Aaron Palacios

Independent security consultant

Cybersecurity first.
Web and automation, built secure.

I harden, build, and automate the web infrastructure small teams depend on — security from the first assessment to the last deploy.

Connect on LinkedIn Lima, Peru · EN / ES
Profile

Secure by design.
Automated by default.

Cybersecurity is my main field. I assess and harden systems first, then build and automate the web infrastructure small teams rely on — security from the start, not bolted on.

My background spans IT operations, system administration, and security — which means I understand how things break before I build them. I work in Spanish and English across Latin America.

How I work

01 Security first
02 Builder
03 Automation
04 Writer

Frameworks

NIST CSF 2.0ISO/IEC 27001Law No. 29733LGPD
Bilingual EN / ES Latin America focus Available for freelance
Work

Selected projects

Engagement details are anonymized to protect client confidentiality.

01

SOC & NOC alert analysis

Challenge

Alert noise buries real threats and drains analyst focus.

Approach

Triaged SOC/NOC alerts by severity and business context, escalated confirmed threats, and turned findings into runbooks.

Outcome

Faster triage, less analyst fatigue.

02

Endpoint detection & response management

Challenge

Enterprise EDR deployed but underused.

Approach

Tuned EDR policies, reviewed alerts, and coordinated response across client environments — matched to each org's risk.

Outcome

Better endpoint visibility, faster containment.

03

Managed phishing simulation program

Challenge

High social-engineering exposure, no benchmark.

Approach

Ran graduated phishing simulations with immediate, blame-free feedback. Results steered training priorities.

Outcome

Click rates fell across three consecutive cycles.

04

Security awareness & training

Challenge

No shared baseline, weak reporting culture.

Approach

Role-based training in plain language, reinforced quarterly. Bilingual delivery (ES/EN).

Outcome

More suspicious-email reports. Security became habit, not a checkbox.

05

OSINT & digital risk monitoring

Challenge

Organizations blind to their external exposure.

Approach

Mapped external footprints — leaked credentials, brand abuse, threat indicators — under strict operational security.

Outcome

Visibility into unknown risk, fed into remediation priorities.

06

Secure web presence & AI-assisted workflows

Challenge

Digital tools built without security from the start.

Approach

Deployed hardened web infra — strict headers, zero-trust access, CSP. Built AI workflows with controls baked in.

Outcome

A+ on public security benchmarks, no added attack surface.

Writing

Essays and newsletter

Why awareness fails when you measure it like an exam

Phishing and the psychology of urgency

Let's work together

Have a project in mind?

Available for freelance — security, web builds, and automation. Reach out and let's talk.