Martín Martín

Martín MartínOffensive security, Madrid

19+ years in IT and security, 7 published CVEs and 1,000+ vulnerabilities reported.

I've been into offensive security since I was 12. By then, I was already on the staff of one of the biggest Spanish-speaking cybersecurity forums of the time. At 14, I joined a small group researching some of the earliest security issues around Bluetooth. I also found bugs in phpBB and other software people used back then, and reported them directly to the developers. Bug bounty programs did not exist yet. That was how I learned: forums, IRC channels, lots of reading, and breaking things on my own. I was self-taught from the start.

Linux was the other obsession. I started working as a sysadmin in 2007, looking after servers, networks, and production systems. It taught me how a company's infrastructure is actually built and run, and where excessive permissions, inherited configurations, and trust relationships tend to hide. Years later, those same details often become the links in an attack chain.

Throughout those years, security research continued outside my day job. I combined operations work with bug bounty, vulnerability research, and building my own tools. Working as a sysadmin taught me how systems behave in the real world. Offensive work taught me to look at them as an attacker would. I still rely on both sides every day.

In 2022, I moved into offensive security full time. I started as a Security Analyst, then became a Senior Security Specialist. Within a few years, I proposed setting up an offensive security department from scratch. I built it, worked out how it should operate, and took the lead, first as Offensive Security Lead and now as Senior Offensive Security Lead.

Today I work across web applications and APIs, mobile, external infrastructure, cloud, and GenAI/LLM systems. I don't see them as separate areas. I want to understand how they connect, follow an attack from one component to the next, and show the impact with evidence another engineer can reproduce.

I still spend time on bug bounty, vulnerability research, coordinating CVE disclosures, maintaining open-source tools, and teaching. My career has been self-taught from the beginning. The certifications came later, to round out what I had already learned by doing the work.

19+ years in IT & security

Corporate path

Same company
Senior Offensive Security LeadCurrent
2026 – PresentGlobal Enterprise · Remote
Offensive Security Lead2025 – 2026
Global Enterprise · Remote
Senior Security Specialist2023 – 2025
Global Enterprise · Remote
Security Analyst2022 – 2023
Global Enterprise · Remote
IT Operations2013 – 2022
Global Healthcare Company · Madrid
Server & Network Administrator2008 – 2013
Spanish SME · Madrid
IT Support Technician2007 – 2008
Spanish Banking Group · Madrid

Independent path

Independent Security ProfessionalActive
2016 – PresentBug Bounty · Pentesting · Training
What I do as freelance
1,000+ vulnerabilities reported
Bug bounty programs & pentests
7 published CVEs
Vulnerability research & coordinated disclosure
Open-source tools
Recon & offensive security automation
200+ students trained · 9.5/10
Mentoring, private training & bootcamp lectures
Talks & speaking
Conferences, universities & meetups

Feedback from clients, colleagues and students

Client names are withheld here because the work was confidential. Public employment history and recommendations are available on LinkedIn.

Client

"We were preparing for our ISO 27001 certification and needed a proper pentest. Martín found issues that our previous vendor and automated scans had completely missed. Clear report, zero fluff, and he took the time to walk our devs through every fix."

Executive at a fintech company
Colleague

"Martín is the type of teammate that makes you wonder how you managed before he joined. His work on alert and incident handling has been excellent. He ran several internal pentests and delivered detailed reports that were key to improving our overall security."

Former colleague, Security team
Student

“Martín is an excellent cybersecurity instructor who brings both technical expertise and real passion to the classroom. He taught us reconnaissance from scratch, with a strong focus on methodology, OSINT, enumeration and attack surface analysis. His attention to detail and ability to engage students make him highly recommendable for any teaching role.”

Recon course student
Student

“I really recommend Martín if you’re a security researcher or just starting in bug bounty. His methodology is excellent and his guidance for building automation tools is top-notch. Any hunter can test their targets much better with his help.”

Bug bounty mentoring student
Student

“Martín has a mindset that shows self-taught, passionate people really make the difference. He always responded fast and with real interest in going further. I don’t understand how he reaches that level of efficiency, but what I know is that he inspired me. Everything is possible.”

Recon course student

Need something tested or explained?

Tell me whether it is a pentest, a training session, a talk or a specific finding. I work remotely from Madrid and usually reply within one working day.