Diego Porras

Software Engineer

Seattle, Washington, United States8 yrs 10 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over 10 years of experience in low-level security engineering.
  • Expert in kernel exploitation and firmware security.
  • Led security programs for fintech and insurtech startups.
Stackforce AI infers this person is a Fintech and Cloud Security expert with a focus on low-level security and vulnerability research.

Contact

Skills

Core Skills

Application SecurityDevsecopsVirtualization

Other Skills

API security testingautomated security testinginfrastructure as codeautomationvulnerability discoveryGitHub actionsFirmware securitycloud securitykernel securitySecure Code ReviewSoftware Development SecurityJavaScriptBluetooth Low EnergyBluetoothKernel-based Virtual Machine (KVM)

About

Low-level security engineer and vulnerability researcher with 10+ years of hands-on experience across kernel, firmware, embedded systems, and platform security. I specialize in real-world exploitation, reverse engineering, and building secure foundations for complex systems. I have led and built product security programs at international fintech and insurtech startups, while maintaining deep technical focus on offensive research and defensive architecture. My work spans from breaking systems at the lowest layers to designing hardened security primitives that scale in production environments. Core expertise includes: * Linux kernel exploitation and OS internals * Firmware security, bootloaders, and secure boot chains * Trusted Execution Environments (TEE) and hardware-backed security * Hypervisors, sandboxing, and isolation mechanisms * Embedded and IoT security research * Reverse engineering, fuzzing, and vulnerability discovery I also bring strong experience in application security and platform architecture, including threat modeling, secure design reviews, and end-to-end system hardening. I’m interested in high-impact roles focused on vulnerability research, kernel and firmware security, hardware-backed trust systems, and next-generation platform security. If you're building security-critical infrastructure, silicon-adjacent platforms, or low-level security tooling, I’m open to collaboration.

Experience

8 yrs 10 mos
Total Experience
2 yrs
Average Tenure
4 yrs 7 mos
Current Experience

Vana

Staff security Engineer

Mar 2025Present · 1 yr 2 mos · Remote

  • Founder of the technical security function for a large Fintech operating in multiple countries.
  • Created automated security testing test-suite and framework for API security testing at scale yielding +30 authorization and authentication related vulnerabilities in an automated way.
  • Created a framework to test for regressions once pentest findings are patched,.
  • Created a zero-touch approach for embedded security defaults in infrastructure as-code. This made developers more effective as it removed the cognitive load of securing IaC
  • Created the DevSecops Function for multiple clients through custom Github actions (container based), custom scripts and automation,.
  • Designed the pentest, threat modeling and security automation frameworks for large customers in the health, finance, and embedded devices sectors.
API security testingautomated security testingDevSecOpsinfrastructure as codeApplication Security

Hack the box

2 roles

Ambassador/Leader Hack The Box meetup Guatemala

May 2022Mar 2023 · 10 mos · Guatemala

Secure Code ReviewSoftware Development Security

Leader - HackTheBox meetup Guatemala

Sep 2021May 2022 · 8 mos · Guatemala

  • Guided hacking sessions for students and professionals. Community effort to bring more skilled professionals/hackers to the security industry
Secure Code ReviewSoftware Development Security

Amazon

Product Security Engineer

Oct 2021Present · 4 yrs 7 mos · Seattle, Washington, United States

  • Current: Product security engineer for devices & Hardware.
  • Firmware, hardware, kernel, cloud security.
  • Jan-Jun 2025: Product security engineer for Compute, Hardware and virtualization of the EC2 platform.
  • EC2 is amazon’s cutting edge compute platform, ie’s the foundational stone of every other AWS service. Working in the EC2 platform has allowed me to dive into low level virtualization, kernel, CPU and custom hardware domains.
  • 2022 - 2025: serverless compute services:
  • Lambda, Serverless analytics, Firecracker.
  • I work on regular basis with kernel level changes to host and guests in virtualization environments, language runtimes security, custom containerization technology, virtualization, hardware qualification for compute capacity added to serverless fleets. I’ve had the opportunity to conduct low level product security reviews involving the Linux kernel, KVM, Graviton (amazons own ARM chips), Intel, AMD and amazons own lightweight hypervisor Firecracker.
  • 2021-2022: Previously I worked with S3 and S3 on the edge as product security engineer. s3 is a distributed object storage service offering high durability and availability.
Firmware securitycloud securitykernel securityvirtualizationApplication SecurityVirtualization

Google summer of code

Google summer of Code '21 - OWASP - Security Knowledge framework

Jun 2021Aug 2021 · 2 mos · Greater London, England, United Kingdom

  • Google Summer of Code is a global program focused on bringing more student developers into open source software development. Students work with an open-source organization on a 10-week programming project during their break from school.
JavaScript

Amazon web services (aws)

AWS Community Builder - Containers

Dec 2020Oct 2021 · 10 mos · Guatemala, Guatemala

  • Community Builder for the Containers branch.
  • The AWS Community Builders program offers technical resources, mentorship, and networking opportunities to AWS enthusiasts and emerging thought leaders who are passionate about sharing knowledge and connecting with the technical community.

Healthcare.com

Application security engineer

Apr 2020Oct 2021 · 1 yr 6 mos

  • Act as SME regarding security throughout the whole application lifecycle. Conduct arquitecture review, manual and dynamic code analysis, and application assessments to guarantee the internal and external products fullfil the best security practices. I also create documentation, security requirements, secure coding guidelines and training materials for engineering teams.
  • I assist teams as a security generalist specialized in code, automation and offensive security in order to harden and improve the organization security posture.
Secure Code ReviewSoftware Development Security

Es - estrategia y seguridad

Cyber Security Consultant: Pentesting

Sep 2019Apr 2020 · 7 mos · Guatemala, Guatemala

  • I provided consultancy for different clients. Main duties included:
  • Perform black-box testing on mobile & web applications
  • Perform code reviews and SAST analysis
  • Conduct secure coding and OWASP proactive controls training for engineering teams
  • Conduct internal training on different security technical subjects for Jr Staff
  • Automate reporting and tooling using python
Secure Code ReviewSoftware Development Security

Devel security

2 roles

Tier 2 Soc Analyst - Incindent Handling and response

Promoted

Jun 2018Feb 2019 · 8 mos

  • Validate Tier 1 observations to determine if incident has occured.
  • Follow up for detected incidents.
  • Proactively chase for indicators of compromise in customer network.
  • Execute incident response plan in case of data breach or security incident
  • Generate new IOCs based on findings
  • Skills applied in a common basis: Powershell/BASH, Python scripting,tcpdump analysis, log monitoring, SIEM, reverse engineering (PE, x86,x86_64), memory and disk forensics, web and infrastructure pentesting.
Secure Code ReviewSoftware Development Security

Security Operations Center Analyst - Tier 1

Jun 2017Jun 2018 · 1 yr

  • Security analist. - Blue Team member.
  • Key responsabilities:
  • Analysis of attack trends, indicators of compromise and management of security incidents for clients.
  • Management of managed security solutions: Data loss prevention, antivirus, IDS, Firewalls, SIEM, network monitoring.
  • Tier 1 support for security solutions offered by the company.

Televida mobile marketing

2 roles

Jr Support Engineer

Promoted

May 2015May 2017 · 2 yrs

  • Objectives: Guarantee the stability of billing and content transfer systems for mobile platforms (SVA).
  • Automate daily operations using scripting languages (Python, bash) and compiled languages (java)
  • Features:
  • Monitoring, preventive diagnosis and troubleshooting of platforms for mass exchange of SMS.
  • Monitoring and troubleshooting of linux servers and internal application containers.
  • Generation of reports from SQL structured data and raw logs from different applications.
  • Generation of tickets and monitoring of system failures.

Asistente de soporte de software

Oct 2014Apr 2015 · 6 mos

  • Objectives: Follow up on internal support requests.
  • Features:
  • Review and diagnosis of failure scenarios in applications, processes and servers.
  • Generation of structured data reports (SQL) as raw logs of the systems.
  • Installation and configuration of agents for infrastructure monitoring.

Stackforce found 100+ more professionals with Application Security & Devsecops

Explore similar profiles based on matching skills and experience