About

I’m Daniel Malaco, an Information Security Engineer in Porto, Portugal. Since 2020 I’ve been at Ascendi, designing and operating the security architecture of critical road infrastructure: next-generation firewalls, SIEM, endpoint protection, identity management, threat intelligence and incident response — the full cycle, from designing the control to analysing the event.

I came to security through networks. For several years I designed, installed and commissioned IP networks for metro and rail systems across four countries — the Doha Metro in Qatar, the Santos VLT in Brazil, and the Odense and Bergen light metros in Denmark and Norway. In transport infrastructure a network failure is not an inconvenience: it is a stopped system and thousands of people going nowhere. That is where I learned to design for redundancy, document for whoever comes next, and test everything in staging before touching production.

In 2020 I turned my focus from networks to the people attacking them. At Hardsecure I deployed next-generation firewalls and ran internal penetration tests — finding vulnerabilities before someone else could exploit them — and I carried that offensive perspective into the defensive work I do today. I take it seriously outside working hours too: SANS SEC504, DFIR and ransomware summits, and a CTF won in Lisbon in 2022.

I like building the tools I use: the ones on this site all run in the browser, and at home I keep a homelab with a k3s cluster on Raspberry Pis that serves as the guinea pig for anything I want to try before it gets anywhere near production. This site is part of that — static, bilingual, tracker-free, with its security posture documented and verifiable.

Experience

The essentials are above; the detail of each role lives here, collapsed.

Information Security Engineer · Ascendi Nov 2020 → present
  • Context: security of critical road infrastructure, in Portugal.
  • Role: designing, deploying and operating information security architecture, handling tasks/incidents in ITSM.
  • Technologies: NGFW, AV/EDR, VA, SIEM, IAM, WAF, SEG.
  • Outcome: ongoing maintenance of the security of networks, systems and applications through policies and procedures; identifying threats and vulnerabilities and implementing controls to mitigate them via monitoring and security-event analysis.
  • External reference: the security infrastructure I helped build was the subject of a Fortinet Customer Story about Ascendi — the article doesn’t name me (it quotes the Head of IT), but I was part of the team behind the work it describes.
Cyber Security Engineer · Hardsecure Feb 2020 → Sep 2020
  • Context: next-generation firewall deployment and internal penetration testing.
  • Role: installing, configuring and supporting NGFW equipment.
  • Technologies: next-generation firewalls (NGFW), network scanning and enumeration.
  • Outcome: located vulnerabilities in networks before they could be exploited.
Systems Engineer · Efacec Jan 2019 → Feb 2020

Odense Letbane (Denmark)

  • Context: light-metro project in Denmark.
  • Role: designing, installing and commissioning IP networks and security.
  • Technologies: system requirements, design and installation documents, lab staging, test and commissioning procedures.
  • Outcome: the light metro’s IP network and security layer taken from design through commissioning — lab staging, test procedures, and a documented handover to operations.

Bergen D42 (Norway)

  • Context: light-metro project in Norway.
  • Role: designing, installing and commissioning IP networks and security.
  • Technologies: system requirements, design and installation documents, lab staging, test and commissioning procedures.
  • Outcome: system requirements turned into documented design, installation and commissioning of the D42 stretch — the technical groundwork for the line entering service.
Junior Consultant · Altran / Network Engineer · Thales Jan 2017 → Dec 2018

Doha Metro (Qatar)

  • Context: metro project in Qatar.
  • Role: designing, installing and commissioning IP networks and BBRS systems (mobile WiFi for trains).
  • Technologies: IP networks, BBRS systems, rail/metro environments.
  • Outcome: IP networks and the BBRS system (the mobile WiFi that follows the trains) delivered from specification through commissioning, on a metro built from scratch.

VLT Santos (Brazil)

  • Context: light rail vehicle (VLT) project in Brazil.
  • Role: designing, installing and commissioning IP networks and BBRS systems (mobile WiFi for trains).
  • Technologies: IP networks, BBRS systems, rail/metro environments.
  • Outcome: IP network and BBRS delivered from design through commissioning, adapting the same rail stack to an urban light-rail system.

Education

Certifications

Fortinet (Credly), SANS SEC504 and the summits, Microsoft, CyberDefenders and more — the full list, with current status and independent verification on Credly, lives on its own page: Certifications.

ATT&CK coverage

The MITRE ATT&CK techniques I cover defensively, tactic by tactic, with the tool or experience behind each one — the same résumé, in the industry’s native language: ATT&CK heatmap.

Skills

Area Detail
Frameworks MITRE ATT&CK, CIS benchmarks & controls, CISA CPG, OWASP Top 10, ISO 27001
Perimeter NGFW, WAF, Security Email Gateway (SEG)
Endpoint Antivirus (AV), Endpoint Detection & Response (EDR)
Identity IAM, Active Directory
Detection & response SIEM, vulnerability assessment (VA), penetration testing
Resilience Business Continuity Planning (BCP)
Languages Python, Bash, PowerShell, Golang, C/C++
Platforms Linux, Windows, AWS, Azure, Rapid7 InsightVM, ServiceNow

Applied frameworks

The frameworks below show up in the work as tools, not as goals. I use them to structure decisions, prioritise controls, and speak the same language as auditors, vendors and regulators. The table says where each one comes in and at what depth — none of them is explained here.

Framework Where it comes into the work Depth
ISO 27001 Reference for security policies and procedures, and for organising technical controls by domain. Reference
NIS2 Regulatory context of the sector I work in — critical transport infrastructure; it informs control and reporting priorities. Context
CIS Controls & Benchmarks Baseline for hardening systems and network equipment, and a reference when checking configurations. Applied
CISA CPG Point of comparison for prioritising baseline controls in critical infrastructure. Reference
OWASP Top 10 Common vocabulary for classifying findings from vulnerability assessment and internal testing, and for tuning WAF rules. Applied
MITRE ATT&CK Mapping detection coverage and structuring incident analysis — technique by technique in the heatmap. Applied

On the depth column. Applied — in regular use, in controls I operate. Reference — consulted during design and prioritisation, with no formal process attached. Context — the sector’s regulatory backdrop, not a programme I run. No row implies certification, formal audit or declared compliance: it is only where the framework comes into the work.

CTFs won

1st place, with a photo and the coin as proof — nothing hand-typed.

Flag the Hack — Fortinet 2026
1st place · 2026

Flag the Hack

Fortinet

1st place in the CTF at the first Flag the Hack event in Portugal — a full attack chain, with prompt-injection stages and FortiSOAR-driven response.

Fabric Challenge 2025 — Fortinet 2025
1st place · 2025

Fabric Challenge 2025

Fortinet

1st place in the CTF, teamed with Bernardo Sousa.

Xperts Summit Portugal 2024 — Ultimate Fabric Challenge — Fortinet 2024
1st place · 2024

Xperts Summit Portugal 2024 — Ultimate Fabric Challenge

Fortinet

1st place in the CTF, teamed with Bernardo Sousa.

SEC504 — Hacker Tools, Techniques, and Incident Handling — SANS Institute 2022
1st place · 2022

SEC504 — Hacker Tools, Techniques, and Incident Handling

SANS Institute

1st place in the SEC504 course CTF, in Lisbon.