The short versionTwelve years, one recurring obsession.
I started in a research lab, not a SOC. My PhD at EURECOM was spent standing up honeypots on the open web and reading what came back: thousands of attackers poking at deliberately weak applications, then doing whatever they actually do once they are inside. That habit of studying behaviour first and writing rules second has followed me into every job since.
From there I went industrial. At Amadeus I built the automation layer for three SOC teams, including an in-house SOAR and the pipelines feeding three different SIEMs. At Glovo I hired and led a cyber defense team of four, and learned what incident command feels like when the company is still trading through the incident. At Dataiku I was the first dedicated security engineer, which meant writing the procedures, choosing the tooling and answering the auditors, all in the same quarter.
Today I am at Aramis Group, building a group-wide threat monitoring and response platform on open source foundations for subsidiaries across several countries. Detection as code, automation wherever a human is doing something twice, and standards that the engineering teams can actually live with.
PublishedPeer reviewed, and still relevant to the day job.
Automatic Extraction of Indicators of Compromise for Web Applications
International World Wide Web Conference, WWW 2016
Attacks Landscape in the Dark Side of the Web
ACM Symposium on Applied Computing, SAC 2017Best paper, security track
Uses and Abuses of Server-Side Requests
Research in Attacks, Intrusions and Defenses, RAID 2016
Uneven Key Pre-Distribution Scheme for Multi-Phase Wireless Sensor Networks
Wireless sensor network security