Esteban Jimenez
CLEARANCE: TOP SECRET
ID #4471-EC

// OPERATIVE DOSSIER //

ESTEBAN JIMENEZ

RED TEAM OPERATOR // BLUE TEAM & SOC // PURPLE TEAM STRATEGIST

Offensive security researcher focused on Red Team operations, API security, and Active Directory exploitation. Currently Red Team Intern at Telefónica Ecuador (Otecel S.A.): authorized pentests, API security testing, and CIS Benchmark audits. Ranked #1 in Ecuador and Top 50 worldwide on Hack The Box (peak #36, Grandmaster rank, Lvl 91), with all 6 Pro Labs and every Fortress completed. Captain of CyberFlippers and UDLA-Cyber.

Location LOCATION Ecuador · Remote Global
Defense UNIT CyberFlippers · Captain
Achievement RANK #1 Ecuador · Top 50 Global · Grandmaster · peak #36
Organization CURRENT POSITION Red Team Intern · Telefónica · Otecel S.A.
Education ACADEMY Cybersecurity Eng. · UDLA → 2027
Offensive security RED TEAM Defense BLUE TEAM & SOC Intelligence PURPLE TEAM Hardware OT / ICS Bug BUG BOUNTY

Top rank Global Mastery & Recognition

Achievement

Hack The Box

#1 Ecuador · Top 50 Global

Hands-on pentesting platform and enterprise lab environment.

Ranking HTB Nacional
Defense

Holmes CTF 2025

Best LatAm Team · Top 66 Global

Hack The Box's first defensive CTF. All 65 flags captured (100%) across Threat Intel, SOC, DFIR, malware reversing, and memory analysis.

Blue Team Win
Flag

LACC — Digital Forensics

Pre-selected · CyberFlippers

Pre-selected in the Digital Forensics category of the Latin American Cybersecurity Challenge, under the CyberFlippers national team.

Team

CyberFlippers Captain

Ecuador National Team

Competitive team focused on international CTFs and technical training.

Experience Professional Trajectory

Feb 2026 — Status ACTIVE

Red Team Intern

Telefónica Ecuador · Otecel S.A.

Orchestrate authorized offensive assessments across corporate infrastructure: CIS Benchmark audits, API security testing, and Docker image certification in production. Every finding directly reduces the attack surface.

Jul 2024 — Present

CTF Player & Captain

Hack The Box · CyberFlippers · UDLA-Cyber

Lead Ecuador's competitive scene as #1 nationally and Top 50 worldwide (peak #36), Grandmaster rank (Lvl 91). Completed all 6 Fortresses and multiple Pro Labs — Reversing, Forensics, and Pwn. Captain of CyberFlippers (national team) and UDLA-Cyber. Pre-selected for LACC in Digital Forensics.

Apr 2024 — Present

Teaching Assistant · Cybersecurity

Universidad de Las Américas (UDLA)

Train the next generation of security operators. Design and supervise exploitation and defense labs, bringing real-world offensive tactics into the classroom.

Apr 2024 — Present

Bug Hunter

HackerOne

Execute coordinated disclosure of critical web vulnerabilities: XSS, CORS misconfigurations, SSRF, and injections. Manual analysis with Burp Suite against OWASP Top 10 vectors, prioritizing technical impact over report volume.

2023 — 2027

Cybersecurity Engineering

Universidad de Las Américas (UDLA)

Academic foundation in Cybersecurity Engineering — systems exploitation, hardening, and forensic analysis. Graduating 2027.

Grid view Competency Matrix

Offensive security Offensive Operations

Kerberoasting AS-REP Roasting DCSync Golden / Silver Ticket Pass-the-Hash Constrained Delegation EDR / AV Bypass Web & API Pentesting

Hardware Tooling & Languages

Python Bash PowerShell C Burp Suite Pro BloodHound Metasploit Ligolo-ng

Defense Blue Team & DFIR

Threat Hunting DFIR Digital Forensics CIS Benchmark Audits Incident Response Log Analysis (EVTX)

Code Authored Projects

Flipper CyberAttack Suite Flagship

PowerShell · Hardware

Automates the full physical-access assessment cycle: payload deployment, BadUSB emulation, and controlled RF attacks from a single Flipper Zero. Built for red-team ops where dwell time in the field matters.

GitHub View source

API Security Testing Suite

Python · API Security

264 offensive test cases against APIs, mapped to the OWASP API Security Top 10. Covers authentication, authorization, injection, data exposure, and rate-limiting. A single run reveals the real security posture of any endpoint.

Shellcode-Evasion-Suite

Python · Defense Evasion

Evasion framework that studies detection signatures across AV/EDR engines on obfuscated payloads. Iterate evasion techniques — encryption, injection, syscall rerouting — and validate effectiveness against real defenses in-lab.

GitHub View source

BloodHound-Parser

Python · Active Directory

Parses and prioritizes BloodHound attack paths to Domain Admin. Reduces noise from thousands of edges to an actionable set of critical paths, ranked by exploitation probability in the live environment.

GitHub View source

Shodan-Intel-Reporter

Python · Threat Intel

Correlates internet-exposed assets against the known CVE database. Automates remote entry-vector detection and generates prioritized reports that shorten the perimeter exposure window.

GitHub View source

BugBounty-Automation-Setup

Shell · Recon

Provisions reproducible pentesting environments from a clean instance in seconds. Preconfigures recon, enumeration, and exploitation tooling so the operator starts working with zero setup friction.

GitHub View source

Terminal Approach

My work sits between two ideas: understanding how something breaks, and being able to explain it. I focus on Red Team and Active Directory because I enjoy chaining small flaws into a full compromise, always in authorized environments.

Over time I learned that exploitation is not enough: a finding only matters if the team receiving it can reproduce and fix it. That is why I treat the report with the same care as the exploit, keeping an auditor's independence and objectivity.

I keep studying every day. There is always something new to break and, now, to protect.

LinkedIn Let's talk on LinkedIn