Application security engineer — building AI-assisted security tooling
Working at KATIM
Senior Cybersecurity Engineer
I own SSDLC and security tooling at KATIM — the whole thing: program, tools, rollout, and vulnerability management.
SSDLC & Tooling
- Defining the SSDLC, planning the implementation, and getting developers to adopt it.
- Picked and integrated the security toolchain — Coverity, Checkmarx, Semgrep, Black Duck SCA — into the Jenkins pipelines and automated the security controls.
Vulnerability Platform
- Built a custom vulnerability-management tool that covers roughly 1,000 repositories.
- Consolidates six scanners across SAST, SCA and secret scanning, dedupes the findings, and runs AI-assisted triage on a local model for privacy.
AI in the Security Work
- Summarizing pull requests, generating custom security rules, and producing per-repo security profiles tuned to each project's characteristics.
Connections
- — Secure SDLC Program
- — Six-Scanner Triage Engine
- — FNZ · Accenture · Deloitte
- — Local-Model Knowledge Base
Previously
FNZ · Accenture · Deloitte
Five years of security work in Madrid before KATIM — from SOC operations to application security to leading a supply-chain initiative across an entire organization.
FNZ Group — Application Security Engineer
Oct 2023 – Jan 2025
- Built the automated security process in GitHub Actions for FNZ's wealth-platform clients: SAST on every pull request, secret scanning, dependency policy.
- Owned AppSec for ten-plus client tenants — pentest scheduling, security requirements, vendor selection — and led the supply-chain workstream.
Accenture — Security Delivery, Analyst → Senior
Oct 2020 – Oct 2023
- Led the software supply-chain security initiative across the organization and built its SLSA knowledge base.
- Managed three security teams of four to eight people: a client-embedded AppSec office, the internal DevSecOps lab, and the supply-chain initiative.
- Stayed hands-on: threat modeling, NIST and OWASP gap analyses, and security code reviews with custom rulesets per client.
Deloitte — Cybersecurity Operator
Feb – Oct 2020
- SOC operations: threat monitoring and incident triage across CrowdStrike, FireEye, Akamai, Splunk and Kibana, plus phishing analysis and end-user support.
Connections
- — Current Role
- — AppSec · 2023 – 25
- — Security Delivery · 2020 – 23
- — SOC · 2020
My Projects
Selected Builds
Things built around the day job, most of them scratching a real itch from it: removing friction and putting AI where it genuinely helps.
CVE Impact Analyzer
- Answers the question a CVE feed can't: does this vulnerability actually affect our products?
- Reads the advisory, then analyzes the build process and the code before returning an evidence-backed verdict — so engineers spend their time on the CVEs that are actually reachable.
AI-Assisted Triage
- AI applied to the security work where it genuinely helps: summarizing pull requests, generating custom security rules, and producing per-repo security profiles tuned to each project.
- All on local models, for privacy.
Checkmarx FP Dashboard
- Tracks the false positives engineering marks and auto-reviews those verdicts with AI — turning one-off triage decisions into data the security program can learn from.
Onboarding Assistant
- Local models over the team's knowledge base: new engineers ask it about complex projects instead of interrupting the veterans — and the data never leaves the building.
Vulnerability Manager
- An open-source vulnerability manager with the scanners built in — Semgrep, TruffleHog, Trivy — instead of aggregating reports from tools you run elsewhere.
- Work in progress; open-source release on the way.
WARD
- A security control plane for agentic software development: bring your agents and your scanners, WARD decides whether the code has enough verified security evidence to ship.
- Work in progress; open-source release on the way.
Connections
- — Local-Model Tooling
- — Evidence-Backed Verdicts
- — Finding-Review Analytics
- — Local-Model Knowledge Base
- — Open Source · Scanners Built In
- — Agentic SDLC Control Plane
- — Six-Scanner Triage Engine
Toolstack
Daily Drivers
AI
- Claude and GPT for the engineering work; local models via Ollama where the data can't leave the building; MCP for wiring agents to real tools.
Scanning
- Semgrep — with custom rules — plus Coverity, Checkmarx, Black Duck SCA, and Trivy.
Pipelines
- Jenkins and GitHub Actions — where the scanners actually live and the controls get enforced.
Glue
- Python and Bash for everything in between.
Connections
- — Plus Toolstack
Blog
Coming Soon
First posts are in progress: running an AppSec program across a thousand repositories, supply-chain integrity that survives contact with real pipelines, and what AI actually changes about application security.
Areas of Interest
Plus Toolstack
The threads I keep pulling on outside the ticket queue — and the tools I pull them with.
Connections
- — SLSA · Provenance
- — Auto-Triage · Rules · Agents
- — LLM Apps · Agents · MCP
- — Harnesses · Orchestration
- — Scanners · Pipelines · AI
Supply-Chain Security
SLSA · Provenance
From leading Accenture's supply-chain initiative — building its SLSA knowledge base — to FNZ's dependency policy to KATIM's SCA rollout: provenance, integrity, and knowing what is actually inside the build.
Connections
- — Plus Toolstack
AI for Security
Auto-Triage · Rules · Agents
Using AI to do the security work: auto-triage at platform scale, generated security rules, per-repo risk profiles — and the evals, guardrails and human review that keep the output trustworthy.
Connections
- — Plus Toolstack
- — Local-Model Tooling
Securing AI
LLM Apps · Agents · MCP
The security of AI systems themselves: LLM applications, agents and the tools they reach, MCP threat models, prompt injection — and reviewing machine-written code before it ships.
Connections
- — Plus Toolstack
Agentic Engineering
Harnesses · Orchestration
Building with agents, not just about them: harnesses, orchestration across terminals and worktrees, local models doing real work — engineering habits that carry straight back into the security tooling.
Connections
- — Plus Toolstack
- — Agentic SDLC Control Plane
Álvaro De la Torre Ruiz
Senior Cybersecurity Engineer
Most appsec programs ship dashboards full of findings nobody fixes. I build the platforms — and the developer programs — that turn scanner noise into shipped fixes.
- CCNSE — Certified Cloud-Native Security Expert, 2025
- CCSE — Certified Container Security Expert, Apr 2024
- CDE — Certified DevSecOps Expert, Jun 2023
- CDP — Certified DevSecOps Professional, May 2022
- PenTest+ — CompTIA PenTest+, Feb 2022
- Spanish — Native
- English — Professional
Writing & Notes
coming soon
Nothing published yet — the first posts are in progress.
Queued: running an application-security program across a thousand repositories, supply-chain integrity that survives contact with real pipelines, and what AI actually changes about application security.