I'm Hugo, a cloud security and software engineer focused on open-source tools and multi-cloud security.
- 🔒 Contributed to Prowler through GitHub, Cloudflare, and Microsoft 365 provider integrations.
- 🛠 Built py-pwsh-session, connecting Python with persistent PowerShell sessions.
- 🌐 Explore more on my website.
More about my work
At Prowler, I worked across the path from cloud-security research to product delivery. That meant studying provider behavior, building checks and integrations, improving APIs and UI, testing edge cases, and supporting releases. The common thread was turning cloud configuration questions into useful findings while making the software dependable for people who run it. My work crossed AWS, Azure, GCP, and Microsoft 365/Entra.
- Security research and accuracy: I mapped cloud configuration checks to frameworks such as CIS, ISO/IEC 27001, and HIPAA, and investigated false positives when provider behavior did not match an assumption. I separated GCP KMS rotation checks by compliance requirement, distinguishing a CIS 90-day limit from frameworks that only require rotation to be enabled.
- Product engineering: I worked on Python integrations, APIs, UI, automated tests, and CI with GitHub Actions, including documentation and release support rather than treating checks as isolated scripts.
- Open source: I worked in public repositories, collaborated on pull requests, and helped contributors move from an issue to a reviewed change.
- GitHub provider: I contributed to the GitHub provider integration and CIS benchmark documentation and compliance. The provider followed Prowler's existing structure, while CIS coverage made its findings useful for benchmark-based security reviews.
- Cloudflare provider: My contributions spanned the provider foundation and zone security checks, API support for registering and authenticating Cloudflare accounts, and UI support for connecting and selecting the provider. This connected security checks to account setup and provider selection across the product.
- Microsoft 365 integration: I worked on bringing PowerShell into the provider for configurations Microsoft Graph alone did not expose, alongside Graph-based checks. Later, certificate authentication in the API supported non-interactive access as Microsoft enforced MFA, while preserving existing authentication options.
- Oracle Cloud (OCI): I contributed to regionless SDK setup and API credential handling, allowing credentials without a scan-region filter while the provider discovers subscribed regions. These were SDK and API parts of a broader team change, not a new provider.
- Okta controls: My contributions added network-zone coverage, API-token checks, and authenticator checks for STIG-aligned assessments. They cover anonymized proxies, token restrictions, password policies, and authenticator configuration within an existing provider.
py-pwsh-session grew out of the team’s Microsoft 365 integration. I worked on persistent sessions, command execution, timeouts, and JSON results so Python applications could reuse an authenticated PowerShell process instead of starting one for each query.
- Cloud security: AWS, Azure, GCP, Microsoft 365/Entra, CSPM, and compliance mapping for CIS, ISO/IEC 27001, and HIPAA.
- Engineering: Python, APIs, UI, testing, PowerShell integrations, and CI/CD with GitHub Actions.
I wrote Running PowerShell from Python about the tradeoffs behind our Microsoft 365 integration, and Certificate-based Microsoft 365 authentication about adapting to MFA enforcement. I also delivered workshops at Hackén 2025 and Hackén 2026, where I appear on the public speaker lists.
I studied computer engineering at the University of Granada and participated in Hackiit, a cybersecurity community centered on hands-on learning, talks, and workshops. My public education page has more background.



