FILE://RESUME

Rafael Guevara Hernandez

Cybersecurity Engineer | Threat Intelligence & Incident Response

Professional Summary

Cybersecurity Specialist with 3+ years in threat analysis, incident response, and SOC operations. Applied Mathematics background with strong analytical skills. Experienced in threat intelligence, automating security workflows with Python and AI-driven tools, and communicating findings to technical and executive stakeholders.

Technical Skills

Security Tools Cortex XDR/XSIAM (Palo Alto), Splunk, Panorama, Burp Suite, Metasploit, Nmap.
Network Protocols TCP/IP, DNS, HTTP/S, DHCP, ARP, ICMP, SNMP; packet analysis and inspection.
Frameworks MITRE ATT&CK, Cyber Kill Chain, OWASP Top 10, Zero Trust Architecture.
Programming Python (Advanced), Bash, SQL, Java; REST API integration and workflow automation.
AI & Automation LLM-powered threat analysis, RAG architectures, agentic security workflows.
Languages Spanish (Native), English (IELTS 7/9 – Proficient).

Professional Experience

Senior Cybersecurity Engineer (Security Services Analytics III) Active

  • Lead end-to-end security incident analysis and response across enterprise environments, using Cortex XDR and other detection platforms to identify, contain, and remediate threats.
  • Design and deploy AI-powered automation pipelines (Python, LLMs) to accelerate threat analysis, incident triage, and security reporting – reducing analyst workload and mean time to response.
  • Develop Python scripts integrating security tools via APIs for automated alert correlation and enrichment.
  • Collaborate cross-functionally with engineering teams to refine detection rules and firewall policies.

Cybersecurity Intrusion Specialist – Advanced Threats

  • Analyzed threat event data and evaluated malicious activity across enterprise environments using Cortex XDR and SIEM platforms, triaging and responding to advanced security incidents.
  • Used threat intelligence platforms to enrich investigations and support defensive decision-making.
  • Conducted static and dynamic malware analysis to understand threat behavior and develop effective countermeasures and IOC extraction.

Jr. SOC Engineer

  • Monitored and triaged security alerts via Splunk and FortiSIEM; ensured timely escalation and documentation.

Key Achievements & Projects

TryHackMe – #1 in Mexico

Ranked #1 in Mexico, Top 1% globally. Paths: Red Teaming, Offensive Pentesting, SOC L1/L2.

Open-Source Security Tooling

Built MCP server integrations for AbuseIPDB and VirusTotal (github.com/alephnan), enabling automated IOC reputation lookups and threat enrichment workflows.

AI-Driven Threat Triage Pipeline

Architected a multi-agent AI system for automated incident triage, runbook extraction, and SOAR payload construction.

Education

Instituto Tecnológico Autónomo de México (ITAM)

B.S. in Applied Mathematics  |  Cryptography, Dynamical Systems, Probability

Certifications

  • Palo Alto Networks: Cortex XDR Consultant (PMXdC), Cortex XDR Support Engineer.
  • Fortinet: NSE Level 1–3.  TryHackMe: Red Teaming, Offensive Pentesting, SOC L1&2, Cyber Defense, Security Engineer, Web Fundamentals.

Interests ‐ AI/ML Security & Research

AI Research Agentic workflows, coherence preservation, long-task orchestration, prompt engineering, LLM red-teaming.
AI Frameworks LangChain, AWS Amazon Bedrock, Ollama, Strands; MCP server development.
AI-Driven Security Automated threat detection, incident response automation, intelligent SOC workflows.