g
gonzaloparra795

Gonzalo P

@gonzaloparra795

Information Security Analyst

Bolivia
Spanish, English
About me
Is your web application truly secure? I'll find the vulnerabilities before attackers do. I'm an Information Security Analyst with 15+ years in the financial sector, specializing in web app penetration testing and GRC. I've completed 100% of the PortSwigger Web Security Academy labs (270/270, incl. Expert level) and hold offensive certs (BSCP, CWES) plus senior GRC credentials (CISM, CISA, CRISC and ISO 31000 LRM). You get real, hands-on exploitation — not just automated scans — plus a prioritized report mapping each finding to business risk and clear remediation steps.... Read more

Skills

g
gonzaloparra795
Gonzalo P
Offline • 

See my services

User Testing
I will perform web app pentesting and manual owasp top 10 security audit

Portfolio

Work experience

Banks

Full-time • 12 yrs 1 mo

National Information Security Analyst

Aug 2021 - Mar 20227 mos

At Banco Unión S.A.: •Strengthened application-layer security by conducting ethical hacking on web applications, identifying and prioritizing vulnerabilities in line with the OWASP methodology, and managing their remediation to closure. •Strengthened the institution's defense posture by overseeing the end-to-end deployment of critical security controls, ensuring operational resilience against internal and external threats. •Reviewed and proposed updates to security policies, standards and procedures to align them with best practices, closing compliance gaps and establishing clear procedural guidelines. •Improved the organization's security posture by comprehensively mapping the attack surface in web infrastructures, successfully identifying hidden assets and reducing uncontrolled entry vectors. •Coordinated risk assessment and mitigation activities across multidisciplinary teams.

INFORMATION SECURITY OFFICER

Apr 2014 - Jun 20217 yrs 2 mos

At Banco Unión S.A.: •Enhanced data protection visibility by coordinating the organization-wide identification and classification of information assets, ensuring critical resources received appropriate security controls based on their sensitivity. •Minimized operational uncertainty by conducting comprehensive risk assessments for new and legacy systems, proactively identifying and neutralizing potential threats before they impacted business processes. •Facilitated data-driven decision-making by producing actionable risk reports that clearly defined severity and mitigation strategies, enabling stakeholders to prioritize security investments effectively. •Secured cardholder data and achieved regulatory adherence by contributing to the implementation of PCI DSS compliance frameworks across critical payment systems. •Cultivated a security-conscious organizational culture by delivering security training, significantly reducing staff susceptibility to social engineering and human error. •Led the administration of access rights and security policies (GPO) in a corporate environment of over 2,000 users, ensuring resource integrity and availability.

INFORMATION SECURITY ANALYST

Nov 2009 - Mar 20144 yrs 4 mos

At Banco Mercantil Santa Cruz: •Conducted detailed risk assessment for new and existing systems in line with recognized security standards and best practices. •Participated in the implementation of ISO 27001 information security management system (ISMS) to strengthen organizational security posture. •Managed the acquisition and implementation of a DLP Solution.