Hi, I'm Paola Medrano

Research Question

"How can intelligent cybersecurity systems help people make better security decisions under uncertainty?"

Paola Medrano

Cybersecurity Engineer · Security Operations · AI Security

Connecting hidden patterns
between people and threats.

Cybersecurity Engineer with experience in Security Operations and applied AI for threat detection and decision support. I build practical security solutions that combine engineering, automation, and applied research. I'm now pursuing a PhD in human-centered security to deepen that work through explainable AI — turning technical evidence into guidance people can trust and act on.

MSc Cybersecurity · Universidad de Alcalá · CISPA Grand Final 2026

4,279 subscribers 234 threats detected · production 2 research papers ★ CISPA Grand Final 2026
Trustworthy Systems
Cybersecurity
Trustworthy AI
Human-Centered Security
Digital Trust
Fraud Detection
Explainable AI
Security Operations
Threat Detection
Digital Resilience
Online Safety
AI for Security
Security & Society
Privacy

What I do

Human-Centered Security

  • Decision support systems under uncertainty
  • Explainable AI for security recommendations
  • PhD research: making threat intelligence actionable

Research

Publications

Evidence-grounded research addressing detection, explainability, and human decision-making in cybersecurity. Every paper is a step toward understanding how people and systems can work better together under threat.

NLP · LLM pipeline
In Progress Work in Progress Jun 2026

Multimodal Detection of Digital Fraud in Spanish with Citizen-Oriented Conversational Explainability

93.4% Accuracy
0.98 AUC-ROC
14,750 Messages corpus
72% External val.

Master's thesis addressing phishing and smishing detection in Spanish-language text messages and URLs. Combines a lightweight TF-IDF classifier, a rule-based URL analysis module (17 features), and an LLM-powered conversational explainability layer, designed to work on partial inputs and generate citizen-readable risk explanations.

M.Sc. Cybersecurity · Universidad de Alcalá · 2026 Read paper
EDR · Live scan
Thesis Jul 2024

Cyber Threat Analysis Using EDR Technology in Bolivian SMEs

234 Malware detected
60.94% Trojans
1.5/4 NIST CSF score
801% ROI

Deployed Sangfor Endpoint Secure on 2 real companies in Cochabamba over 2 months. Identified 234 malware instances, 2 APT-level indicators, and trojans as the dominant threat vector (60.94%), primarily introduced through illegal software activators.

B.Sc. Network & Telecommunications Engineering · UPDS · 2024 Read paper
CISPA Hackathon Championship · Saarbrücken 2026

Recognition

Road to the Grand Final

Selected to compete at CISPA, the Helmholtz Center for Information Security, Germany's national research institute and one of the world's top-ranked institutions in cybersecurity. The championship brings together the most promising emerging researchers from across Europe.

What is CISPA

CISPA Helmholtz Center is a world-class research institute dedicated to information security, consistently ranked among the global elite for security research output. Being selected for their flagship championship reflects research-level standing, not a student competition, but an academic proving ground.

PhD Track

This competition is part of a larger trajectory: pursuing a doctorate in human-centered security, building systems that transform complex threat intelligence into understandable, actionable guidance for the people who need it most.

Jul 2026

Grand Final

Saarbrücken

Germany

CISPA Hackathon Championship

Official announcement

Talks

Presentations

Sharing research findings with practitioners and the academic community.

El Arte de la Ciberinteligencia

Keynote

Conferencia de Seguridad · 2025

Explorando técnicas avanzadas de inteligencia en ciberseguridad y análisis de amenazas.

Open in Drive

¿Tu equipo ya fue hackeado y no lo sabes?

Workshop

Taller de Conciencia en Seguridad · 2024

Indicadores de compromiso y técnicas de detección de brechas silenciosas en tu organización.

Open in Drive
RESEARCH PROTOTYPE TESTING PHASE

Nawi

Intelligent decision-support for cybersecurity

Nawi transforms technical cybersecurity evidence into understandable guidance. Rather than simply flagging threats, it helps people recognize risks, interpret alerts, and respond with confidence.

Transforms technical signals into human-readable guidance
Explains why something is risky, not just that it is
Designed for people who need to decide, not just detect
Decision SupportExplainable AINLPPrivacy-first
Testing phase · Android Mándame tu correo para probarla

Nawi todavía no está publicada. Escríbeme con tu correo de Google y te añado como tester en Android.

Nawi app screenshot

Content

@pwn3dbypao

Making complex security accessible to people who need it most.

4,279 subscribers
More videos on @pwn3dbypao

Get in touch

Contact

Open to research collaborations, academic partnerships, speaking invitations, and feedback on ongoing work.

Location: Madrid, Spain