I’m Daniel Malaco, an Information Security Engineer in Porto, Portugal. Since 2020 I’ve been at Ascendi, designing and operating the security architecture of critical road infrastructure: next-generation firewalls, SIEM, endpoint protection, identity management, threat intelligence and incident response — the full cycle, from designing the control to analysing the event.
I came to security through networks. For several years I designed, installed and commissioned IP networks for metro and rail systems across four countries — the Doha Metro in Qatar, the Santos VLT in Brazil, and the Odense and Bergen light metros in Denmark and Norway. In transport infrastructure a network failure is not an inconvenience: it is a stopped system and thousands of people going nowhere. That is where I learned to design for redundancy, document for whoever comes next, and test everything in staging before touching production.
In 2020 I turned my focus from networks to the people attacking them. At Hardsecure I deployed next-generation firewalls and ran internal penetration tests — finding vulnerabilities before someone else could exploit them — and I carried that offensive perspective into the defensive work I do today. I take it seriously outside working hours too: SANS SEC504, DFIR and ransomware summits, and a CTF won in Lisbon in 2022.
I like building the tools I use: the ones on this site all run in the browser, and at home I keep a homelab with a k3s cluster on Raspberry Pis that serves as the guinea pig for anything I want to try before it gets anywhere near production. This site is part of that — static, bilingual, tracker-free, with its security posture documented and verifiable.
Experience
The essentials are above; the detail of each role lives here, collapsed.
Information Security Engineer · Ascendi Nov 2020 → present
- Context: security of critical road infrastructure, in Portugal.
- Role: designing, deploying and operating information security architecture, handling tasks/incidents in ITSM.
- Technologies: NGFW, AV/EDR, VA, SIEM, IAM, WAF, SEG.
- Outcome: ongoing maintenance of the security of networks, systems and applications through policies and procedures; identifying threats and vulnerabilities and implementing controls to mitigate them via monitoring and security-event analysis.
- External reference: the security infrastructure I helped build was the subject of a Fortinet Customer Story about Ascendi — the article doesn’t name me (it quotes the Head of IT), but I was part of the team behind the work it describes.
Cyber Security Engineer · Hardsecure Feb 2020 → Sep 2020
- Context: next-generation firewall deployment and internal penetration testing.
- Role: installing, configuring and supporting NGFW equipment.
- Technologies: next-generation firewalls (NGFW), network scanning and enumeration.
- Outcome: located vulnerabilities in networks before they could be exploited.
Systems Engineer · Efacec Jan 2019 → Feb 2020
Odense Letbane (Denmark)
- Context: light-metro project in Denmark.
- Role: designing, installing and commissioning IP networks and security.
- Technologies: system requirements, design and installation documents, lab staging, test and commissioning procedures.
- Outcome: the light metro’s IP network and security layer taken from design through commissioning — lab staging, test procedures, and a documented handover to operations.
Bergen D42 (Norway)
- Context: light-metro project in Norway.
- Role: designing, installing and commissioning IP networks and security.
- Technologies: system requirements, design and installation documents, lab staging, test and commissioning procedures.
- Outcome: system requirements turned into documented design, installation and commissioning of the D42 stretch — the technical groundwork for the line entering service.
Junior Consultant · Altran / Network Engineer · Thales Jan 2017 → Dec 2018
Doha Metro (Qatar)
- Context: metro project in Qatar.
- Role: designing, installing and commissioning IP networks and BBRS systems (mobile WiFi for trains).
- Technologies: IP networks, BBRS systems, rail/metro environments.
- Outcome: IP networks and the BBRS system (the mobile WiFi that follows the trains) delivered from specification through commissioning, on a metro built from scratch.
VLT Santos (Brazil)
- Context: light rail vehicle (VLT) project in Brazil.
- Role: designing, installing and commissioning IP networks and BBRS systems (mobile WiFi for trains).
- Technologies: IP networks, BBRS systems, rail/metro environments.
- Outcome: IP network and BBRS delivered from design through commissioning, adapting the same rail stack to an urban light-rail system.
Education
- MSc in Electrical and Computers Engineering — FEUP, Faculty of Engineering of the University of Porto (2009–2016), specialised in Network and Communication Services.
Certifications
Fortinet (Credly), SANS SEC504 and the summits, Microsoft, CyberDefenders and more — the full list, with current status and independent verification on Credly, lives on its own page: Certifications.
ATT&CK coverage
The MITRE ATT&CK techniques I cover defensively, tactic by tactic, with the tool or experience behind each one — the same résumé, in the industry’s native language: ATT&CK heatmap.
Skills
| Area | Detail |
|---|---|
| Frameworks | MITRE ATT&CK, CIS benchmarks & controls, CISA CPG, OWASP Top 10, ISO 27001 |
| Perimeter | NGFW, WAF, Security Email Gateway (SEG) |
| Endpoint | Antivirus (AV), Endpoint Detection & Response (EDR) |
| Identity | IAM, Active Directory |
| Detection & response | SIEM, vulnerability assessment (VA), penetration testing |
| Resilience | Business Continuity Planning (BCP) |
| Languages | Python, Bash, PowerShell, Golang, C/C++ |
| Platforms | Linux, Windows, AWS, Azure, Rapid7 InsightVM, ServiceNow |
Applied frameworks
The frameworks below show up in the work as tools, not as goals. I use them to structure decisions, prioritise controls, and speak the same language as auditors, vendors and regulators. The table says where each one comes in and at what depth — none of them is explained here.
| Framework | Where it comes into the work | Depth |
|---|---|---|
| ISO 27001 | Reference for security policies and procedures, and for organising technical controls by domain. | Reference |
| NIS2 | Regulatory context of the sector I work in — critical transport infrastructure; it informs control and reporting priorities. | Context |
| CIS Controls & Benchmarks | Baseline for hardening systems and network equipment, and a reference when checking configurations. | Applied |
| CISA CPG | Point of comparison for prioritising baseline controls in critical infrastructure. | Reference |
| OWASP Top 10 | Common vocabulary for classifying findings from vulnerability assessment and internal testing, and for tuning WAF rules. | Applied |
| MITRE ATT&CK | Mapping detection coverage and structuring incident analysis — technique by technique in the heatmap. | Applied |
On the depth column. Applied — in regular use, in controls I operate. Reference — consulted during design and prioritisation, with no formal process attached. Context — the sector’s regulatory backdrop, not a programme I run. No row implies certification, formal audit or declared compliance: it is only where the framework comes into the work.



