ESTEBAN ROSALESCV ↓
01 / OVERVIEW
AVAILABLE · COSTA RICA / UTC−6
ESTEBAN ROSALESSECURITY ENGINEER

I protect critical infrastructure through security testing, detection, response and hardening.

My work covers detection engineering, incident response and infrastructure hardening for environments where downtime has a real cost.

SELECTED PROOF / PRODUCTION OUTCOMES
−60%LESS ALERT NOISEWazuh detection tuning
>90%FASTER DEPLOYMENTAnsible security baselines
55→5.8%CRACKABLE CREDENTIALSAssessment through validation
02 / OPERATIONS

Core operational domains

OPS-01

Detection Engineering

  • Wazuh SIEM
  • Log analysis
  • Alert triage
  • Custom detection
  • Malware analysis
OPS-02

Incident Response

  • NIST 800-61
  • Containment
  • Forensics support
  • Timeline reconstruction
  • Root cause
OPS-03

Infrastructure

  • Windows Server
  • Linux
  • Active Directory
  • Proxmox VE
  • VMware
  • Backup & DR
OPS-04

Automation & IaC

  • Ansible
  • PowerShell
  • Bash
  • Configuration baselines
  • Internal tooling
OPS-05

Network Security

  • Firewall design
  • VLAN segmentation
  • VPN
  • DNS / DHCP
  • Zero-trust principles
OPS-06

Security Assurance

  • Risk assessment
  • IT audit
  • Control reviews
  • Remediation tracking
  • Security awareness
03 / CASE FILES

Selected engineering outcomes

These cases show the problem I faced, what I changed and the result I was able to measure.

CASE-00124/7 HEALTHCARE

Detection Engineering / Wazuh

PROBLEM

A 24/7 server environment had fragmented logging, which made security events slow to find and hard to prioritize.

INTERVENTION

I centralized the telemetry in Wazuh, tuned noisy detections and defined a consistent process for reviewing alerts.

OUTCOME / MTTDDAYS → MINUTES
OUTCOME / ALERT NOISE−60%
CASE-002120 ACCOUNTS

Credential Hardening

BEFORE55%
AFTER5.8%
ASSESSDEMONSTRATEREMEDIATEVALIDATE
CASE-003ANSIBLE / VMWARE

Infrastructure Hardening Automation

01 / MANUAL STATEPer-host configurationVariable starting point
02 / APPLY BASELINEAnsible automationRepeatable security state
03 / VERIFYMeasure complianceSurface configuration drift
04 / REMEDIATEConverge and repeat>90% faster deployment
CASE-004MALWARE RESEARCH / AGENT TESLA

Reverse Engineering / Fileless Execution Chain

ANALYSIS

I traced a staged PowerShell chain through Base64 decoding, RC4 decryption, in-memory execution, Assembly.Load and Reflection.

EVIDENCE

I recovered the embedded PE, recorded its SHA1 indicators, checked the file structure and reviewed strings associated with credential theft.

ANALYSIS PATH
01 / INPUTObfuscated PowerShell
02 / TRACEDecode and inspect
03 / EVIDENCERecovered PE
04 / LABS

Home lab & projects

Wild Boar

I built Wild Boar to keep incidents, audits, risks, pentest findings and supporting evidence in one Django application.

Django 6PostgreSQLIncidentsAuditsRisksPentestLog ExplorerReporting
05 / EXPERIENCE

Employment records

EMPLOYMENT / 002
2023.07 — PRESENT · HEALTHCARE / 24×7

Hospital Clínica Bíblica

IT Security & Systems Specialist

Security operations · infrastructure · Wazuh SIEM · incident response · risk assessment · technical security reviews · security awareness.

EMPLOYMENT / 001
2023.01 — 2023.05 · PUBLIC SECTOR

Municipalidad de Carrillo

Security Analyst

Risk assessment · NIST incident response planning · Ansible hardening · internal penetration testing.

06 / CREDENTIALS

Credentials & education

CERTIFICATIONS

ISC2
Certified in Cybersecurity (CC)
TryHackMe
Jr Penetration Tester
Systems Auditing
Detecting Cybersecurity Flaws

EDUCATION

University of Costa Rica
B.S. in Business Informatics · 2019—2022
English
B2 · Instituto Estelar · 2024—2025