Overview
Work History
Skills
Accomplishments
Additional Information
Timeline
Generic

Francisco Irio

Senior Penetration Tester
Heredia

Overview

2025
2025
years of professional experience

Work History

Senior Penetration Tester

Equifax
1 2023 - Current
  • Conduct comprehensive penetration testing assessments on various systems, networks, and applications to identify vulnerabilities and potential security risks.
  • Lead and manage a team of penetration testers, providing guidance and mentoring to ensure the delivery of high-quality assessments.
  • Collaborate with cross-functional teams, including IT, development, and security, to define and implement security measures and best practices.
  • Develop and execute penetration testing strategies, methodologies, and test plans tailored to the organization's specific needs and objectives.
  • Stay up-to-date with the latest security vulnerabilities, exploits, and industry trends to continuously enhance the effectiveness of penetration testing activities.
  • Perform in-depth analysis of testing results, preparing detailed reports and actionable recommendations for stakeholders, including senior management.
  • Assist in the remediation process by providing guidance and recommendations to address identified vulnerabilities and weaknesses.
  • Conduct security awareness training sessions and workshops to educate employees on best practices and promote a security-conscious culture.
  • Act as a subject matter expert on penetration testing methodologies, tools, and industry standards, providing guidance and support to junior team members.
  • Participate in incident response activities, assisting in the investigation and mitigation of security incidents, as needed.
  • Maintain documentation of penetration testing activities, including methodologies, findings, and remediation actions, ensuring compliance with internal policies and regulations.

Senior Penetration Tester

Fiserv
06.2014 - Current

As a Penetration Tester certified in Offensive Security and trained in Mobile Application Security and Penetration Testing (MASPT), my primary responsibility is to identify vulnerabilities in Fiserv's applications during the development phase. I simulate attacks to uncover security flaws, enabling proactive resolutions that enhance application security before public release.


I am proud to be part of Costa Rica's premier Penetration Testing team, which consists of three dedicated professionals. We are responsible for developing and standardizing procedures that maintain Fiserv's software quality, playing a vital role in project security oversight and ensuring comprehensive coverage.

Network Monitoring Manager

SBR SportsBook Review
05.2014 - 06.2014
  • Costa Rica
  • Responsible to monitor the network making use of several tools to make sure that all services were properly running.

Software Support Engineer

Dell
03.2013 - 05.2014
  • Responsible to provide support for Dell's application STAT through tickets or live chat
  • Only member authorized to provide support to “STAT” application.

Application Lifecycle Management Support Engineer

Hewlett-Packard
10.2009 - 12.2013
  • Responsible to provide support to big customers who owned a license of Quality Center
  • Software utilized to manage the lifecycle and deliver applications in an efficient way.

Poject Portfolio Management Support Engineer

Hewlett-Packard
01.2011 - 05.2013
  • Responsible to provide support for big customers that used PPM as their main Project Management tool, this tool manages budgets, tasks, roles, employees, milestones.

IT Manager

American International School, AIS
01.2006 - 01.2007
  • Rica
  • AIS is a private school located in Cariari, Costa Rica
  • Responsible for all computer related operations
  • Network Layout/Redesign
  • Migration from Windows OS to Ubuntu OS
  • Servers and Students Lab Maintenance.

Skills

Hacking / Cyber Security Reporting & Analysis

PERSONAL PROJECTS

The Pentest Crew Podcast (10/2019 – Present)

Founder of the first podcast in Latinamerica dedicated to cybersecurity

Accomplishments

  • Offensive Security Certified Professional (OSCP)
  • I am presently undertaking diligent studies in preparation for the Foundational Web Application OSWA.
  • Mobile Application Security and Penetration Testing from eLearnSecurity Academy.
  • I directed the development and implementation of the Mobile Penetration Testing program for Equifax, crafting a comprehensive methodology tailored to safeguard their mobile applications. This role involved coordinating with cross-functional teams to integrate advanced security measures, ensuring robust protection against potential threats and vulnerabilities.


  • CONFERENCES & COURSES
  • Instituto Tecnológico de Costa Rica (01/2018)
  • Conducted an informative session at TEC University, providing students with an introduction to the field of ethical hacking. The session included a live demonstration exemplifying advanced techniques employed in securing mobile and web applications, showcasing the attainment of full remote control over portable devices.

Additional Information


  • Operating Systems: Windows, Linux, MacOS, IOS, Android.
  • SIEM Technologies: Splunk, Crowdstrike.
  • Penetration Testing: Burp Suite Professional.
  • DAST/SAST: Snyk, NetSparker, Sentinel, Fortify, Burp Enterprise, Nessus, OpenVAS, Qualys.
  • Cloud Security:Cloud Platforms: AWS, Google Cloud Platform.
  • Scripting and Programming Languages: Python, PowerShell, Bash for automation and developing security tools.
  • Vulnerability Scanning Tools: Nessus, OpenVAS, Qualys.
  • Mobile Pentest: Genymotion, Android Studio, Jailbreak and Rooting toolkits, Frida tools and scripts.

Timeline

Senior Penetration Tester

Fiserv
06.2014 - Current

Network Monitoring Manager

SBR SportsBook Review
05.2014 - 06.2014

Software Support Engineer

Dell
03.2013 - 05.2014

Poject Portfolio Management Support Engineer

Hewlett-Packard
01.2011 - 05.2013

Application Lifecycle Management Support Engineer

Hewlett-Packard
10.2009 - 12.2013

IT Manager

American International School, AIS
01.2006 - 01.2007

Senior Penetration Tester

Equifax
1 2023 - Current
Francisco IrioSenior Penetration Tester