Cybersecurity Professional · Philippines

Kiara
Vicencio

Attack surface analyst. Risk investigator. Systems thinker. Building deep technical capability across vulnerability management, and security analysis — one lab at a time.

View my work Lab notes →
Status Available for remote roles
Location Philippines (PH)
Current UpGuard · Remote AU
Target Vulnerability Analyst · Security Analyst
Domain kmbv.cc
01 — Profile
About

I'm a cybersecurity professional with hands-on experience in attack surface monitoring, risk validation, and technical support — currently working remotely for UpGuard in Sydney.

My day-to-day involves investigating exposed services, analysing SSL/TLS configurations, troubleshooting authentication failures, and coordinating with engineering teams on bug tickets and platform-level incidents. Before that, I conducted OSINT and assisted with vulnerability assessments across 50+ financial institutions at SGV & Co. (EY Philippines).

I'm now deepening my technical foundation through a structured 6-month lab program — building proficiency in vulnerability scanning, cloud hardening, compliance frameworks, and system administration to move into a dedicated analyst or sysadmin role.

Based
Philippines
Education
B.S. Computer Science — Silliman University, 2023
Certifications
ISC² CC · CompTIA Sec+ (in progress)
Domain
02 — Work
Experience
Jan 2024 — Present
UpGuard · Remote, AU
Technical Support Analyst

Primary technical point of contact for enterprise customers using UpGuard's cyber risk and attack surface monitoring platform. Daily work involves investigating and validating security alerts by analysing exposed services, SSL/TLS configurations, and web infrastructure using Nmap, OpenSSL, and cURL.

Troubleshoot complex platform, networking, and authentication issues including SSO failures and DNS misconfigurations. Monitor global cybersecurity developments and escalate high-risk threats to L2 engineering teams.

~95%+ CSAT · <1 min first response · <24h resolution SLA
Nmap / OpenSSL / cURL / DNS SSO / Okta / Auth0 / Entra OSINT Knowledge Management Process Improvement Attack Surface Mgmt Incident Response
Sep — Nov 2022
Dashlabs.ai · Remote, PH
Infrastructure and Security Intern

Collaborated with the Infrastructure and Security Team to set up SSH Keys and SSH Certificates.

Python Kali Linux SSH Cybersecurity Networking
Sep — Nov 2022
Perti Solutions · Remote, CA
Infrastructure and Security Intern

- Maintained strong overall quality control of software by performing tests on varying platforms, adhering to reliability, performance, and customer expectation. - Found and reported major bugs, and offered suggestions to senior management to enhance the overall quality of the software. - Developed Low and High Fidelity Wireframes for a web application using Figma. - Managed and tracked other interns' projects and reported their progress to senior management. - Provided Technical Support including but not limited to setting up meetings, reviewing and creating documents for Perti and its clients, chairing meetings, and setting up demonstrations.

Technical Support Troubleshooting Project Management Figma Black Box Testing
Jan — May 2022
SGV & Co. (EY) · Remote, PH
Cybersecurity Consulting Intern

Conducted OSINT and attack surface analysis across 50+ banks and 4 government agencies, identifying exposed assets and potential vulnerabilities for client security assessment reports. Collaborated with senior consultants to deliver client-facing findings.

OSINT Nmap DNSDumpster
Nov 2018 — Mar 2019
Silliman University · Dumaguete, PH
ICT Lab Technical Support Intern

Provided technical support to 30+ students and faculty. Assisted in deploying and maintaining IT resources for academic use. Received Certificate of Recognition for Excellence.

Certificate of Recognition for Excellence
Technical Support Network Troubleshooting Hardware
03 — Capabilities
Skills
Security & Analysis
Risk validation & investigation OSINT & attack surface analysis Incident response coordination Pattern recognition & correlation
Networking & Systems
TCP/IP · DNS · TLS/PKI Windows Server · Active Directory Linux (Ubuntu, Kali) Authentication systems (Okta, Auth0, SSO)
Tools
bash · Nmap · OpenSSL · cURL · dig · nslookup · wget · whois DNSDumpster · Shodan · Qualys SSL Labs · MxToolbox · BGP n8n · Claude Postman
Languages
C/C++ Python HTML/CSS Javascript
Reporting & Comms
Technical documentation Remediation tracking & SLAs Knowledge base management Cross-functional stakeholder comms
Currently Learning
Active Directory administration & GPOs Vulnerability Scanning (Nessus, OpenVAS) Web app security testing (Burp Suite, OWASP Top 10) CIS benchmark hardening & Lynis CVSS scoring & remediation reporting
04 — Credentials
Certifications
Earned
Certified in Cybersecurity (CC)
ISC²
Earned
Introduction to Cybersecurity (CISCO)
ISC²
Earned
Introduction to Networking (CISCO)
ISC²
Planned
CompTIA Security+
CompTIA
Planned
CompTIA Network+
CompTIA
05 — Live Lab
Under construction ▓▓▓▓▒▒▒▒▒▒
kmbv.cc
kali@lab ~ testssl.sh kmbv.cc
# TLS/SSL security audit — kmbv.cc
 
$ testssl.sh kmbv.cc
 
Testing protocols (via sockets)
 SSLv2    not offered ✓
 SSLv3    not offered ✓
 TLS 1    not offered ✓
 TLS 1.1  not offered ✓
 TLS 1.2  offered ✓
 TLS 1.3  offered ✓ (final)
 
Testing server defaults
 HSTS     max-age=31536000 ✓
 DNSSEC   signed ✓
 CAA      configured ✓
 
Rating: A+

kmbv.cc is both my portfolio domain and a live security training environment — a real attack surface I configure, harden, monitor, and iterate on as part of my hands-on lab program.

Every subdomain serves a dual purpose: a real service and a learning objective. Security controls are implemented, documented, and tracked through an ASM platform.

kmbv.cc
Portfolio & home page
lab.kmbv.cc
Lab notes & write-ups
git.kmbv.cc
Self-hosted Gitea instance
siem.kmbv.cc
Wazuh SIEM dashboard
mail.kmbv.cc
SPF / DKIM / DMARC research
Let's connect

Open to vulnerability analyst and security analyst roles — remote preferred, particularly AU, SG, or international remote.