NoHype Engineering · Buenos Aires · Since 2023
EzequielGutesman
Fractional CTO. Engineering leadership shaped by two decades of cybersecurity research and development.
I work with founders, CEOs and engineering leaders on technology strategy, team building and software delivery. I started as a web developer at Digbang, spent seven years as a security researcher at CORE Security Technologies and then ten years at Onapsis, where I built the research team and later led engineering and research together. For eleven years I also taught programming and directed special projects in computing at Escuela Técnica ORT.
Technical leadership, part time and hands on
Most of my work is as a fractional CTO or VP of Engineering: I join a company for a defined period and take responsibility for the technology and the engineering team alongside the founders. I also coach CTOs and engineering managers who are taking on larger roles.
Technology strategy and innovation
Aligning the technical roadmap with the business plan, deciding what to build, buy or leave out, and setting up a way to prototype and validate new product ideas.
Engineering organization
Team structure, hiring, career paths and the working climate that keeps good people productive over time.
Delivery and SDLC
Development process, QA automation, CI/CD and DevOps practices, with progress tracked through DORA, SPACE and DevEx metrics.
Architecture and technical debt
Architecture reviews for scale and maintainability, and a prioritized plan for technical debt that the business can follow.
Funding rounds and due diligence
Getting the technology, security posture and team ready for investor or acquirer review, based on having gone through several of these processes.
Coaching engineering leaders
One-on-one work with CTOs and engineering managers on decisions, team health and communication with the rest of the company.
Security as part of engineering
I have worked in offensive security and product security since 2005, first at CORE Security Technologies and then at Onapsis. As a CTO I bring that into the engineering process from the start.
- Product security and secure SDLC
- Application security programs and penetration testing teams
- Risk assessment based on how attackers operate
- Cybersecurity topics specific to the software engineering process in due diligence
Professional engineering and research teams
At Onapsis I built the research team from scratch and later ran product engineering and research as one organization.
- Hiring and structuring research and R&D teams
- Research agendas tied to the product roadmap
- Prototyping, publications and patents
- Moving research results into shipped features
From diagnosis to handover
Each engagement is different, but the sequence is usually the same.
- Step 1
Diagnosis
Interviews with the team and leadership, plus a review of the code, architecture, delivery data and security posture.
- Step 2
Priorities
A short written plan with the few changes that matter most, agreed with the founders.
- Step 3
Work inside the team
I take part in decisions, rituals, hiring and reviews, and coach the people who will lead after me.
- Step 4
Handover
Decisions are documented and ownership moves to internal leaders so the team can continue on its own.
What "no hype" means in practice
- Measure firstProcess changes start from the team's own delivery and quality data.
- Proven technologyNew tools come in when they solve a specific problem the team has today.
- Security in the pipelineSecurity belongs in design reviews, CI and the definition of done.
- Team health mattersA stable team with a healthy working environment ships more reliably and works better with the rest of the company.
- Written decisionsArchitecture and organizational decisions are recorded with their context, so the next person can follow the reasoning.
Twenty years in engineering and security
- 2023 —
Fractional CTO · VP of Engineering · Tech coach
NoHype Engineering
Working with engineering leaders in high-growth companies on SDLC practices, team building, architecture and due diligence.
- 2017 – 2023
VP of Engineering & Security Research
Onapsis
Responsible for the flagship product and for security research. Software architecture, SDLC, QA, support, product security, penetration testing teams and leadership coaching.
- 2012 – 2017
Director of Research
Onapsis
Built the security research team from scratch. Led product innovation, prototypes, patents, conference publications and penetration testing services.
- 2005 – 2012
Security Researcher
CORE Security Technologies
Research on new attack vectors in web applications, wireless networks and other technologies, and penetration testing. Co-inventor of three of the patents listed below and speaker at Black Hat USA, Hack.lu, FIRST and PyCon Argentina.
- 2004 – 2005
Developer
Digbang!
Web development in PHP, .NET and Perl.
- 2001 – 2012
Programming professor · Director of Special Projects in Computing
Escuela Técnica ORT
Taught software programming, directed special projects in computing and advised on the computer science curriculum.
Teaching
Information Security module, Master in Management + Analytics (MIND)Universidad de San Andrés · 2017–2020
Community
Speaker in 2013; later on the content committee, selecting talks for the conferenceEkoparty · 2020–2024
Education
Computer ScienceUniversidad de Buenos Aires
Engineering Leadership for Emerging LeadersMIT Professional Education · 2017
Computing technician, cum laudeEscuela Técnica ORT · 2000
Talks, papers and patents
Most of this work comes from CoreLabs and Onapsis Research, done with colleagues listed as co-authors.
| Year | Venue | Title |
|---|---|---|
| 2014 | NoSuchCon, Paris | Blended Web and Database Attacks on Real-time, In-Memory Platforms |
| 2013 | Ekoparty, Buenos Aires | ERP Security: How Hackers Can Open the Safe and Take the Jewelswith Jordan Santasieri |
| 2012 | PyCon Argentina | No toca BOTOn: Amazon Web Services desde Pythonwith Fernando Russ |
| 2011 | Hack.lu | Abusing the Windows WiFi Native API to Create a Covert Channelwith Andrés Blanco |
| 2009 | FIRST, Santiago | Attacker-centric risk assessment and metricswith Fernando Miranda |
| 2008 | Hack.lu | gFuzz: An Instrumented Web Application Fuzzing Environment |
| 2007 | Black Hat USA | A Dynamic Technique for Enhancing the Security and Privacy of Web Applicationswith Ariel Waissbein and Ariel Futoransky |
| Year | Venue | Title |
|---|---|---|
| 2011 | Hack.lu | Abusing the Windows WiFi Native API to Create a Covert Channelwith Andrés Blanco |
| 2010 | ACM CSIIRW | The impact of predicting attacker tools in security risk assessmentswith Ariel Waissbein · doi:10.1145/1852666.1852752 |
| 2008 | Hack.lu | gFuzz: An Instrumented Web Application Fuzzing Environment |
| 2007 | Black Hat USA | A Dynamic Technique for Enhancing the Security and Privacy of Web Applicationswith Ariel Futoransky and Ariel Waissbein |
| Number | Year | Title |
|---|---|---|
| US 10,257,228 | 2019 | Real-time detection and prevention of segregation of duties violations in business-critical applicationsOnapsis |
| US 9,923,917 | 2018 | Automatic calculation of cyber-risk in business-critical applicationsOnapsis |
| US 9,183,397 | 2015 | Automated computer security compromise as a serviceCore Security |
| US 8,146,135 | 2012 | Establishing and enforcing security and privacy policies in web-based applications (continuation)Core Security |
| US 7,831,995 | 2010 | Establishing and enforcing security and privacy policies in web-based applicationsCore Security |