As part of our ongoing series spotlighting cybersecurity leaders within our community, we sat down with Nastassja Portero, Offensive Security Specialist at Nestlé, to talk about her unlikely path into the field, how she builds learning paths for the next generation, and the confidence it took to go from questioning whether she belonged to contributing to global offensive security projects at one of the world's largest companies.
From tourism administration to global offensive security at Nestlé
Nastassja's technical foundation was built long before she ever considered cyber security as a career.
"We’re a team of five responsible for offensive security activities across the company, working with teams and environments all around the world. Our scope covers both the global landscape and the local environments of every market and affiliate.
Penetration testing and Red Team exercises are a big part of what we do, but our work goes well beyond that. We’re building internal offensive security frameworks adapted to the different technologies and environments we have at Nestlé. We also run a Bug Bounty Program and support several Breach & Attack Simulation initiatives to continuously validate and improve our security controls.
Another important area is developing our own tools and capabilities to make the team more efficient. AI is currently a major focus for us, and we recently proposed a new internal AI Red Teaming product to help assess the risks associated with AI technologies.
Personally, I’m currently leading two of these products and expect to take ownership of additional initiatives over the next few months"
Her actual degree was in business and tourism administration, not IT. A childhood spent tinkering with operating systems, courtesy of a father who built robots for fun, gave her an early technical foundation most of her peers didn't have.
"I think I got into tech because of my dad. He was a real geek and was always building things like robots at home. I grew up playing with computers, installing stuff, breaking things, and figuring out how to fix them.
Funny enough, I barely used Windows when I was younger. My dad kept changing operating systems all the time, so I was constantly adapting to something new. Looking back, that's probably where I developed the curiosity and problem-solving mindset that eventually led me into cybersecurity"
Building expertise years before she held the title
Long before offensive security appeared on a résumé or a job title, Nastassja had already become the person her friends in the field turned to for answers.
"It started as a hobby for me. I had a lot of friends working in offensive security, and during COVID, when everyone was locked down, they were dealing with a huge workload and often reached out with questions. I would help where I could, share ideas, and discuss different technical challenges with them.
Through those conversations, I realized I actually had many of the skills needed to do the job myself. I'd always been interested in security and had been doing CTFs in my spare time just for fun.
At the same time, COVID showed me how unstable the tourism industry could be, so I decided it was the right moment to make a career change. I went back to school and completed a higher degree in Network and Systems Administration, specializing in Cybersecurity, and that's how I made the transition into the field."
By the time she formally entered the industry, she had already spent years building technical skills through self-study, CTFs, and helping friends in the field.
From intern to global offensive security
Within a single internship, Nastassja was already leading a global product, and her potential was clear enough that leadership created a role for her before she'd even finished.
"When I finished my higher degree, I needed to do an internship, and that's how I ended up at Nestlé. It wasn't really planned, but shortly after I joined, my manager left and I found myself coordinating the global phishing simulation service because there was nobody else to take ownership of it.
I took on the role, changed a lot of the internal processes, and it ended up being a success story. Around the same time, during a Security & Compliance team-building event, I met our CISO, Rafael Villoria, and Alrick, who was the Technical Lead for Offensive Security at the time. We started talking about cybersecurity, certifications, and some of the side projects I had been working on.
I guess that event was very successful because they were keen to bring me into Offensive Security, even while I was still an intern. The only issue was that I was already coordinating the phishing operations, so I couldn't move over right away.
In the end, I ended up doing both roles at the same time during my internship. It was definitely challenging, but it was also a great learning experience. By the time my internship finished, a new position had been created in Offensive Security, and I had the opportunity to join the team full time."
Teaching juniors the fundamentals first, before the flashy exploits
Now responsible for structuring how some new joiners and interns learn, Nastassja is deliberate about resisting the pull toward advanced, attention-grabbing attacks before the basics are solid.
"Many years ago, cybersecurity wasn't as developed as it is today. If you wanted to learn, you mostly had to teach yourself. You'd spend hours reading niche blogs, talking to people in random chat groups, and learning through trial and error.
Today, it's almost the opposite problem. There’s an incredible amount of information available, but it can be difficult to filter through it and figure out what's actually useful.
One thing I've noticed is that a lot of people tend to skip the fundamentals. They jump straight into learning specific attacks or tools without really understanding what's happening underneath. So when I'm working with a junior person, even someone who already has an IT background, my first goal is to make sure they have a solid understanding of the basics: networking, TCP/IP, how the different layers interact, and what is actually happening behind the scenes.
Once those foundations are in place, everything else becomes much easier. They can learn new technologies, understand attacks faster, and adapt much more easily because they understand the concepts, not just the tools. "
She tailors the path to each person's interests, but insists everyone start in the same place.
"We have interns within Vulnerability Management, where Offensive Security sits, and the first thing I try to understand is what they're actually interested in. Sometimes we get people with a developer background who aren't necessarily passionate about cybersecurity from the start, and that's completely fine.
My approach is always to make sure they learn the fundamentals first. I want them to understand the basics of cybersecurity and vulnerability management, the kind of knowledge an L1 SOC analyst should have, because I believe everyone working in security should start from that foundation.
Once they have those basics, we build a learning path around their interests. Right now, for example, one of our interns is more focused on development, while the other is more interested in networking. For the intern I'm mentoring directly, we started with a structured learning path and then moved on to more practical scenarios.
At the moment, they're working through real bug bounty findings so they can learn how to use tools like Burp Suite and understand what things like SQL injection actually are, what's happening behind the scenes, and how attackers exploit them. At the same time, they're contributing to real tasks for the team, which helps connect the theory to practical experience.
We also use platforms like TryHackMe because they provide really good step-by-step content for beginners. Once they've built confidence and the right foundations, we gradually move them towards more advanced training and hands-on challenges. "
"It's kind of a green flag when you can admit you don't know"
Asked how she builds psychological safety for junior team members in a field where admitting uncertainty can feel risky, Nastassja pointed to leading by example.
"You have to lead by example. When I'm working with junior profiles, interns, or even people who are more senior than me in other areas but not in offensive security, I have no problem saying, "I don't know." It's actually a good sign when someone can openly say, "I don't know."
Especially in offensive security, we touch so many different topics that it's impossible to be an expert in everything. For me, it's actually a positive sign when someone can admit they don't know something or aren't completely sure. It shows honesty and a willingness to learn.
That's also why I focus so much on helping beginners build strong fundamentals. Once you understand the basics, you can trust your own reasoning and problem-solving skills. You might not always have the exact answer right away, but your understanding of the fundamentals will usually guide you toward the right solution."
That confidence, she says, doesn't come automatically, especially as one of the youngest people, and one of relatively few women, on a highly experienced team.
"Building confidence in this field can be challenging, especially when you're a women and young or feel less experienced than the people around you. I'm one of the youngest people on my team, and many of my colleagues have fifteen or more years of experience.
A lot of it comes from trusting yourself and recognizing what you do know. Of course, confidence doesn't develop in isolation. Your team, your manager, and the overall company culture all play a big role in helping you grow.
For me, if you feel like you're missing knowledge in a particular area, then you learn it. That's part of the mindset. I think you need a real commitment to both your career and your own development in this field.
Cybersecurity moves so fast that learning never really stops. Even after a full day of work, many of us will spend some personal time exploring new technologies, reading, testing things, or developing new skills. It's an ongoing journey, but if you're someone who genuinely enjoys learning, it doesn't really feel like a burden. It's just part of what makes the field so interesting."
The relief of finally cracking it
Asked what excites her most right now, Nastassja didn't point to a specific technology so much as the process of the work itself.
"Cybersecurity is such a broad field. Even within a SOC, you have offensive security, digital forensics, threat intelligence, threat hunting, incident response, and so many other areas you can specialize in.
For me personally, the most interesting part is figuring out how something can be exploited, how you could actually hack it in the real sense of the word. I enjoy the challenge of digging into a problem, trying different approaches, hitting dead ends, and eventually finding a way through. It's a bit of a roller coaster. The sense of accomplishment when you finally succeed is great, even if that feeling sometimes lasts only a few minutes compared to the hours or days you spent getting there.
We often joke within the team that there's nothing you can't hack; it's usually just a matter of time, knowledge, and effort. In the end, it really comes down to passion and curiosity. If you're interested enough in a problem, you'll keep digging until you find an answer.
A lot of the time, you start investigating one technology and end up somewhere completely different. Maybe the answer lies in an old bypass technique that still works on a newer version, or in some unexpected interaction between systems. That's what makes the work so interesting. You constantly have to learn, adapt, and keep exploring.
More broadly, I think that's what I enjoy most about cybersecurity. You're always learning something new and developing skills across different domains. And when all that effort finally pays off and you solve a problem or understand how something works, it's incredibly rewarding."
From self-doubt to a career in global offensive security
Asked what she'd tell someone hesitant to enter the field, Nastassja spoke candidly about her own early lack of confidence.
"Honestly, at first I regretted not going straight into cybersecurity. I kept thinking, why didn't I just do an engineering degree or follow an IT path from the start? I wasn't very confident in my own abilities, and I didn't feel technical enough. As a woman, you also look around and see a field that is still heavily male-dominated, and it can be difficult to picture where you fit in.
I think women sometimes feel like they have to prove themselves twice before people trust them. Not necessarily because others consciously think less of them, but because we often carry our own doubts and biases about ourselves.
My advice would be not to let that stop you if it's something you're genuinely interested in, something you enjoy, and something that would make you happy at the end of the day. Cybersecurity is a huge field. Maybe you start in offensive security and discover that forensics, incident response, threat hunting or compliance is actually what excites you most. Maybe threat hunting or threat intelligence turns out to be a better fit. There are so many different paths you can take.
Sometimes people get into cybersecurity because of something they saw in the news, on social media, or in a movie, and then end up building a career in a completely different area than they originally imagined. That's one of the great things about this field: there are always opportunities to find what really motivates you.
I wasn't confident at all when I started. If someone had told me back then that I would one day be working in global offensive security for the world's largest food and beverage company, I probably wouldn't have believed them. That's why I think it's important not to underestimate yourself and to keep moving forward, even when you're not completely sure you're ready. Often, you're far more capable than you think. "
We'll leave Nastassja with one quickfire, industry-old debate.
True or false: the best red teamers study blue team skills, and the best blue teamers study red?
"Both are true, at least from my perspective. As someone working in offensive security, you need to understand what the blue team is capable of so you can understand how detection works and how an attacker might try to avoid it. At the same time, if you're on the defensive side, it helps a lot to understand how threat actors think and operate.
On our team, we're constantly trying to learn from the blue team. We work closely with them and regularly exchange insights. Sometimes they'll tell us that a custom detection rule was triggered by something we didn't expect, and that's valuable feedback for us. We learn from it, adapt our techniques, and improve our understanding. The technology and the tactics on both sides are evolving all the time, so staying connected is incredibly important.
I think that's something people should never lose sight of. Whatever your main specialization is, whether it's offensive security, incident response, threat hunting, or something else, it's worth investing time in understanding the other side as well. It makes you better at your own job.
At the same time, it's important to accept that nobody can know everything in cybersecurity. The field is simply too big, and it's growing every day. I think a lot of people become frustrated because they feel they should know every technology, every attack technique, or every security domain. The reality is that none of us ever will, and that's perfectly normal.
My advice is to focus first on the areas that genuinely interest you and build strong expertise there. Then, learn what you need around that to be effective in your role. Curiosity is important, but you don't have to master everything at once. The people who stay in this field for the long run are usually the ones who keep learning while accepting that there will always be more to discover. That's part of what makes cybersecurity so interesting in the first place."