Martín MartínOffensive security, Madrid
19+ years in IT and security, 7 published CVEs and 1,000+ vulnerabilities reported.
I've been into offensive security since I was 12. By then, I was already on the staff of one of the biggest Spanish-speaking cybersecurity forums of the time. At 14, I joined a small group researching some of the earliest security issues around Bluetooth. I also found bugs in phpBB and other software people used back then, and reported them directly to the developers. Bug bounty programs did not exist yet. That was how I learned: forums, IRC channels, lots of reading, and breaking things on my own. I was self-taught from the start.
Linux was the other obsession. I started working as a sysadmin in 2007, looking after servers, networks, and production systems. It taught me how a company's infrastructure is actually built and run, and where excessive permissions, inherited configurations, and trust relationships tend to hide. Years later, those same details often become the links in an attack chain.
Throughout those years, security research continued outside my day job. I combined operations work with bug bounty, vulnerability research, and building my own tools. Working as a sysadmin taught me how systems behave in the real world. Offensive work taught me to look at them as an attacker would. I still rely on both sides every day.
In 2022, I moved into offensive security full time. I started as a Security Analyst, then became a Senior Security Specialist. Within a few years, I proposed setting up an offensive security department from scratch. I built it, worked out how it should operate, and took the lead, first as Offensive Security Lead and now as Senior Offensive Security Lead.
Today I work across web applications and APIs, mobile, external infrastructure, cloud, and GenAI/LLM systems. I don't see them as separate areas. I want to understand how they connect, follow an attack from one component to the next, and show the impact with evidence another engineer can reproduce.
I still spend time on bug bounty, vulnerability research, coordinating CVE disclosures, maintaining open-source tools, and teaching. My career has been self-taught from the beginning. The certifications came later, to round out what I had already learned by doing the work.
19+ years in IT & security
Corporate path
Independent path
Certifications
Feedback from clients, colleagues and students
Client names are withheld here because the work was confidential. Public employment history and recommendations are available on LinkedIn.
Executive at a fintech company"We were preparing for our ISO 27001 certification and needed a proper pentest. Martín found issues that our previous vendor and automated scans had completely missed. Clear report, zero fluff, and he took the time to walk our devs through every fix."
Former colleague, Security team"Martín is the type of teammate that makes you wonder how you managed before he joined. His work on alert and incident handling has been excellent. He ran several internal pentests and delivered detailed reports that were key to improving our overall security."
Recon course student“Martín is an excellent cybersecurity instructor who brings both technical expertise and real passion to the classroom. He taught us reconnaissance from scratch, with a strong focus on methodology, OSINT, enumeration and attack surface analysis. His attention to detail and ability to engage students make him highly recommendable for any teaching role.”
Bug bounty mentoring student“I really recommend Martín if you’re a security researcher or just starting in bug bounty. His methodology is excellent and his guidance for building automation tools is top-notch. Any hunter can test their targets much better with his help.”
Recon course student“Martín has a mindset that shows self-taught, passionate people really make the difference. He always responded fast and with real interest in going further. I don’t understand how he reaches that level of efficiency, but what I know is that he inspired me. Everything is possible.”
Need something tested or explained?
Tell me whether it is a pentest, a training session, a talk or a specific finding. I work remotely from Madrid and usually reply within one working day.