Francisco Irio
Application Security Engineer
Heredia Province, Heredia, Costa Rica
12+ Years Exp
Summary
Franscisco Irio, an Application Security Engineer and Senior Penetration Tester with 12 years of experience, excels at collaborating with system owners and developers to enhance security practices. He conducts comprehensive security reviews, identifies vulnerabilities, and proactively addresses risks. Proficient in security assessment tools. Francisco leads assessments, penetration tests, and bug bounty responses. He is skilled in CI/CD tools, utilizing Jenkins for pipeline security. His toolkit includes BurpSuite, OWASP ZAP, and Fiddler for penetration testing, and Veracode, Snyk, Netsparker, and Whitehat for vulnerability scanning. Francisco excels in conducting thorough security reviews, proposing enhancements, and collaborating with system owners and lead developers to implement security best practices. With a deep understanding of common web application vulnerabilities, such as XSS and CSRF, Francisco is well-versed in OWASP Top 10 and their mitigation strategies. He possesses extensive knowledge of computing security fundamentals and is an expert in web frameworks and underlying protocols. As a team player, He actively contributes to the common cybersecurity goal and the company's visiona and has experience working with development and QA teams to ensure application security principles are enforced throughout the SDLC process.
Technical Skills
Detailed View
Work Experience
Senior Application Security Engineer
Equifax
Full Time | 08/01/2023 - Present
Costa Rica
- Conducted thorough penetration testing assessments on diverse systems, networks, and applications, effectively identifying vulnerabilities and potential security risks.
- Took charge of leading and supervising a team of penetration testers, providing expert guidance and mentorship to ensure the delivery of high-quality assessments.
- Fostered seamless collaboration with cross-functional teams, including IT, development, and security, to define and implement robust security measures and best practices.
- Developed and executed customized penetration testing strategies, methodologies, and test plans, aligning them with the organization's specific needs and objectives.
- Maintained a current knowledge of the latest security vulnerabilities, exploits, and industry trends, using OWASP Top Ten and other web application security threats, with a focus on mitigating risks associated with protocol-level vulnerabilities.thereby continuously enhancing the effectiveness of penetration testing activities.
- Conducted in-depth analysis of testing results, generating detailed reports and actionable recommendations for stakeholders, including senior management.
- Played a pivotal role in the remediation process by offering guidance and recommendations to address identified vulnerabilities and weaknesses.
- Led security awareness training sessions and workshops, effectively educating employees on best practices and fostering a security-conscious culture.
- Served as a subject matter expert on penetration testing methodologies, tools, and industry standards, providing invaluable guidance and support to junior team members.
- Participated in incident response activities, contributing to the investigation and mitigation of security incidents as required.
- Maintained meticulous documentation of penetration testing activities, encompassing methodologies, findings, and remediation actions, to ensure compliance with internal policies and regulations.
Penetration Tester
Fiserv
Full Time | 22/06/2014 - 22/12/2022
Costa Rica
- Served as a dedicated Penetration Tester, leveraging Offensive Security Certification and undergoing comprehensive training for Mobile Application Security and Penetration Testing Certification (MASPT) in the current year. The role involved identifying vulnerabilities in Fiserv's applications during the development phase, ensuring their robustness upon release.
- Identified and mitigated SQL injection vulnerabilities in database-driven web applications, ensuring the confidentiality and integrity of data.
- Conducted penetration testing, emulating the tactics of a real-world hacker to uncover potential vulnerabilities and security gaps. This proactive approach enabled developers to promptly address and patch any identified issues, bolstering the overall security posture of the applications.
- Took pride in being a pivotal member of the exclusive Penetration Testers team in Costa Rica, consisting of only three members. This unique position called for the establishment of innovative paths, as well as the implementation of robust processes and procedures to uphold the quality standards of Fiserv's software.
- Collaborated closely with the team to actively engage in various projects, with each member assigned specific roles and objectives aligned with project goals. This collective effort ensured the comprehensive evaluation and enhancement of software security across all initiatives.
Network Monitoring Manager
SBR SportsBook Review
Full Time | 20/04/2014 - 12/06/2014
Costa Rica
- Contributed to SBR, a company providing comprehensive information on major betting houses, enabling customers to make informed decisions by comparing lines and selecting optimal betting options.
- Played a crucial role as a member of the Network Operation Center Team, where he meticulously monitored the network using various specialized tools.
- Utilized JIRA administration tool for effective ticket management, tracking objectives, setting milestones, generating daily reports, and addressing requests.
- Took on additional responsibilities including assisting in the control of the company's IT assets and collaborating with the global team to conduct IT inventory audits, ensuring disaster recovery procedures were well-assured.
- Demonstrated proficiency in proactive monitoring to ensure the entire network operated smoothly, anticipating potential downtimes or compromised servers and devising preemptive plans.
- Analyzed and interpreted network protocols, including TCP/IP, UDP, and IPSEC, to identify vulnerabilities and security threats.
- Conducted security assessments and penetration testing on web applications and services, ensuring the protection of data transmitted over HTTP and HTTPS.
- Held accountability for server maintenance, conducting thorough log reviews, and preparing post-mortem reports to enhance system performance.
- Conducted routine checks for events and performed basic maintenance on the website to guarantee accurate information display, promptly making any necessary adjustments.
- Maintained open communication across the organization regarding infrastructure changes, downtimes, and false positives, while effectively coordinating with the team for backup and restoration processes.
Software Support Engineer
Dell
Full Time | 07/04/2013 - 10/04/2014
Costa Rica
- Played a key role in Dell's integration of Quest (Software Company) in 2012, which involved establishing a dedicated support team in Costa Rica to cater to customers using Quest-developed applications.
- Led teams typically comprising 4-5 members, ensuring seamless support for a range of applications.
- Held the distinct responsibility for the application "STAT" and was the sole authorized member to provide comprehensive support via tickets or live chat to all licensed customers.
Project Portfolio Management Support Engineer
Hewlett-Packard (HP) Software
Full Time | 30/09/2009 - 28/03/2013
Costa Rica
Project Portfolio Management Support Engineer (Jan 2011 - Mar 2013):
- Provided dedicated support for major clients utilizing PPM as their primary Project Management tool, overseeing crucial aspects such as budgets, tasks, roles, employees, and milestones.
- Managed the seamless integration of Project Portfolio Management with Service Center, ensuring a cohesive and effective workflow between the two HP products.
- Leveraged Service Manager as the primary application for Service Desk operations, overseeing critical functions including ticket tracking, customer accounts, schedules, and on-call schedules.
- Effectively managed workload, queries, charts, and daily operational goals within Service Manager, optimizing efficiency and productivity in the Service Desk.
Quality Center Support Engineer (Oct 2009 - Dec 2010):
- Provided crucial support to major clients including NASA, US Army, Coca Cola, and Nestle, ensuring seamless utilization of Quality Center for testing and software development procedures.
- Played a pivotal role in the Quality Team at Hewlett-Packard, dedicated to identifying and implementing best practices, procedures, and training programs to enhance the customer experience.
- Attained a promotion to second-tier support, demonstrating exceptional proficiency in Quality Center, Application Lifecycle Management, Service Manager, and Project Portfolio Management within HP Enterprise Products.
- Met 24x7 On-Call requirements, delivering prompt responses during shift rotations to address customer needs.
- Efficiently triaged and resolved trouble tickets, contributing to a smoother operational flow.
- Spearheaded the definition of metrics aimed at enhancing customer satisfaction and experience.
- Collaborated closely with third-party vendors and contractors, fostering effective partnerships.
- Actively contributed innovative ideas to streamline operational processes and improve overall efficiency.
- Engaged with the Research and Development team to identify and implement patches, fixes, and workarounds, ensuring optimal service delivery for customers.
IT Manager
American International School (AIS)
Full Time | 08/01/2006 - 30/01/2007
Costa Rica
- Successfully led the migration from Windows OS to Ubuntu OS, enhancing system efficiency and compatibility.
- Demonstrated adeptness in the maintenance of servers and the Student Lab, ensuring seamless operations for all stakeholders.
- Spearheaded all computer-related operations at the American International School, overseeing a wide range of responsibilities.
- Engineered a comprehensive redesign of the network layout, catering to the needs of 96 computer clients, resulting in improved service delivery.
- Implemented Linux support for computer clients, established secure file sharing and storage on Microsoft Windows, and ensured uninterrupted Internet access.
- Orchestrated the deployment of four new Linux servers, providing critical services required by the school.
- Managed and maintained a network comprising 90 Edubuntu Clients and 6 Windows XP Clients, ensuring optimal performance.
- Overlooked the maintenance of computers for the Management Team, guaranteeing a seamless working environment.
- Prioritized and met the unique computing needs of students, creating a conducive learning environment.
- Effectively managed the budget for the lab and material procurement, optimizing resource allocation.
- Demonstrated expertise in refurbishing old computers and repurposing used parts to create functional machines, resulting in cost savings and sustainability.
Education
Bachelor's in Computer Engineering
Latin University
Major in Computer Engineering
Certifications

Offensive Security Certified Professional OSCP
Offensive Security | Issued On : {getDate(e?.issued_date)}

Mobile Application Security and Penetration Testing
INE Security (FKA eLearnSecurity) | Issued On : {getDate(e?.issued_date)}