Security Testing & Quality Assurance — Finding bugs before attackers do.

Pentesting web · QA funcional · AI Systems Testing ·

{/}

<about_me>

eJPT Certified · 13+ years experience · Based in Spain, working worldwide

I’m Estefanía, a cybersecurity and QA specialist with 13+ years of remote experience working for international companies. I find what’s broken, what’s vulnerable, and what doesn’t behave the way it should.
My background combines web pentesting, functional QA and AI systems evaluation — three disciplines that share one core skill: systematic thinking and attention to detail.

(!)

<portfolio>

Code & Projects
Cheatsheets & Write-ups

Code & Projects QA tools, automation scripts, pentest lab documentation and technical projects. View on GitHub →
Cheatsheets & Write-ups A growing knowledge base with pentesting cheatsheets, CTF write-ups and security references — built for practitioners. Open the knowledge base →

{#}

<services>

{«_pentesting «} {«_QA «} {«_IA «}

{«_pentesting «}

Web Pentesting OWASP methodology. Reconnaissance, exploitation and documented report with remediation steps. Web applications, APIs and infrastructure.

{«_QA «}

QA & Security Testing Functional and security coverage in one engagement. Manual testing, API validation, E2E automation and bug reporting with full traceability.

{«_IA «}

AI Systems QA Prompt testing, adversarial evaluation and edge case detection for LLMs. RLHF annotation and rubric design for frontier AI models.

Scroll to Top