Josué Encinar

Product Security Lead
@
IriusRisk

Professional Expertise & Experience

Josué Encinar is an AppSec Specialist whose expertise is firmly rooted in the practical realities of offensive security. He brings a valuable, attacker-centric mindset to threat modeling and secure development, providing organizations with intelligence on how systems are truly exploited.

His expertise is built upon:

  • Offensive Security: Josué is a proven ethical hacker and offensive security enthusiast, giving him first-hand knowledge of the vulnerabilities and attack paths he writes about.
  • Security Tool Development: He actively develops and contributes to security tools, including projects like Gotator (for generating DNS wordlists) and HomePWN (a Swiss Army Knife for IoT pentesting), demonstrating a high level of technical proficiency and contribution to the security community.
  • Practical SDLC Integration: Josué's focus is on translating complex security flaws into pragmatic solutions that developers can adopt across the entire Software Development Lifecycle (SDLC).

Key Contributions and Achievements

Josué's contributions establish him as an authority who understands how to build systems that resist real-world attacks:

  • Vulnerability Insight: His content provides essential insight into the mind of an attacker, which is critical for effective risk assessment and countermeasure derivation.
  • Community Contributor: His open-source contributions on platforms like GitHub solidify his commitment to the security community and verify his technical skills in security research and code development.
  • Threat Modeling Focus: He advises on using automated threat modeling to efficiently integrate the attacker's perspective into the design process, ensuring security flaws are found and fixed before code is written.

Blogs by

Josué Encinar

Software security
Adding security into the SDLC
May 15, 2023