whoami

Manuel Roldán

|

Who I am

MR
Open to CISO & Security Leadership roles

Manuel Roldán

Application & AI Security Specialist

@ Veritran · Buenos Aires, Hybrid

20+ years turning security from a blocker into a business enabler. Started in Venezuelan banking, scaled through Argentina's leading fintechs — now building AI-driven security tooling that replaces hours of manual triage with code.

I play both sides: offense (pen testing, red team, vuln research) and defense (SAST/DAST, threat modeling, security champions). Currently focused on the intersection of LLMs × AppSec automation.

0+ years in tech & security
0+ international certifications
2 open-source security tools

core stack

AppSec DevSecOps AI Agents Threat Modeling Red Team SAST / DAST Kubernetes ISO 27001 PCI-DSS

Career timeline

Feb 2025
present
current

Application & AI Security Specialist

Veritran · CABA, Hybrid

AI-driven security tooling for global payments infrastructure. Building SpecIA and autonomous AI agents for vulnerability triage at enterprise scale.

AppSec AI Agents Python SpecIA
Sep 2023
Jan 2025

Application Security Lead

ueno bank S.A. · Remote

Built the AppSec program from zero in a cloud-native fintech. SAST/DAST pipelines, threat modeling, security champions culture, and secure SDLC.

AppSec Program SAST / DAST Threat Modeling
Apr 2022
Sep 2023

Cybersecurity Engineer Leader

Wazuh, Inc. · Remote

Security lead for the world's most-used open source SIEM. Threat modeling, security roadmap, and DevSecOps at global scale.

SIEM DevSecOps Open Source
Feb 2020
May 2022

Cybersecurity Lead — Red & Blue Team · Fintech Security Lead

Naranja X · Pomelo · Buenos Aires

Led Red and Blue teams simultaneously at Naranja X (Argentina's largest fintech). Built cloud security posture from scratch at Pomelo.

Red Team Blue Team Cloud Security
2017
2020

Senior Consultant · SecOps Engineer

BTR Consulting · Despegar.com · gA · Buenos Aires

Cloud pentesting at BTR; Big Data SIEM at Despegar.com; cloud incident response automation at gA. First years in Argentina.

Pentesting SIEM Cloud IR
2006
2017

Specialist → Security Manager → Founder

Banco de Venezuela · Banco del Tesoro · Banco Bicentenario · EntreClicK.com · Venezuela

Foundations in Venezuelan state banking: GRC, hardening, regulatory compliance, and incident response. Simultaneously founded my own offensive security consultancy.

GRC Banking Founder

Áreas de impacto

🛡️

DevSecOps & Automatización

Diseño e integración de SAST/DAST y análisis de dependencias en el SDLC. Pipelines CI/CD seguros por defecto.

🤖

IA Aplicada a Ciberseguridad

Agentes autónomos y bots defensivos con LLMs para automatizar triaje, auditorías y respuesta a incidentes.

📋

GRC & Cumplimiento

Estrategias de ciberseguridad, políticas y alineación bajo ISO 27001 y PCI-DSS. Gobierno de riesgo pragmático.

⚔️

Seguridad Ofensiva & Defensiva

Análisis de vulnerabilidades, penetration testing, threat modeling (OWASP), respuesta a incidentes y forense.

Proyectos destacados

SpecIA
AppSec AI Agents Open Source Spec-Driven Dev

Security-Aware Spec-Driven Development

SpecIA detecta bugs de seguridad críticos antes de escribir una sola línea de código. Analiza los specs de features, identifica vulnerabilidades (auth bypass, XSS, SQL injection, insecure storage) en segundos y audita la implementación para verificar que todas las brechas fueron corregidas. Construido para agentes de IA.

$ specia review oauth-login.md

🔴 Risk Level: CRITICAL

Spoofing — Missing PKCE Flow
   → Authorization code interception = account takeover
   → Fix: Implement PKCE (RFC 7636)

Information Disclosure — Tokens in localStorage
   → Any XSS = full account compromise
   → Fix: Use httpOnly, Secure, SameSite=Strict cookies

Recommendation: BLOCK (must fix before implementation)
Ver en GitHub →

Credenciales

🎓
CEH
Certified Ethical Hacker · EC-Council
🔬
CHFI
Computer Hacking Forensic Investigator · EC-Council
🏛️
CSX
CyberSecurity Fundamentals · ISACA
🌐
CCENT
Cisco Certified Entry Networking Technician
☁️
CCZT
Certificate of Competence in Zero Trust · CSA · feb 2026
🧠
Agile TM
Agile Threat Modeling · Security Journey · dec 2024

Hablemos

¿Querés hablar de AppSec, DevSecOps, IA o simplemente conectar? Encontrame en LinkedIn o explorá mis proyectos en GitHub.