Gustavo Daniel Cortez
Brugge, Belgium · my email (on the CV) · LinkedIn · GitHub
Download CV (PDF)Summary
Hands-on engineer across AI systems, cloud infrastructure, and security. Currently building secure digital solutions at Cor4 Digital: a production on-premise computer-vision safety system, an AI-driven WhatsApp and Telegram reservation platform, and the company's web front ends. Before that, production work on commercial IaaS, on-premise LLMs on dedicated GPU infrastructure, and n8n workflows hardened against prompt injection. Cybersecurity background in full-scope penetration testing, ELK-based threat monitoring, and vulnerability assessment.
Experience
- Computer-vision safety system. Delivered a production system on 8 plant cameras (26 Python modules, an 11-table SQLite store, 3 n8n workflows), covering frame capture through RF-DETR detection, ByteTrack tracking, zone rules and automated Telegram and PDF reporting.
- Accuracy without new hardware. Cut false positives 98% (64 to 1 over 70 frames) and raised true detections 7% (771 to 828) by benchmarking four model sizes, fixing inference resolution and switching the DVR off its substream.
- Private by design. Zero internet egress and no facial recognition: person IDs come from spatiotemporal continuity instead of biometrics. Reverse-engineered a DVR's proprietary DVRIP/Sofia protocol to unblock a client whose unit exposed no RTSP endpoint.
- From one site to a product. One-step install via network auto-discovery and offline installers validated across 7 camera source types. Alert delivery raised to 100% under concurrent violations by re-keying deduplication to per-person identity.
- Restaurant reservation agent. Built the front end and owner dashboard for an AI agent that books tables over WhatsApp and Telegram, in React 19, TypeScript and Tailwind CSS v4, with n8n-backed auth and Google Sheets as the data layer. Staff mark tables occupied and create, edit or cancel bookings from a month calendar and day view, with a 7-second undo on destructive actions. Bilingual, light and dark, every colour pairing audited with a canvas-based contrast checker.
- Company and client websites. Built Cor4 Digital's bilingual company site (React, TypeScript, Vite; app catalogue, consulting, team and contact pages, n8n contact webhook) and a 17-page Spanish and English site for Yorservi S.R.L., an oilfield-services client, with GSAP ScrollTrigger and Lenis scroll choreography, prerendered to static HTML. Security built in: a hash-based Content Security Policy, HSTS and hardened response headers, consent-gated storage and a rate-limited contact form.
- AI ticketing. A production n8n workflow connecting Zammad, Rocket.Chat, PostgreSQL and Qdrant: RAG retrieval with Ollama embeddings, on-premise LLM drafting and confidence-score routing. Estimated to cut 40% of manual L1 support work.
- Private inference. Deployed Qwen 3 30B on GPUStack on a dedicated GPU VM, air-gapped from the public internet, so customer ticket data never leaves the company network.
- Prompt-injection hardening. Strict JSON output schemas and prompt-level rules, verified with adversarial payloads (jailbreaks, instruction overrides, payloads hidden in ticket bodies and image attachments) plus magic-byte validation on attachments. Built a Python test framework for tool abuse, reasoning-chain hijack, confidence manipulation and SQL injection.
- Provisioning as code. Python automation against the whitesky.cloud API to create cloudspaces, spin up VMs, add users and manage resources, removing manual console work.
- Network isolation. OPNsense first-match LAN ruleset with whitelist-based isolation, and WireGuard with per-user /32 tunnel IPs, so backend services are reachable over VPN only.
- Health triage. A second n8n workflow polls the Meneja API every 5 hours, runs each failed healthcheck through an AI agent against a GitLab knowledge base, and posts severity-sorted reports to Rocket.Chat. Kept the Docker fleet (n8n, Ollama, Qdrant, PostgreSQL, pgAdmin) healthy and documented the playbooks.
Freelance
- Internal network vulnerability assessment, residential care organisation. Asset discovery across the internal subnets, authenticated host scanning and manual verification, plus external perimeter and IPv6 checks. Findings scored with CVSS and CWE and delivered as a client report with prioritised remediation.
- Workstation assessment and OSINT review, independent pharmacy. Internal host and service-exposure scan, and an OSINT review of what attackers can learn about the business in public for phishing and fraud. Delivered with plain-language remediation for non-technical staff.
- Client names and findings withheld under confidentiality.
Projects
- 5 Critical, 4 High and 4 Medium findings. Across VPN, DMZ and internal lab segments. Reached SYSTEM-level access through XML-RPC deserialization RCE, Elasticsearch MVEL script RCE, Pass-the-Hash, SNMPv1 misconfiguration and RDP credential interception.
- Lateral movement and subnet pivoting with Metasploit, Impacket and credential harvesting. Delivered an audit report with CVSS scoring, CWE references, topology maps and a remediation roadmap.
- Triaged 2,000+ ModSecurity alerts by attack type and tightened WAF rules against the top patterns, cutting mean time to detection about 30%. A Cowrie SSH honeypot wired to Elasticsearch and Kibana captured 500+ brute-force attempts and SQLMap scans.
- Wraps Nmap with OS fingerprinting, custom NSE scripts, decoy scanning and normalized JSON, XML and grepable output for downstream tooling. Source
- Real-time encrypted messaging backend for 100 concurrent users, with AES-256, async I/O and environment-based secret management. Source
- Exponential, hyperbolic and harmonic decline-curve forecasting behind a Flask interface, with dataset upload and Excel reports. Source
Technical skills
- AI and computer vision
- RF-DETR, ByteTrack, OpenCV, PyTorch (CPU inference), zone and geofence logic, model benchmarking, GPUStack, Ollama, Qwen 3 30B, RAG, Qdrant, prompt engineering, AI agent security testing
- Automation
- n8n (production flows, webhooks), REST APIs, Telegram Bot API, SQLite (WAL), PostgreSQL, automated PDF reporting, schema-validated LLM output
- Front end
- React 19, TypeScript, Vite, Tailwind CSS v4, react-router, GSAP, Lenis, WCAG AA auditing, i18n, light and dark theming
- Video and cameras
- DVRIP/Sofia, RTSP (Hikvision, Dahua, Reolink, Axis), ONVIF discovery, multi-channel NVR, MJPEG over HTTP, USB capture
- Cloud and DevOps
- Docker, Linux, VMware, OPNsense, WireGuard, CI/CD, Bash, Infrastructure as Code, IaaS provisioning; AWS at project level
- Kubernetes
- Talos Linux 3-node cluster, kubectl, NodePort and ClusterIP services, MetalLB, Metrics Server, Horizontal Pod Autoscaling, failure recovery testing
- Security
- Secure SDLC, threat modelling, firewall design, segmentation, Metasploit, Nmap, Burp Suite, OWASP ZAP, Wireshark, Pass-the-Hash, ARP spoofing
- Detection and forensics
- Elasticsearch, Kibana, Filebeat, ModSecurity log analysis, Cowrie, Autopsy and The Sleuth Kit, timeline reconstruction
- Languages
- Python, JavaScript, TypeScript, Bash, SQL, Flask, Java, PHP, C# (.NET) with Supabase PostgreSQL
Education and languages
Bachelor of Applied Computer Science, Cybersecurity Professional
High School Diploma
English and Spanish, both proficient.