Expertise & Credentials

A bilingual practice built on senior, certified practitioners across security leadership, governance and audit, offensive security, cloud operations, and delivery — with deep experience in healthcare, government, and regulated sectors.

Disciplines

The capabilities we bring to an engagement

Every engagement is staffed from these practice areas according to its scope. Which practitioners are assigned is agreed with you before work begins.

Security Leadership

Governance, Strategy & vCISO

Executive-level security strategy, governance structures, audit readiness, and risk reduction programs — building incident response capability and security architecture aligned to HIPAA/HITECH, NIST, SOC 2, and ISO 27002.

Risk & Compliance

GRC & IT Controls

IT general controls, risk and control matrices (RCMs), risk registers, evidence collection, and remediation tracking — helping healthcare and SMB organizations strengthen governance and prepare for audits under COSO, NIST CSF, CIS, ISO 27001, and HIPAA.

Offensive Security

Penetration Testing & Adversary Simulation

Penetration testing, Active Directory exploitation, vulnerability assessment, and incident response — delivered as technical reports with executive summaries and risk-prioritized findings mapped to MITRE ATT&CK.

Cloud & SecOps

Microsoft Cloud Security & Operations

Security operations across Microsoft Sentinel, Defender, and Entra ID — Conditional Access, MFA, PIM/JIT, threat hunting with KQL, and incident response in hybrid environments aligned to NIST and HIPAA.

Delivery

Business Analysis & Change Management

Operational intelligence and analytics across healthcare, insurance, and energy — EHR implementations, HIPAA-aligned change management, performance dashboards, and translating complex data into decisions leadership can act on.

Engineering

Cybersecurity Engineering

Building and hardening the controls a program depends on — endpoint and email security, logging and monitoring pipelines, backup and recovery, and the day-to-day engineering that turns a policy into an enforced control.

Architecture

Network Architecture

Segmentation, perimeter and firewall design, secure remote access, and network visibility — reviewing existing topology and designing the changes that limit how far an intrusion can travel.

AI Security

AI Governance & Red Teaming

AI governance, risk assessment, and adversarial testing of chatbots, LLM applications, and agents — delivered with NestGovAI, our own red-team platform, and mapped to the OWASP Top 10 for LLM Applications 2026 and MITRE ATLAS.

Credentials

Certifications held across the practice

Grouped by domain. The senior certifications that anchor each area are shown first.

Practice Profile

Who you are working with

Seniority
Practitioners with 15 to 20+ years in security, audit, and technology leadership
Languages
Fully bilingual — engagements, workshops, and deliverables in English or Spanish
Based in
Puerto Rico, serving the island and beyond
Sector experience
Healthcare, government and municipal, telecommunications, insurance, energy, financial and regulated industries, and SMB
Frameworks in practice
HIPAA/HITECH, NIST CSF and 800-53, ISO 27001/27002, SOC 2, PCI DSS, CIS, COSO, IRS Publication 1075, MITRE ATT&CK and ATLAS, OWASP
Community
Active in Puerto Rico's cybersecurity community — BSides Puerto Rico, FiberX, and ISSA

Certifications listed reflect credentials and coursework held across the CyberNest Secure practice, not by any single individual, and are not all held by every practitioner assigned to an engagement. CyberNest Secure provides cybersecurity consulting and advisory services and does not guarantee compliance.

Work with a team that has done this before

Tell us what you are trying to protect and we will tell you which of these disciplines your engagement needs.

Schedule a 30-Minute Consultation