Curriculum vitae / 2026

Diego
Borghgraef

Senior Cyber Security Consultant

Security that survives contact with reality.

Senior Cyber Security Consultant with four years of experience at EY, focused on Defensive Security, Cyberfootprinting and M&A Cyber Assessments. I work where technical depth, business pressure and operational constraints meet—turning complex security problems into practical capabilities.

EY

Senior Cyber Security Consultant

4 years
  • Defensive-security delivery across SIEM/SOC implementation, Microsoft Sentinel, SOAR, threat hunting, incident response and ransomware forensics.
  • Cyberfootprinting and external-attack-surface work combining exposure discovery, OSINT, breach intelligence, metadata analysis, OCR and automated reporting.
  • Cybersecurity M&A assessments and due diligence performed under strict access and delivery timelines.
  • Cloud, Kubernetes, OT and authorised offensive-security assessments across government, transport, pharmaceutical, food and critical-infrastructure environments.
Diego Borghgraef / Curriculum vitae 01 / 02

Selected technical work

Built for the work itself.

HSKY / CV

01

Attack Surface Management Platform

A proprietary platform that turns broad external reconnaissance into structured intelligence and repeatable reporting.

  • Domain and exposed-service analysis
  • Breach intelligence and metadata extraction
  • OCR-assisted PII analysis
  • Automated, reviewable reporting

02

M&A Fieldwork Application

A purpose-built web application for mapping, extracting and reporting security information during time-sensitive on-site M&A work.

  • Structured fieldwork and evidence capture
  • Consistent mapping across workstreams
  • Faster extraction of report-ready information
  • Targets ranging from 50+ to 300+ users
01

Defensive

SIEM, SOC, SOAR, detection, threat hunting, IR and forensics.

02

Cyberfootprinting

OSINT, attack surface, breach intelligence and automation.

03

M&A

Cyber assessments, due diligence, fieldwork and reporting.

04

Cloud

Azure, IAM, CIS benchmarks, Kubernetes, Intune and DevSecOps.

05

OT

Asset discovery, vulnerability assessment and posture reviews.

06

Offensive

Authorised web, infrastructure, mobile and purple-team testing.

  • SC-200Microsoft Security Operations Analyst
  • AZ-900Microsoft Azure Fundamentals
  • CCNACisco Certified Network Associate

Bachelor Information Security
Thomas More

Dutch / French / English