driven Threat Triage Pipeline
Architected a multi-agent AI system for automated incident triage, runbook extraction, and SOAR payload construction.
Education
Instituto Tecnológico Autónomo de México (ITAM)
B.S. in Applied Mathematics | Cryptography, Dynamical Systems, Probability
Certifications
- Palo Alto Networks: Cortex XDR Consultant (PMXdC), Cortex XDR Support Engineer.
- Fortinet: NSE Level 1–3. TryHackMe: Red Teaming, Offensive Pentesting, SOC L1&2, Cyber Defense, Security Engineer, Web Fundamentals.
Interests ‐ AI/ML Security & Research
| AI Research | Agentic workflows, coherence preservation, long-task orchestration, prompt engineering, LLM red-teaming. |
|---|---|
| AI Frameworks | LangChain, AWS Amazon Bedrock, Ollama, Strands; MCP server development. |
| AI-Driven Security | Automated threat detection, incident response automation, intelligent SOC workflows. |