Hi! I'm Daniel Aunan
Cybersecurity engineer working with identity & access management, PKI, penetration testing, and network security. Explore my projects, learn more about my work, and feel free to reach out!
Cybersecurity engineer working with identity & access management, PKI, penetration testing, and network security. Explore my projects, learn more about my work, and feel free to reach out!
I'm Daniel, a cybersecurity engineer working with identity and access management (IAM) and public key infrastructure (PKI). I hold a double master's degree in Computer & Network Engineering from INSA Toulouse and Security of Computer Systems from Institute National Polytechnique de Toulouse (INP) ENSEEIHT. I specialize in penetration testing, network and identity security, and CTF challenge development, with experience working at EUROCONTROL's EATM-CERT securing critical aviation infrastructure.
Learn more about meMy main focus areas are identity and access management (IAM), public key infrastructure (PKI), penetration testing, and network and OT security. I enjoy working close to real systems — understanding how things actually work, where they break, and how attackers think — especially in high-impact environments like aviation and industrial systems.
I’ve worked in diverse environments ranging from aviation cybersecurity at EUROCONTROL (EATM-CERT), to OT network operations at Intility, and software development at AutoStore. Today I work with IAM and PKI in a security engineering role. This mix allows me to bridge development, operations, and security rather than treating them as isolated disciplines.
I regularly work with tools such as Nmap, Burp Suite, Wireshark, and various cloud and container security tools. I’m comfortable scripting in Python and Bash, and I have experience with Java and C. On the infrastructure side, I have a strong networking background and Cisco CCNA certification.
I work with identity and access management and public key infrastructure — access models, authentication and authorization, certificate lifecycles, and key management. I combine that with a background in OT and critical infrastructure security, where monitoring, incident response, and network operations matter in environments where availability and safety are critical.
I approach security from both an attacker and defender perspective. I enjoy threat modeling, hands-on testing, and turning findings into practical mitigations. I value clear communication — especially when explaining risks and solutions to non-security stakeholders.
I continuously learn through hands-on projects, CTFs, research, and real-world problem solving. My academic research includes work on malicious container images and supply-chain attacks in Kubernetes environments, and I actively keep up with emerging threats and techniques.
I’m comfortable working in multidisciplinary and international teams. I’ve collaborated with engineers, operators, and security professionals across Europe, and I value clear documentation, structured workflows, and knowledge sharing as much as technical skill.