T QASL · Test Security · AppSec Forensic
Conversemos → Let's talk → ← Portafolio ← Portfolio
QASL · Application Security Forensic QASL · Application Security Forensic

QA Tech Lead
especializado en Application Security forense.
QA Tech Lead
specialized in forensic Application Security.

13+ años en QA. Creador de QASL Test Security (CFQI v1.0) — capa de interpretación forense sobre scanners (Semgrep, Trivy, OWASP ZAP, gitleaks, Checkov, MobSF), alineada a OWASP Top 10 2021, OWASP ASVS 4.0 y NIST SP 800-218 SSDF. 13+ years in QA. Creator of QASL Test Security (CFQI v1.0) — forensic interpretation layer over scanners (Semgrep, Trivy, OWASP ZAP, gitleaks, Checkov, MobSF), aligned to OWASP Top 10 2021, OWASP ASVS 4.0 and NIST SP 800-218 SSDF.

SAST SCA DAST IaC Security DevSecOps SBOM · CycloneDX
13+
Años en QA
Years in QA
10/10
Categorías OWASP Top 10 2021
OWASP Top 10 2021 categories
3
Dimensiones forenses · CFQI · D1·D2·D3
Forensic dimensions · CFQI · D1·D2·D3
3
Dashboards Grafana auto-provisionados
Auto-provisioned Grafana dashboards
2
PDFs por audiencia · Executive + Pericial
PDFs per audience · Executive + Forensic
— Tesis técnica — — Technical thesis —

Un scanner sin interpretación es ruido.
Una vulnerabilidad sin grado
es opinión.
A scanner without interpretation is noise.
A vulnerability without a grade
is opinion.

QASL Test Security · CFQI convierte hallazgos en dictamen QASL Test Security · CFQI turns findings into a verdict
I · Núcleo forense I · Forensic core

CFQI · Code Forensic Quality Index

Algoritmo propio que normaliza hallazgos de scanners distintos en un único veredicto: score 0–100 · grado A→F · 3 dimensiones forenses · penalización Λ por riesgo. Defendible matemáticamente ante auditoría. Proprietary algorithm that normalizes findings from different scanners into a single verdict: 0–100 score · A→F grade · 3 forensic dimensions · Λ risk penalty. Mathematically defensible under audit.

CFQI v1.0
3 dimensionesdimensions · A→F · 0–100
Sin promediar · Λ penalty No naive averaging · Λ penalty
De una bolsa de hallazgos a un veredicto numérico From a bag of findings to a numeric verdict
"No promediamos severidades. Las penalizamos." "We don't average severities. We penalize them."

CFQI no es un agregador de scanners (eso lo hacen DefectDojo o Dependency-Track). Es la capa de interpretación forense que se monta encima: convierte una bolsa ruidosa de findings en un score 0–100 con grado A/B/C/D/F sobre tres dimensiones independientes — estructural, comportamental y operacional — más una penalización Λ por riesgo crítico que impide que un proyecto con 1 vulnerabilidad CRITICA "promedie bonito" gracias a 99 hallazgos LOW. Cada decisión es defendible matemáticamente ante auditor, regulador o tribunal. CFQI is not a scanner aggregator (that's what DefectDojo or Dependency-Track do). It's the forensic interpretation layer on top: turns a noisy bag of findings into a 0–100 score with A/B/C/D/F grade across three independent dimensions — structural, behavioral and operational — plus a Λ risk penalty that prevents a project with 1 CRITICAL vulnerability from "averaging nicely" thanks to 99 LOW findings. Every decision is mathematically defensible before an auditor, regulator or court.

D1
Genealogía estructural
Structural genealogy
Raíces del código
Code roots
35% · SAST · IaC

Análisis estático del código y dependencias. Mide la salud del código en reposo. Static analysis of code and dependencies. Measures the health of the code at rest.

D2
Behavior coherence
Behavior coherence
Entrada/salida
I/O behavior
30% · DAST · runtime

Comportamiento bajo ataque dinámico. Mide cómo responde el sistema vivo. Behavior under dynamic attack. Measures how the live system responds.

D3
Operational quality
Operational quality
Runtime real
Live runtime
35% · SCA · secrets · config

Calidad operativa en producción. Secretos expuestos, dependencias vulnerables, misconfig. Operational quality in production. Exposed secrets, vulnerable dependencies, misconfig.

Λ
Penalización riesgo
Risk penalty
Sin promediar
No averaging
CVSS · EPSS · CWE

Castiga severidades CRITICAL/HIGH para que no se diluyan en el promedio. Penalizes CRITICAL/HIGH severities so they don't dilute in the average.

CFQI Forensic Dashboard — 4 gauges D1/D2/D3 + Λ penalty + audit table per project
GRAFANA · CFQI FORENSIC · 4 GAUGES D1·D2·D3·Λ · AUDIT TABLE PER PROJECT GRAFANA · CFQI FORENSIC · 4 GAUGES D1·D2·D3·Λ · AUDIT TABLE PER PROJECT
D1 · D2 · D3
OWASP ASVS 4.0 · NIST SP 800-218 SSDF
Penalización Λ
Λ Penalty
CVSS v3.1 · EPSS · CWE Top 25
Risk model
Risk model
ISO 31000:2018 · Risk Management
SBOM
CycloneDX · NTIA Minimum Elements
II · Herramienta flagship II · Flagship tool

QASL Test Security

Capa de interpretación forense sobre scanners. Stack completo de operación: FastAPI Normalizer con Swagger UI, PostgreSQL 16, 3 dashboards Grafana auto-provisionados y PDF Generator que entrega Executive (3pp) + Dictamen Forense (1p firmable). Forensic interpretation layer on top of scanners. Full operations stack: FastAPI Normalizer with Swagger UI, PostgreSQL 16, 3 auto-provisioned Grafana dashboards and PDF Generator delivering Executive (3pp) + Forensic Verdict (1pp signable).

QASL Test Security
FastAPI · PostgreSQL 16 · Grafana
Privado · Manual operativo + Demo Private · Operational manual + Demo
Application Security · Forensic

De una bolsa de findings a un dictamen. From a bag of findings to a verdict.

No es un agregador de scanners (eso lo hacen DefectDojo o Dependency-Track). Es la capa de interpretación forense que se monta encima: convierte una bolsa ruidosa de hallazgos en un score 0–100 con grado A/B/C/D/F sobre 3 dimensiones (Static · Dependencies · Runtime), entregando dos PDFs separados por audiencia: Executive (3pp · CIO/CISO) y Dictamen Forense (1p firmable · auditores y compliance). Not a scanner aggregator (that's what DefectDojo or Dependency-Track do). It's the forensic interpretation layer on top: turns a noisy bag of findings into a 0–100 score with A/B/C/D/F grade across 3 dimensions (Static · Dependencies · Runtime), delivering two PDFs separated by audience: Executive (3pp · CIO/CISO) and Forensic Verdict (1pp signable · auditors and compliance).

Flujo: scanners → CFQI → dictamen Flow: scanners → CFQI → verdict
Semgrep Trivy OWASP ZAP gitleaks Checkov MobSF
CFQI
Output
Code Forensic Quality Index
Score 0–100 · Grado A/B/C/D/F Score 0–100 · Grade A/B/C/D/F
3
Dimensiones forenses
Forensic dimensions
D1 Estructural (35%) · D2 Behavior (30%) · D3 Operational (35%) · penalización Λ. D1 Structural (35%) · D2 Behavior (30%) · D3 Operational (35%) · Λ penalty.
2
PDFs por audiencia
PDFs per audience
Executive (3pp · CISO) y Dictamen Forense (1p firmable · auditores). Executive (3pp · CISO) and Forensic Verdict (1pp signable · auditors).
3
Dashboards Grafana
Grafana dashboards
Executive · Forensic · OWASP coverage. Auto-provisionados al arranque. Executive · Forensic · OWASP coverage. Auto-provisioned on startup.
6
Endpoints REST · OpenAPI 3.1
REST endpoints · OpenAPI 3.1
FastAPI Normalizer con Swagger UI interactivo. SARIF/JSON ingest. FastAPI Normalizer with interactive Swagger UI. SARIF/JSON ingest.
Stack
FastAPI PostgreSQL 16 Grafana 10.4 PDFKit · Node 18+ Docker Compose v2 Python 3.10+ SARIF/JSON normalizer CycloneDX SBOM
Estándares aplicados
Applied standards
OWASP Top 10 · 2021 OWASP ASVS 4.0 NIST SP 800-218 SSDF ISO/IEC 27001:2022 ISO 31000 · Risk CWE / CVE / CVSS / EPSS
III · Motores integrados III · Integrated engines

Seis scanners. Un solo dictamen. Six scanners. One verdict.

Test Security no compite con los scanners — los normaliza. Cada motor cubre una capa específica del SDLC, todos alimentan el algoritmo CFQI vía SARIF/JSON normalizer y terminan en un solo dictamen. Test Security doesn't compete with scanners — it normalizes them. Each engine covers a specific SDLC layer, all feed the CFQI algorithm via SARIF/JSON normalizer and converge into a single verdict.

6 motoresengines
SAST · SCA · DAST · IaC · Mobile
SARIF/JSON normalizer SARIF/JSON normalizer
Cobertura por capa del SDLC Coverage per SDLC layer
"El que opera sin SAST + SCA + DAST + IaC, no tiene seguridad: tiene esperanza." "Operating without SAST + SCA + DAST + IaC isn't security — it's hope."

Cada uno de los seis motores integrados es el estándar de su categoría: Semgrep para SAST policy-based, Trivy para SCA + container, OWASP ZAP para DAST runtime, gitleaks para detección de secretos, Checkov para Infrastructure-as-Code, y MobSF para mobile SAST sobre APK/IPA. Test Security no los reemplaza — los normaliza vía un FastAPI Normalizer con contrato OpenAPI 3.1 que ingiere SARIF y JSON propietario, los persiste en PostgreSQL 16, y los entrega a CFQI para producir el dictamen final. Each of the six integrated engines is the standard for its category: Semgrep for policy-based SAST, Trivy for SCA + container, OWASP ZAP for runtime DAST, gitleaks for secret detection, Checkov for Infrastructure-as-Code, and MobSF for mobile SAST on APK/IPA. Test Security doesn't replace them — it normalizes them via a FastAPI Normalizer with OpenAPI 3.1 contract that ingests SARIF and proprietary JSON, persists them in PostgreSQL 16, and feeds CFQI to produce the final verdict.

S1
Semgrep
SAST policy-based
Policy-based SAST
2000+ rules · multi-language

Análisis estático con reglas comunitarias y custom. JS, Python, Go, Java, Ruby, TS — sin compilar. Static analysis with community + custom rules. JS, Python, Go, Java, Ruby, TS — no compile needed.

S2
Trivy
SCA + container + IaC
SCA + container + IaC
CVE · CycloneDX SBOM

Escaneo de dependencias, imágenes Docker e IaC. Genera SBOM CycloneDX para compliance. Dependencies, Docker images and IaC scanning. Generates CycloneDX SBOM for compliance.

S3
OWASP ZAP
DAST runtime
Runtime DAST
SQLi · XSS · CSRF · LFI

Escaneo activo sobre el sistema vivo. Baseline + full scan en pipeline CI/CD vía Docker. Active scanning against the live system. Baseline + full scan in CI/CD pipeline via Docker.

S4
gitleaks
Detección de secretos
Secret detection
pre-commit · CI · history

Detecta API keys, tokens, certificados y credenciales en código + historial git completo. Detects API keys, tokens, certificates and credentials in code + full git history.

S5
Checkov
Infrastructure-as-Code
Infrastructure-as-Code
Terraform · K8s · CloudFormation

Análisis de IaC: Terraform, Kubernetes, CloudFormation, ARM, Helm. Policies CIS y custom. IaC analysis: Terraform, Kubernetes, CloudFormation, ARM, Helm. CIS and custom policies.

S6
MobSF
Mobile SAST · APK/IPA
Mobile SAST · APK/IPA
Android · iOS · static + dynamic

Análisis estático y dinámico de aplicaciones móviles. APKs Android e IPAs iOS, malware checks. Static and dynamic mobile app analysis. Android APKs and iOS IPAs, malware checks.

Ingest
Ingest
SARIF + JSON propietario · OpenAPI 3.1
SARIF + proprietary JSON · OpenAPI 3.1
Persistencia
Persistence
PostgreSQL 16 · single source of truth
Procesamiento
Processing
CFQI v1.0 · 3 dimensiones + Λ
CFQI v1.0 · 3 dimensions + Λ
Output
Grafana · 2 PDFs · API REST
Grafana · 2 PDFs · REST API
IV · Cobertura IV · Coverage

OWASP Top 10 · 2021

Cobertura 10/10. Cada categoría tiene scanner asignado, métrica de detección y entrada en el dictamen CFQI. Sin huecos. Sin "lo cubrimos parcialmente". 10/10 coverage. Every category has an assigned scanner, a detection metric and an entry in the CFQI verdict. No gaps. No "partially covered".

10/10 categoríascategories
OWASP Top 10 · 2021
Scanner + métrica + dictamen Scanner + metric + verdict
A01
Broken Access Control
Broken Access Control

Bypass de autorización, IDOR, escalada de privilegios, exposición de objetos. Authorization bypass, IDOR, privilege escalation, object exposure.

OWASP ZAP · Semgrep · auth probes
A02
Cryptographic Failures
Cryptographic Failures

Algoritmos débiles, claves expuestas, datos sensibles en claro, TLS mal configurado. Weak algorithms, exposed keys, sensitive data in clear, misconfigured TLS.

Semgrep · gitleaks · OWASP ZAP TLS
A03
Injection

SQLi, NoSQLi, command injection, XSS, LDAP injection, header injection. SQLi, NoSQLi, command injection, XSS, LDAP injection, header injection.

OWASP ZAP · Semgrep taint · MobSF
A04
Insecure Design
Insecure Design

Threat modeling ausente, patrones inseguros, lógica de negocio sin controles. Missing threat modeling, insecure patterns, business logic without controls.

ASVS review · architecture audit
A05
Security Misconfiguration
Security Misconfiguration

Defaults inseguros, headers HTTP faltantes, debug expuesto, S3 buckets abiertos. Insecure defaults, missing HTTP headers, exposed debug, open S3 buckets.

Checkov · OWASP ZAP · Trivy config
A06
Vulnerable Components
Vulnerable Components

Dependencias outdated, CVEs conocidos sin patchear, transitive deps ocultas. Outdated dependencies, known unpatched CVEs, hidden transitive deps.

Trivy · CycloneDX SBOM · CVSS · EPSS
A07
Auth Failures
Auth Failures

Credenciales débiles, brute-force sin rate limit, session fixation, MFA ausente. Weak credentials, no rate limit on brute-force, session fixation, missing MFA.

OWASP ZAP · Semgrep auth · session probes
A08
Data Integrity Failures
Data Integrity Failures

Deserialización insegura, dependencias sin firma digital, CI/CD comprometido. Insecure deserialization, unsigned dependencies, compromised CI/CD.

Trivy · Semgrep · SBOM signing
A09
Logging & Monitoring Failures
Logging & Monitoring Failures

Logs ausentes en eventos críticos, ataques no detectados, sin alerting. Missing logs on critical events, undetected attacks, no alerting.

Grafana · Loki · audit log review
A10
SSRF

Server-Side Request Forgery, acceso a servicios internos vía URLs externas. Server-Side Request Forgery, access to internal services via external URLs.

OWASP ZAP · Semgrep ssrf rules
V · Entregable V · Deliverable

Esto es lo que recibe tu equipo. This is what your team actually gets.

Un documento de una página firmable con expediente, autor, veredicto numérico, hallazgos por dimensión y recomendación accionable. No opinión — algoritmo aplicado sobre tres capas. A one-page signable document with file number, author, numeric verdict, findings per dimension and actionable recommendation. Not opinion — algorithm applied across three layers.

CFQI v1.0
Auditable · Firmable · Defendible Auditable · Defensible · Signable
Dictamen Forense CFQI v1.0 — formato pericial 1 página
Algoritmo CFQI · 3 dimensiones + Λ CFQI algorithm · 3 dimensions + Λ

Veredicto numérico. Recomendación accionable. Numeric verdict. Actionable recommendation.

Cada análisis termina en un documento de una página firmable: expediente numerado, autor identificado, verdicto 0–100 con grado A/B/C/D/F, hallazgos por dimensión y recomendación. No es opinión técnica — es algoritmo aplicado sobre tres capas (estática, dependencias, runtime) más penalización Λ por riesgo crítico. Every analysis ends in a one-page signed document: numbered file, named author, 0–100 verdict with A/B/C/D/F grade, findings per dimension and a recommendation. Not technical opinion — algorithm applied across three layers (static, dependencies, runtime) plus Λ penalty for critical risk.

  • D1 · Genealogía estructural — 35% · raíces del código.D1 · Structural genealogy — 35% · code roots.
  • D2 · Behavior coherence — 30% · entrada/salida.D2 · Behavior coherence — 30% · I/O.
  • D3 · Operational quality — 35% · runtime real.D3 · Operational quality — 35% · live runtime.
  • Penalización Λ por riesgo · sin promediar dimensiones.Λ risk penalty · no naive averaging.
VI · Para reclutadores VI · For recruiters

Tipos de vacantes que encajan Roles that fit

13+ años en QA, especialización profunda en Application Security forense y DevSecOps. Disponible para roles full-time, contract o freelance — Buenos Aires presencial o remoto LATAM/Global. 13+ years in QA, deep specialization in forensic Application Security and DevSecOps. Available for full-time, contract or freelance roles — Buenos Aires on-site or remote LATAM/Global.

Disponibilidad inmediataAvailable now
Buenos Aires · Remoto LATAM/Global Buenos Aires · Remote LATAM/Global
AppSec Engineer · Senior

Application Security Engineer Application Security Engineer

Equipos que necesitan llevar la AppSec del PDF de hallazgos al dictamen defendible. Teams that need to move AppSec from a findings PDF to a defensible verdict.

  • SAST · Semgrep policy-based + reglas customSAST · policy-based Semgrep + custom rules
  • SCA · Trivy + CycloneDX SBOM + CVE/CVSS/EPSSSCA · Trivy + CycloneDX SBOM + CVE/CVSS/EPSS
  • DAST · OWASP ZAP baseline + full scan en CIDAST · OWASP ZAP baseline + full scan in CI
  • Threat modeling · OWASP ASVS 4.0 reviewThreat modeling · OWASP ASVS 4.0 review
  • Reportes pericial-grade · CFQI dictamen + ExecutiveAudit-grade reports · CFQI verdict + Executive
Conversar en LinkedIn → Connect on LinkedIn →
DevSecOps Lead

DevSecOps Lead DevSecOps Lead

Equipos que están metiendo seguridad en pipelines CI/CD con quality gates reales. Teams shifting security into CI/CD pipelines with real quality gates.

  • Security gates en GitHub Actions / GitLab CISecurity gates in GitHub Actions / GitLab CI
  • SBOM CycloneDX · supply-chain complianceCycloneDX SBOM · supply-chain compliance
  • IaC scanning · Checkov · Terraform/K8s/CFNIaC scanning · Checkov · Terraform/K8s/CFN
  • Container security · Trivy + Docker hardeningContainer security · Trivy + Docker hardening
  • Policy as Code · NIST SP 800-218 SSDF alignmentPolicy as Code · NIST SP 800-218 SSDF alignment
Conversar en LinkedIn → Connect on LinkedIn →
Security Champion · Pentest QA

Pentest QA & Mobile Security Pentest QA & Mobile Security

Equipos con apps web/móviles bajo regulación que necesitan red-team interno y mobile SAST. Teams with regulated web/mobile apps that need internal red-team and mobile SAST.

  • Pentest manual + automatizado · OWASP ZAP avanzadoManual + automated pentest · advanced OWASP ZAP
  • Mobile SAST · MobSF Android (APK) + iOS (IPA)Mobile SAST · MobSF Android (APK) + iOS (IPA)
  • Secrets detection · gitleaks pre-commit + historySecrets detection · gitleaks pre-commit + history
  • OWASP Top 10 2021 · 10/10 coberturaOWASP Top 10 2021 · 10/10 coverage
  • Compliance PCI-DSS · ISO 27001 · ISO 13485Compliance PCI-DSS · ISO 27001 · ISO 13485
Conversar en LinkedIn → Connect on LinkedIn →
VII · Sectores AppSec VII · AppSec sectors

Donde una vulnerabilidad no es opinión. Where a vulnerability isn't opinion.

Verticales con auditoría regulatoria, datos sensibles y consecuencias legales por brechas. Cada sector recibe el dictamen pericial CFQI alineado a su marco normativo específico. Verticals with regulatory audit, sensitive data and legal consequences for breaches. Each sector receives the CFQI forensic verdict aligned to its specific compliance framework.

B

Banca & Fintech Banking & Fintech

Core banking, gateways de pago, PSD2, open banking. Donde un IDOR o un SQLi cuesta multas regulatorias. Core banking, payment gateways, PSD2, open banking. Where an IDOR or SQLi costs regulatory fines.

PCI-DSS · ISO 27001 · BCBS 239 · SWIFT CSCF
S

Salud & HealthTech Healthcare & HealthTech

HIS, PHI, telemedicina, dispositivos médicos conectados. Compliance HIPAA + ISO 13485 + GDPR sanitario. HIS, PHI, telemedicine, connected medical devices. HIPAA + ISO 13485 + healthcare GDPR compliance.

HIPAA · ISO 13485 · HL7 FHIR · MDR
G

Gobierno & Defensa Government & Defense

Sistemas públicos, RFPs con requisitos AppSec, infraestructura crítica. Auditable end-to-end. Public systems, RFPs with AppSec requirements, critical infrastructure. End-to-end auditable.

NIST SP 800-218 · ISO 27001 · IEEE 1028 · NDA
E

Enterprise SaaS Enterprise SaaS

Multi-tenant SaaS, APIs públicas, integraciones B2B. SOC 2 Type II + ISO 27001 + due diligence de clientes. Multi-tenant SaaS, public APIs, B2B integrations. SOC 2 Type II + ISO 27001 + customer due diligence.

SOC 2 · ISO 27001 · OWASP ASVS 4.0 · CycloneDX
VIII · Marco normativo AppSec VIII · AppSec compliance framework

Respaldado por estándares AppSec vigentes Backed by current AppSec standards

Ningún criterio inventado. Cada métrica CFQI y cada scanner integrado se apoya en estándares públicos vigentes que cualquier auditor o regulador puede cross-validar. No invented criteria. Every CFQI metric and every integrated scanner rests on current public standards any auditor or regulator can cross-validate.

8 estándares AppSecAppSec standards
OWASP + NIST + ISO + IEEE + PCI
Cross-validable por auditor Auditor cross-validatable

El framework no inventa categorías propias para clasificar vulnerabilidades. Cada control y cada métrica se apoya en estándares públicos AppSec vigentes reconocidos por gobierno, banca, salud y enterprise — facilitando auditorías, RFPs, due diligence de clientes y compliance regulatorio internacional. The framework doesn't invent vulnerability categories. Every control and every metric is grounded in current public AppSec standards recognized by government, banking, healthcare and enterprise — easing audits, RFPs, customer due diligence and international regulatory compliance.

OWASP Top 10 · 2021
10 riesgos críticos web
Top 10 critical web risks
OWASP ASVS 4.0
Application Security Verification Standard
Application Security Verification Standard
NIST SP 800-218 SSDF
Secure Software Development Framework
Secure Software Development Framework
ISO/IEC 27001:2022
Sistema de gestión de seguridad de la información
Information security management system
ISO/IEC 27034
Application security guidelines
Application security guidelines
ISO 31000:2018
Risk Management framework
Risk Management framework
CWE / CVE / CVSS / EPSS
Taxonomía + scoring de vulnerabilidades
Vulnerability taxonomy + scoring
CycloneDX · NTIA SBOM
Software Bill of Materials estándar
Software Bill of Materials standard
Compliance
Compliance & certificaciónCompliance & certification
Procesos auditables alineados a OWASP ASVS + NIST SSDF + ISO 27001. Listo para SOC 2, PCI-DSS o auditoría regulatoria.Auditable processes aligned to OWASP ASVS + NIST SSDF + ISO 27001. Ready for SOC 2, PCI-DSS or regulatory audit.
Defendibilidad
Defensibility
Dictamen defendibleDefensible verdict
Cada score CFQI tiene fundamento matemático trazable. Cada hallazgo queda en el expediente. Cero opinión, todo número.Every CFQI score has traceable mathematical foundation. Every finding stays in the audit trail. Zero opinion, all numbers.
Diferenciación
Differentiation
Ventaja en RFP & due diligenceRFP & due-diligence edge
Credibilidad respaldada por estándares · transparencia metodológica · dictamen pericial firmable.Standards-backed credibility · methodological transparency · signable forensic verdict.
Eficiencia
Efficiency
Reducción de ruidoNoise reduction
De 10.000 hallazgos crudos a 1 score con 4 categorías priorizadas. Triage automático con CVSS + EPSS + Λ.From 10,000 raw findings to 1 score with 4 prioritized categories. Auto-triage with CVSS + EPSS + Λ.
IX · Contacto IX · Contact

¿Vacante en AppSec / DevSecOps? Conversemos. Hiring for AppSec / DevSecOps? Let's talk.

Si tu equipo está armando o consolidando la práctica de Application Security y necesita un QA Tech Lead que sepa instrumentar SAST/SCA/DAST/IaC en serio, escribime. Respondo en menos de 24 horas. Buenos Aires presencial · Remoto LATAM/Global. If your team is building or consolidating an Application Security practice and needs a QA Tech Lead who can seriously instrument SAST/SCA/DAST/IaC, drop me a line. I reply within 24 hours. Buenos Aires on-site · Remote LATAM/Global.