Skip to content

Bray Lozano

I came from IT support, which is what gives me the judgement to know where an infrastructure breaks before having to defend it. I work on the security of an industrial company, and I build my own tools by directing AI agents.

Bray Lozano, cybersecurity technician

Bray LozanoCybersecurity technicianCantabria, España

Right now

Work
Cybersecurity technician · FONESTAR Sistemas
Last published change
September 2026
Learning
The SC-900

What I am working on

ProductActive

Argos

Self-hosted cybersecurity platform for small companies. It brings asset inventory, vulnerability management, threat intelligence, Spanish ENS compliance, backups, device fleet and staff training into a single workflow. It is built as modules, and some stand on their own: Talos came out of it.

Commercial product under development. The code is not public, but the architecture and the decisions behind it can be described.

  • Next.js
  • React
  • TypeScript
  • SQLite
  • Prisma
ToolActive

Talos

Hardening audit for Linux and Windows servers in a single dependency-free binary. Read-only, it never changes anything, and finishes a full server in under ten seconds. It carries 147 checks written as data files, each with its severity, weight, the Spanish ENS controls it covers and how to remediate it. It came out of a larger platform and I released it separately because it stood on its own.

  • Go
  • YAML

★ 1GoSept 2026

WebsiteActive

1mpulso

My own studio, building websites for freelancers and small businesses on a subscription basis. Static sites with security headers and a restrictive content policy, no third-party trackers, and deployments that roll back in one click. The client never has to learn any of it.

The studio's code and its client sites are not public.

  • Astro
  • React
  • Tailwind
  • Cloudflare Pages
ResearchActive

Inyección SQL sin autenticar en Metabase

Metabase published a maximum-severity advisory without explaining the vector, giving only a log signature to search for. Two well-known companies had already confirmed attacks through the same flaw. I built a lab with three containers, two vulnerable versions and one patched, and reconstructed the mechanism by sending identical requests to both: the vulnerable one ran a query the patched one did not, with a value I had not supplied anywhere.

The lab and the proof of concept are not published. The flaw is patched, but thousands of exposed instances remain unpatched, so this describes the mechanism and not how to exploit it.

  • Docker
  • PostgreSQL
  • Burp Suite
  • Análisis de parches

All fourteen projects

Career

  1. Mar 2026 · ongoing

    Cybersecurity technician

    FONESTAR Sistemas

    I work on the security posture of the organisation. I validate and test endpoint and information protection configurations, run risk analysis and take part in incident response alongside the systems team. I support the documentation of the information protection governance framework and the preparation of compliance audits, review security events to catch problems early, and work with systems on cloud environment requirements and vulnerability management. And I am designing the company cybersecurity training plan, which is the part that will reach the whole workforce.

  2. Feb 2026 · ongoing

    Cyber-volunteer

    INCIBE

    I give awareness talks and workshops in Cantabria for children, teenagers, families and educators. I cover school cyberbullying prevention, privacy and digital identity, and run basic training for adults on fraud, malware and secure device configuration. I also point people to official help resources, such as Spain's 017 helpline. I think education is the cheapest security control there is, and I am available to any school or association that needs it.

  3. Jan 2026 · ongoing

    Founder and developer

    1mpulso

    I set up a small studio that builds websites for freelancers and small businesses on a subscription basis. What I bring to it is what I apply in security: proper headers, dependencies kept current, no third-party trackers and deployments that roll back in one click. I handle everything from design to domain, so the client never has to learn any of it. Two clients in production.

  4. Oct 2021 · ongoing

    IT support technician

    Servicios propios

    Support for individuals and small businesses, on request. Installing and tuning Windows, upgrading and migrating hardware, recovering infected machines and purchase advice. The most complete job was replacing the machines and the network cabling of a small company, end to end and with usage training included.

About me

Outside work

I keep training at workshops and conferences, and since February 2026 I have been accredited as an INCIBE cyber-volunteer, running free awareness workshops. Before all of this there were almost four years of volunteering across six countries.

See community

What to write about

Free awareness talks for schools and associations in Cantabria, job offers, open source collaboration, or an audit. I answer myself, and it takes a day or two.

Get in touch