I’m looking to apply my penetration testing and vulnerability assessment skills to improve industrial security. I want hands-on work aligned to ISA/IEC 62443 and ISO 27001 and NIST, with clear mitigation ownership and continuous learning.
Javier Mauricio Carrasco Guzmán
@javiermauriciocarras
Cybersecurity Engineer specializing in OT/ICS and IT pentesting, vulnerability assessment, and AI-assisted exploitation for IT.
What I'm looking for
I’m a Cybersecurity Engineer focused on OT/ICS security, delivering hands-on penetration testing and vulnerability assessment for industrial control systems, IoT, and enterprise IT infrastructure. I’m eJPT certified and actively applying ISO 27001 and ISA/IEC 62443 to identify critical weaknesses, document findings with CVSS scoring, and propose practical mitigation plans.
I specialize in OT/ICS assessments using Nmap, Metasploit, Burp Suite, and MITRE ATT&CK methodology, including SCADA security work and protocol-focused reviews (e.g., Modbus/DNP3). I also bring Active Directory offensive security experience—building and running penetration testing labs, including privilege escalation and post-exploitation workflows—while using OSINT and AI-assisted pentesting to accelerate reconnaissance and attack-surface analysis.
Experience
Work history, roles, and key accomplishments
Software Developer
Tyssa S.A. de C.V.
Jan 2023 - Jan 2024 (1 year)
Implemented a phased defense-in-depth mitigation strategy and developed automation modules to reduce manual operation time in internal processes. Improved legacy systems and contributed custom exploitation scripts for operational continuity and compatibility.
Penetration Testing
Instituto Politécnico Nacional (ESCOM)
Jan 2020 - Jan 2024 (4 years)
Performed penetration tests on web application APIs, identifying SQL/command injection issues, exposed endpoints with sensitive data, and DoS vectors. Applied OWASP methodology to guide testing and reporting.
ICS/SCADA Pentest Workshop
Bsides CDMX
Designed and delivered a technical workshop on penetration testing of Siemens PLCs and industrial networks. Developed custom exploitation scripts in Python as part of the training content.
Active Directory Pentesting Lab
Marvel/Shield.local
Built and documented an Active Directory lab for internal attack scenarios, including initial access using LLMNR/NBT-NS and NTLMv2 hash capture/cracking. Performed post-compromise enumeration and escalation path analysis using BloodHound and ldapdomaindump.
Education
Degrees, certifications, and relevant coursework
Instituto Politécnico Nacional (IPN) — ESCOM
Bachelor of Science in Computer Engineering, Computer Engineering
2020 - 2024
Pursued a B.S. in Computer Engineering at ESCOM (IPN) from 2020 to January 2024.
Instituto Politécnico Nacional (IPN) — CECyT No. 3
High School Diploma, High School
2016 - 2020
Completed high school studies at CECyT No. 3 (IPN) from 2016 to 2020.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Javier Mauricio?
You can contact Javier Mauricio and 90k+ other talented remote workers on Himalayas.
Message Javier MauricioGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
