EDPSErnesto Del Palacio Saiz

ErnestoDel PalacioSaiz

Cyber security · Presales · Software

6+

years

In technology and cyber security

120+

exercises

Cyber exercises and workshops at Deloitte

40–80

deals

Enterprise opportunities in parallel at Omada

€1M

ARR ceiling

Largest deal band worked at Omada

01

Career

Consulting, security ownership and enterprise presales, plus the company I have run alongside since 2022.

2022 – Today

Copenhagen, Denmark

Current

Incredibilis Corporation

Founder

My own software company, run alongside full-time employment since 2022. I find, pitch and close my own clients, then own requirements, architecture, development and delivery.

  • Built an athlete-management platform from the ground up: multitenant SaaS, React front end, PostgreSQL schema design on Supabase, REST APIs, CI/CD pipelines and containers. Hosted and ran it myself.
  • Used it in my own personal-training practice to win and retain clients, then productised it for other trainers. I onboarded and trained the users myself, handled the pushback, and supported them day to day so it stayed in use instead of stopping at launch.
  • Separately hired to further develop an existing platform serving 2,500 customers and 30,000 leads: architected, built and tested a MongoDB to Supabase migration, designed to cut database cost and improve scaling. The project was cancelled before launch, so the migration never ran in production.
  • That platform is where the heavier API work sits: self-built REST APIs with OpenAPI specs, an API gateway and access control, and PostgreSQL schema design with Drizzle.
  • Built and run my own CRM: designed the schema, wrote the code, and use it to run my own go-to-market end to end, from target list and segmentation through to closed deal.
  • Build my own LLM tooling to deliver faster: MCP servers, document retrieval and multi-step, tool-calling automation. I code with AI agents as part of how I deliver.
  • Manage a small delivery team of two freelancers plus additional specialists, and have continued to deliver crisis management exercises as paid consulting since leaving Deloitte.
  • 2,500customers the migration was built and tested for
  • 2015writing production code since
  • Founder
  • Full stack
  • Supabase
  • Next.js
  • CI/CD
  • Client delivery

2024 – Today

Copenhagen, Denmark

Current

Omada A/S

Senior Presales Engineer

Technical lead on enterprise deals for an identity governance and administration platform, working alongside Account Executives from first discovery through to technical close.

  • Own the technical side of the enterprise sales cycle: qualification, discovery, demos, workshops, and the proofs of value and pilots I scope and run end to end inside customer environments.
  • Integrate via REST and SOAP APIs, including OpenAPI specs, across AWS, Azure and GCP, plus LDAP and Active Directory directory integrations, Microsoft 365 and Entra ID, Jira, ServiceNow and SAP.
  • Work the identity governance domain daily: access reviews, entitlements, joiner-mover-leaver workflows, segregation of duties and least-privilege access.
  • Produce the deliverables that move a deal: solution proposals, statements of work, RFx responses and technical documentation, for engineers, architects and C-level stakeholders.
  • Sit between customer, sales and product as the technical voice of the customer, feeding recurring requirements back so that what is sold can actually be delivered.
  • Built ChatGPT agents for RFIs, RFPs and proposals, cutting turnaround by more than 70%.
  • Trained and enabled channel partners, and took formal MEDDPICC training here to qualify and prioritise.
  • 40–80enterprise opportunities carried in parallel
  • €50k–1MARR deal band
  • 70%+cut in RFx turnaround
  • Presales
  • Identity governance
  • REST & SOAP APIs
  • AWS / Azure / GCP
  • MEDDPICC
  • Enterprise

2023 – 2024

Copenhagen, Denmark

GetWhy A/S

Information Security Manager

The entire security function of a SaaS product company, built from scratch, with no direct reports and everything to drive across engineering.

  • Sole owner of security: cloud infrastructure security, application security and code review, vulnerability management, GRC, ISMS and risk management.
  • Coordinated penetration tests and drove remediation of 12 critical vulnerabilities and misconfigurations, closing real breach exposure.
  • Closed high-risk gaps across an acquired company's infrastructure during M&A integration.
  • Defined a three-year security maturity strategy and a risk register, applying FAIR to quantify and prioritise, and implemented a Technical Vulnerability Management Program.
  • Facilitated security assessments against ISO 27001 and NIST, reviewing controls and evidence and giving practical remediation recommendations.
  • Delivered security training and broadcast company-wide security awareness updates.
  • 12critical vulnerabilities remediated
  • 3-yearsecurity maturity strategy defined
  • AppSec
  • Vulnerability management
  • GRC
  • ISO 27001
  • NIST
  • FAIR
  • M&A

2021 – 2023

Copenhagen, Denmark

Januar ApS

Cyber Security Specialist & IT Operations

Second line of defence and subject-matter expert at a financial-sector payments institute, covering both security and the IT estate.

  • Implemented CrowdStrike Falcon and worked hands-on with Microsoft Defender to detect and remediate real security incidents, investigating root cause and collecting evidence from affected systems.
  • Internal escalation point behind an outsourced SOC, an incident response retainer and managed vulnerability scanning. Defined the requirements and scored the competing proposals in their selection.
  • Used MITRE ATT&CK for threat modelling and to define the scope of penetration tests. Wrote security policies, response playbooks and contingency plans.
  • Rolled out device management on Microsoft Intune across every end-user device, working through real resistance, writing the guidance and training people myself, then ran the estate afterwards: access provisioning and deprovisioning, remote support, ticketing and asset inventory.
  • Main contributor to the security governance forum, where priorities were agreed with business and technical stakeholders. Ran GDPR compliance work in a regulated financial context.
  • Ran two cyber exercises: an interactive tabletop and a full simulation of a major cyber incident.
  • Danish FSApayments-institute licence, key contributor
  • 0 → managedsecurity maturity on CMMI
  • Company-wideIntune MDM rollout
  • Incident response
  • CrowdStrike Falcon
  • Microsoft Defender
  • MITRE ATT&CK
  • Intune / MDM
  • Regulated finance

2020 – 2021

Madrid, Spain

Deloitte

Cyber Wargaming Senior Consultant

Built simulated enterprise environments and ran the crisis exercises that put client incident response teams under real pressure.

  • Built fully functional simulated enterprise and SOC environments with SIEM and log analytics (Splunk, ELK, IBM QRadar) and endpoint and network security tooling (Microsoft Defender, Carbon Black, Check Point), and developed the detection rules and use cases that drove each exercise.
  • Designed the attack scenarios against MITRE ATT&CK.
  • Led crisis management exercises for financial and energy sector clients, scoping each one with executive and technical stakeholders and writing the findings up afterwards.
  • Trained customer incident response teams to use that tooling in their own operations.
  • Managed engagements end to end: scope, timelines, multiple stakeholders and internal specialists, presenting and facilitating with senior stakeholders under pressure.
  • 120+cyber exercises delivered
  • 100%success rate, Europe and Latin America
  • Highestscore in the annual performance evaluation
  • Crisis exercises
  • Splunk
  • ELK
  • QRadar
  • Detection rules
  • MITRE ATT&CK
  • Client-facing

2019 – 2020

Madrid, Spain

Deloitte

Cyber Risk Strategy Consultant

Consulting across financial services, energy, insurance and pharma: gap analyses, corporate security strategy and operating models, with executive stakeholders.

  • Led projects conducting gap analyses and defining corporate cyber security strategy with executive stakeholders.
  • Assisted in operating-model assessment and target-operating-model definition for insurance-sector companies.
  • Delivered security consulting for financial-sector clients: ISMS and governance, and a PCI-DSS compliance check for a customer.
  • Took part in a CMMI appraisal.
  • 50%faster delivery from a self-developed agile process
  • Strategy
  • Gap analysis
  • PCI-DSS
  • Target operating model
  • CMMI

2017 – 2018

Madrid, Spain

Accenture

Identity & Access Management Intern

First identity work: building IAM integrations on a microservices architecture, which is where the through-line to Omada starts.

  • Built IAM integrations importing users, resource assignments and access contexts across large datasets using SQL, on a microservices architecture for scalable and secure identity management.
  • Worked on API gateway, API governance and standards, and auth and access control on APIs.
  • Handled LDAP and Active Directory directory integrations.
  • IAM
  • SQL
  • Microservices
  • API gateway
  • LDAP / AD

2016 – 2017

Spain

Yoopper Global International S.L.

Full Stack Developer

Full products end to end in PHP and JavaScript: web apps with APIs, database through to UI.

  • Full stack development in PHP and JavaScript, shipping complete products rather than front ends.
  • PHP
  • JavaScript
  • Full stack

2015

Italy

More for Less srl

Full Stack Developer

Where the production code starts: C# and .NET, full stack, 2015.

  • Full stack development in C# and .NET, database through to UI.
  • C#
  • .NET
  • Full stack

02

Projects & initiatives

Built under my own company rather than for an employer. Products, internal tooling and sites.

  1. 01

    Tabletop as a Service

    Crisis simulation platform

    A facilitation console for running cyber security tabletop exercises, with AI stakeholders players can actually argue with.

    An administrator builds an exercise from an ordered set of injects and drives it like a slideshow, while players see the current inject synced in real time, answer polls whose results can be revealed on every screen, and hold private conversations with AI stakeholder agents that each carry their own system prompt. It comes directly from running more than 120 of these exercises by hand at Deloitte: the parts that used to need three facilitators in the room are the parts this automates.

    • Next.js 16
    • TypeScript
    • Supabase
    • Postgres RLS
    • Realtime
    • Claude API

    In build

    2026

  2. 02

    Task Manager

    Spec-first project management

    A ClickUp-class task manager built spec-first: nothing gets written that a numbered specification does not already describe.

    Full hierarchy from workspace down to task, with list, board, table, calendar and Gantt views, subtasks, comments, custom fields and activity logs, plus a freeform whiteboard and a task-driven mindmap canvas. The interesting part is the method rather than the feature list: 18 atomic, independently shippable specifications form the backlog, and row-level security enforces workspace roles at the database rather than in the application.

    • Next.js
    • React
    • TypeScript
    • Supabase
    • RLS
    • tldraw
    • React Flow

    In build

    2026

  3. 03

    Go-to-market CRM

    Internal revenue system

    The CRM I built and run my own go-to-market on, from target list and segmentation through to closed deal.

    A small, opinionated pipeline tool for a team that has outgrown a shared spreadsheet but does not need a commercial CRM: one record per company, contact and deal, every open deal in exactly one stage, a durable activity timeline, and tasks that stop follow-ups living in one person's head. I designed the schema and wrote the code. It is my own internal system, not something I sell.

    • TypeScript
    • Postgres
    • Specification-led

    Running

    2026

  4. 04

    Coaching platform

    Athlete management SaaS

    The multitenant coaching platform I built for my own personal-training practice, then productised for other trainers.

    Coaches manage athletes, exercises, workouts, programs, nutrition and body-composition tracking. Every domain goes through an RTK Query slice pointed at a single serverless proxy, so the browser never holds a database credential, and the coach record is the tenancy key threaded through every query. It won and retained my own clients before anyone else used it, which is the only product test I trust.

    • React
    • Redux Toolkit
    • Tailwind
    • Supabase
    • Auth0
    • Vercel Edge

    Running

    2023

  5. 05

    Coaching mobile app

    React Native companion

    The athlete-facing side of the same platform: programs, a daily journal, diet tracking and progress, on iOS and Android.

    A bare React Native app, not Expo, sharing its Supabase backend with the web platform. Auth is magic-link, and row-level security does the per-athlete isolation properly: the client authenticates as the real user, so PostgREST enforces the boundary rather than the app asking politely. Three languages, offline-aware storage, and charts for body composition and personal records.

    • React Native 0.74
    • Redux Toolkit
    • Supabase
    • RLS
    • i18next
    • Notifee

    In build

    2024

  6. 06

    X Post Mocker

    Exercise inject builder

    Builds the realistic fake social posts you drop into a crisis simulation to see how a team reacts.

    It runs entirely on localhost: no hosted services, no accounts, nothing leaves the machine. Every export is stamped with a red SIMULATION ribbon and a watermark, and those are deliberately not removable, because a training artefact that can pass for a real post is a liability rather than a feature. Built to feed the tabletop exercises.

    • Next.js 16
    • React 19
    • Tailwind
    • Playwright
    • html2canvas

    In build

    2026

  7. 07

    Incredibilis Fitness

    Coaching site

    Three-language marketing and funnel site for the coaching practice.

    Static Astro in English, Danish and Spanish, with pricing tiers and availability driven from a single typed config file so the copy and the offer never drift apart. Cookie-gated analytics, self-hosted fonts, and a serverless route handling the funnel.

    • Astro
    • Tailwind 4
    • TypeScript
    • Resend
    • Vercel
  8. 08

    Incredibilis Consulting

    Consultancy site

    Bilingual marketing site for the offensive-security and AI side of the company: penetration testing, automated red teaming, tabletop exercises and advisory.

    English and Danish, static Astro with near-zero JavaScript and a single on-demand route for the contact form. The design brief was honest authority for a DORA and NCCS compliance audience: standards alignment, methodology and deliverables, and no fabricated testimonials or client logos, which is harder to make convincing than the alternative.

    • Astro 7
    • Tailwind 4
    • TypeScript
    • Supabase
    • Vercel

03

About

I am a Senior Presales Engineer at Omada, where I own the technical side of enterprise identity governance deals with Account Executives: discovery, demos, workshops, and the proofs of value and pilots I run end to end inside customer environments.

Before presales I ran security myself. I was the whole security function at GetWhy and the second line of defence at a Danish payments institute, so I know what it costs when something is missed. Before that I consulted at Deloitte across financial services, energy and insurance.

Outside of that I coach people in health and fitness, I hold a First Response Emergency Care certification, and I am interested in physical security and history. What motivates me most, at work and outside it, is having a positive impact on the people around me.

How I work

  • Consultative before anything elseI find the real problem and the success criteria first, then I demo.
  • The same answer for an engineer and for a CIOI change the level of detail, never the substance, so every stakeholder can trust it.
  • Hands-on, not just slidesI code, build, and run proofs of value myself, so I stay credible with engineers.
  • Honest about the limits of my knowledgeI would rather say I am not sure and go and check.

04

Toolkit & credentials

Presales & delivery

  • Technical discovery
  • Proofs of value and pilots
  • Demos and workshops
  • Solution proposals and SOWs
  • RFx responses
  • MEDDPICC (trained at Omada)
  • Channel partner enablement

Identity & access

  • Identity governance (IGA)
  • Joiner-mover-leaver workflows
  • Access reviews and entitlements
  • Segregation of duties
  • Least-privilege access
  • LDAP / Active Directory
  • Microsoft 365 / Entra ID

Security

  • Application security and code review
  • Vulnerability management
  • GRC, ISMS and risk management
  • ISO 27001 and NIST assessments
  • MITRE ATT&CK
  • CrowdStrike Falcon, Microsoft Defender
  • Splunk, ELK and QRadar
  • FAIR quantitative risk
  • Crisis management exercises

Engineering

  • TypeScript and Python
  • Next.js, React, React Native, Astro
  • PostgreSQL and Supabase
  • REST and SOAP APIs, OpenAPI
  • API gateway and access control
  • CI/CD pipelines and containers
  • AWS, Azure, GCP
  • MCP servers and LLM tooling

Education

  • MSc, Technology EntrepreneurshipTechnical University of Denmark (DTU)2021–2023
  • Exchange, Computer Science & EngineeringUniversity of Florida2018–2019
  • BSc, Computer Science & EngineeringUniversidad Carlos III de Madrid2015–2020
  • Technician, Networked SystemsIES Julián Marías2013–2015

Certifications

  • Red Team Certified Professional
  • Certified Threat Intelligence AnalystEC-Council
  • Digital Forensics and Incident ResponseCourse completed
  • eWPTXeLearnSecurity (final exam pending)
  • Professional Scrum Master IScrum.org
  • Introduction to Kubernetes (LFS158x)Linux Foundation
  • Level 6 Diploma in Hostile Environment OperationsProQual Awarding Body, 2023
  • International Personal Security Detail (PSD)City & Guilds, 2023
  • Private Military ContractorEuropean Security Academy, 2023
  • Tactical Combat Casualty CareNAEMT, 2024
  • First Response Emergency CareEuropean Security Academy, 2023

Languages

  • SpanishNative
  • EnglishC1, fluent and professional

05

Let's talk.

The fastest way to reach me is LinkedIn. I read every message that is actually about the work.

linkedin.com/in/saizdev