Security Engineering · Software Development

I build secure systems
teams can trust.

Specialized in secure software development, security audits, and vulnerability assessment, applying best practices throughout the entire development lifecycle.

View my work
00The author
Álvaro Reyes

Fig. 00
Álvaro Reyes

01Status
Open to new opportunities
Get in touch
02Focus

Threat modeling, secure SDLC, and vulnerability assessment on one side. Java, Python, and full-stack development on the other.

03Latest writing
The Tale of Impact
04Elsewhere
01About

Most teams hire a developer or a security specialist.
I do both.

I am a passionate software engineer with strong skills in software development as well as in security analysis. I have experience in secure software development, threat modeling and risk management, helping teams identify vulnerabilities and build safer, more reliable applications. I am comfortable blending coding expertise with security best practices to create solutions that are both functional and secure.

Long-term goals

I enjoy solving complex problems, identifying risks, and protecting systems without slowing teams down.

01Security-first delivery

I identify risks early and embed security best practices without slowing delivery.

02Standards & threat modeling

ISO 27001, PCI-DSS, HIPAA — applied through structured threat modeling and actionable security content.

03Continuous depth

From post-quantum cryptography research to production fraud systems — always learning, always shipping.

You get one person who can own secure development end to end: find what's exposed, ship the fix, and keep systems reliable without a ticket queue.

How it works
01Assess

What's vulnerable, manual, or misaligned with standards

02Build

The secure code, controls, or tooling that closes the gap

03Operate

Monitoring, reviews, and iteration. Same person.

02Experience

A decade securing systems, end to end.

From banking fraud platforms to enterprise threat modeling — building reliable software with security woven in from day one.

Role
CEO & Co-founder
Mirror
2026 – Present
Highlights from current role
• Defined product vision and MVP for a wardrobe-focused styling assistant • Building the mobile app end-to-end while the product is in active startup development • Designing the core flow around daily outfit decisions and personal style
IndexSelected roles
01

CEO & Co-founder

Mirror · 2026 – Present

Building Mirror, a mobile app that helps people dress with more confidence by taking the guesswork out of everyday outfit decisions. Leading product direction and technical development in the early startup phase — from shaping the core styling experience to shipping features that help users plan looks, combine pieces from their wardrobe, and make faster, better choices.

Impact• Defined product vision and MVP for a wardrobe-focused styling assistant • Building the mobile app end-to-end while the product is in active startup development • Designing the core flow around daily outfit decisions and personal style

02

Threat Modeling Teacher

CENTIC · May 2025 – Present

Deliver introductory threat modeling workshops as the opening module of a broader security training program. Teach practical threat identification and mitigation using industry methodologies such as STRIDE and LINDDUN, tailored to mixed technical and non-technical audiences.

Impact• Recurring workshops with ~26 students per class • Practical threat identification and mitigation for mixed audiences • Methodologies covered include STRIDE and LINDDUN

03

Lead Security Research Engineer

IriusRisk · March 2020 – May 2026

Responsible for applying knowledge of current security standards such as ISO 27001:2023, PCI-DSS v4.0, and HIPAA to various security initiatives. Conducted threat modeling activities by integrating these standards to identify and evaluate potential security risks. Developed and maintained detailed threat model content based on trusted sources of information, ensuring that security measures are aligned with industry best practices and current regulatory requirements.

Impact• Enhanced threat modeling coverage by 40% across enterprise clients • Reduced security content creation time by 25% through automation improvements • Contributed to security standards compliance for 50+ client implementations

04

Senior Java Developer

Minsait by Indra · August 2017 – February 2020

Contributed to projects within the Risk & Fraud Management area of the BBVA Security Department. Developed and maintained Java-based applications aimed at enhancing the bank's risk detection and fraud prevention capabilities.

Impact• Improved fraud detection accuracy by 15% in banking security systems • Reduced system response time by 30% through code optimization • Enhanced system reliability with 99.9% uptime in production environments

05

Fullstack Java EE Developer

DEKRA · September 2016 – March 2017

Involved in the development and maintenance of various projects, including mobile applications, Configuration Management Databases (CMDBs), and maintenance roles. Contributed to designing, implementing, and supporting these solutions to ensure their functionality, performance, and continual improvement.

Impact• Developed mobile applications serving 10,000+ users • Improved CMDB system performance by 40% through database optimization • Reduced maintenance time by 35% through automated deployment processes

Education
Universitat Oberta de Catalunya
Master's Degree in Security in Information and Communication Technology · 2016-2018

State of the art in post-quantum cryptography and McEliece/Niederreiter simulators This project summarizes the most relevant research developments, standardization efforts, and recent advances in the field, as well as the simulators and tools available for analyzing, implementing, and evaluating the performance and security of these schemes.

University of Málaga
Bachelor's Degree in Computer Engineering, Information Systems · 2011-2016

Attacks on IPv4/IPv6 networks This project addresses common vulnerabilities in these protocols and examines different attack techniques used in IP networks, as well as their potential impact on the availability, integrity, and confidentiality of communications.

Competitions
ECSC National Selection Aspirant
INCIBE · CyberCamp CTF · 2017

Selected as an aspirant for Spain's national team in the European Cyber Security Challenge through INCIBE's CyberCamp Individual CTF pipeline. Ranked among the top 25 candidates in the national selection process.

HighlightQualified for the on-site CTF final at CyberCamp Santander, competing against the country's top cybersecurity talent.

03Projects

Projects where security and code meet.

Here I showcase a collection of projects, both large and small, that I have worked on

IndexSelected builds
01

Post-Quantum Cryptography Research

research

An in-depth academic initiative exploring post-quantum algorithms and practical simulation of code-based cryptosystems.

OutcomesWorking cryptosystem simulations · Security and performance findings · Migration recommendations

Python · Cryptography · Mathematical Modeling

02

STRIDE Classifier

security

Automatic threat classification system based on machine learning techniques that categorizes threats according to the STRIDE model.

OutcomesAutomatic threat classification · Improved risk management · Reduced time in threat analysis

Python · Machine Learning · Multi-label Classification

03

IriusRisk Threat Content CLI

development

Command-line application that accelerates threat modeling workflows by generating import-ready IriusRisk XML. Given a component, it suggests relevant threats and countermeasures and automatically maps metadata such as MITRE ATT&CK techniques, CWEs, STRIDE categories, and related security taxonomies.

OutcomesFaster threat model content creation · Consistent taxonomy mapping · Reduced manual metadata configuration

Python · CLI · AI · XML · IriusRisk · Threat Modeling · MITRE ATT&CK · CWE · STRIDE

04

Microservices Load Testing GUI

development

Graphical load testing tool built with Java Swing to stress-test a fleet of microservices under configurable traffic profiles. Supports mutual TLS authentication, parallel and concurrent requests, and aggregated reporting to verify that the platform can sustain expected production load.

OutcomesValidated platform capacity targets · mTLS behavior verified under load · Repeatable performance test workflows

Java · Swing · mTLS · Load Testing · Microservices · Concurrency

05

Nonograms Solver

development

Automated system that combines computer vision and solving techniques to intelligently solve nonogram puzzles.

OutcomesAutomatic nonogram solving · Demonstration of applied AI techniques · Educational tool for algorithms

Python · OCR · Machine Learning · Computer Vision

06

IPv4/IPv6 Security Analysis

research

A practical investigation of attack vectors, protocol weaknesses and mitigation strategies in mixed network infrastructures.

OutcomesVulnerability catalog · Proof-of-concept demonstrations · Hardening guidelines

Network Security · Protocol Analysis · Security Assessment

07

QR Transmitter

security

Covert communication system that uses QR codes to transfer information between devices while maintaining a low detection profile.

OutcomesFunctional covert communication · Evasion detection techniques · Demonstration of stealthy attacks

Python · QR Generation · Secure Communication

08

Winrar Brute Force Cracking Tool

security

Security analysis tool that implements optimized brute force algorithms for password recovery in compressed files.

OutcomesEfficient password recovery · Vulnerability demonstration · Security audit tool

Java · Brute Force Algorithms · Cryptography

09

Risk and Fraud Management Platform

security

Enterprise-grade backend focused on high-volume transaction analysis, secure integrations and actionable monitoring.

OutcomesImproved fraud detection speed · Reduced false positives · Stronger traceability and reporting

Java · Spring Boot · PostgreSQL · Security Frameworks

10

CaixaManager

development

Financial management system that automates the processing of bank statements and provides analysis and account control tools.

OutcomesAutomated account management · Detailed financial analysis · Reduced time in administrative tasks

Java · Python · Excel · Data Analysis

11

Project Jin

development

2D horror game developed with the Godot engine that combines survival mechanics with an immersive horror atmosphere.

OutcomesComplete functional game · Immersive user experience · Game development demonstration

Godot · GDScript · Game Design · 2D Graphics

12

Volume Manager

development

Mobile application that allows remote control of the volume of network-connected devices through an intuitive and secure interface.

OutcomesFunctional remote control · Intuitive user interface · Multi-platform solution

Expo · React Native · Network Communication · Device Control

13

CopiaSeg

development

Backup data system that automates the creation and management of backups with flexible configurations and change tracking.

OutcomesAutomated backup system · Efficient backup management · User-friendly interface

Java · File Management · Automation · User Interface

14

Idealisbot

development

Scraping tool that automates the extraction of information about real estate properties for analysis and market comparisons.

OutcomesAutomated data extraction · Property database · Real estate analysis tool

Python · Web Scraping · Data Extraction · Information Processing

15

Rodrigo Voice Assistant

development

Virtual assistant that allows the execution of commands and tasks through voice recognition, similar to commercial assistants.

OutcomesFunctional virtual assistant · Accurate voice recognition · Task automation through voice

Python · Voice Recognition · Natural Language Processing · Automation

16

MidiPART

development

Music analysis system that uses artificial intelligence to evaluate the complexity of piano pieces from MIDI files.

OutcomesAutomatic difficulty evaluation · Music analysis tool · CLI and client-server interface

Python · AI · Music Analysis · CLI · Client-server

04Skills

The stack behind secure applications,
audits, and tooling.

Security standards and analysis on one side. Backend, frontend, and cloud on the other. Most of my work lives where they intersect.

IndexCapabilities
01

Programming Languages

JavaPythonJavaScript & TypeScriptSQLCPHPMATLABGroovyBashPowerShellHaskell
02

Frameworks & Libraries

Spring BootSpring FrameworkReactReact NativeExpoNext.jsAngularNode.jsDjangoFlaskTyperFastAPIPyTorchGDScript
03

Databases

PostgreSQLMongoDBMySQLOracle DatabaseSQLiteRedisDynamoDBNeo4jElasticsearch
04

Security & Standards

ISO 27001:2023PCI-DSS v4.0HIPAAThreat ModelingRisk ManagementOWASP Top 10Secure SDLCZero Trust ArchitectureOAuth 2.0OpenID ConnectSAML 2.0JWTEncryption (AES, RSA)Public Key Infrastructure (PKI)Identity and Access Management (IAM)Vulnerability ManagementPenetration TestingSecurity AuditingData Protection & PrivacyGDPR Compliance
05

Tools & Technologies

AWSDockerGitGitHubBitbucketKubernetesTerraformJenkinsSwagger / OpenAPIGitHub ActionsPrometheusGrafanaXAMPP StackELK StackPostmanNginx
Certs & credentials
CISSP
ISC2
English 4SKILLS MCER B2
TOEIC
CryptoCert Certified Crypto Analyst
CryptoCert
Forensic tools and pentesting procedures
University of Málaga
Web Server & Web Application Security
IEEE Xplore
IriusRisk Threat Modeling DeRisker
IriusRisk
Android: Mobile App Development
MiriadaX

Security-by-design isn't a phase — it's how I ship. Threat modeling, standards compliance, and clean code take ideas to production with confidence. built to last.

Soft skills
Problem Solving

Analytical mindset for complex technical challenges.

Team Collaboration

Cross-functional and remote team experience.

Communication

Can explain technical topics to non-technical audiences.

Continuous Learning

Always improving with new technologies and trends.

Agile Methodologies

Hands-on with Scrum and Kanban.

Security-by-Design

Security is considered from day one.

05Contact

Looking for security engineering, secure development, or both. Let's talk.

Send a message
Based in

Málaga, Spain
Remote friendly

Elsewhere

Always down to talk threat modeling, secure architecture, and what's broken in your stack.

Álvaro Reyes2026