marcelo-moreno

$whoami

Marcelo Moreno

Computer Science, Security Concentration

Minor in Design & Innovation

Purdue University · Expected Dec 2026

Marcelo Moreno
01About me

Hi, I'm Marcelo, a final-year Computer Science student at Purdue focused on security. Across a Big Four consulting firm, a global exchange, a financial services group and a research lab, I've learned security from many angles, like assessments, SOC operations, cloud and research. Beyond the technical skills, the lesson that came up in every one of them is that communication is essential in security, because a finding only matters once the people who have to act on it understand it, and that idea is what led me to start Legible.

I'm also very interested in AI safety and the impact it will have on cybersecurity, and that's why over the past year I've been going deep into these systems, building agents, workflows and automations, and learning how to use them safely and responsibly.

Cybersecurity AI/Automation Communication/Translation This is where I land.
02Experience
  1. 2026
    Ernst & Young Cybersecurity Consultant I · Lima, Perú · Jun 2026 – Aug 2026

    EY is a "Big Four" global professional-services firm, spanning assurance, tax, and advisory across 150+ countries.

    This past summer I joined EY as a Cybersecurity Consultant, working with several clients and carrying real responsibility from the start. For a global automotive client I first spent time understanding how their Security Operations Center worked and where the gaps were, and from there I proposed and built a monitoring platform that brings everything into one consolidated triage queue, so EY analysts and the client's own team can work from the same place. For a critical infrastructure client I reviewed their cloud security across several providers, and in between I worked on vulnerability management and a few smaller projects.

    It took a lot of effort and full commitment, and it was worth it not only for the experience itself but also because I got to learn from some of the best professionals in the field. I also want to highlight the soft skills, since consulting taught me that the job isn't only finding and documenting issues but also explaining them clearly to the people who need to act on them.

    Marcelo Moreno on his first day at the EY office, Lima
    First Day at the Office
    The EY office building illuminated at night, Lima
    The Office at Night
  2. 2025
    Cboe Global Markets Incident Response Intern · Chicago, IL · Jun 2025 – Aug 2025

    Cboe runs some of the world's largest options, equities, futures, and FX markets, across North America, Europe, and Asia Pacific.

    At Cboe I was an Incident Response intern on the Threat Detection & Response team, inside a 24/7 global SOC where, after an intensive security operations training, I spent the summer investigating alerts from the queue and taking each one through the full triage and escalation process. It showed me how a global SOC really works and why it matters so much, especially when it protects the critical infrastructure behind some of the world's largest markets.

    Working inside such an advanced team taught me how much a solid methodology matters, and it also showed me how much room there is to keep improving, even in a mature operation. Along the way I learned new tools, communicated with people across different teams, and researched the best way for employees to bring AI into their day-to-day work.

    Marcelo Moreno on the Cboe trading floor, Chicago
    Cboe Trading Floor · Chicago
    Marcelo Moreno with his team at the Cboe Intern Summit
    Cboe Intern Summit
  3. 2024
    PurSec Lab, Purdue Undergraduate Research Assistant · West Lafayette, IN · May 2024 – Present

    PurSec Lab is Purdue's largest security research group, led by Prof. Berkay Celik.

    In summer 2024 I started research at PurSec Lab, where I went deep on security and AI by reading and dissecting papers, designing and running experiments, analyzing results, and writing up findings. I enjoyed it so much that it grew into more than two years of AI security research on LLM and VLM systems, which continues to this day.

    Purdue campus, summer 2024
    Purdue Campus Summer 2024

    See the research

  4. 2023
    Interbank Cybersecurity Intern · Lima, Perú · Jun 2023 – Aug 2023

    One of Peru's largest banks, part of Intercorp Financial Services, serving millions of retail and commercial clients.

    Interbank is where it all started. I joined the Detection & Response team just as the bank was evaluating new security technologies from major vendors like IBM, and I helped run a SOC maturity assessment to map out how their security operations would grow over the next few years. It gave me the foundations of cybersecurity and showed me how these teams evolve over time.

    They also gave me the chance to present that strategy to the bank's top leadership, which meant translating technical operations into business metrics they could act on. That's where I first saw how much communication matters when the same idea has to reach very different audiences, and it has been a passion of mine ever since.

    Marcelo Moreno with fellow interns on his first day at Interbank
    First Day at the Office
03Research
PurSec Lab

2+ years at PurSec Lab, Purdue University. Advised by Doguhan Yeke, under PI Prof. Berkay Celik. Purdue ranks #2 in the U.S. and #5 worldwide for computer security.

> "go past the red car, turn left, then stop at the blue building" start red car blue building
01read the instruction02find candidate places03compare routes with an LLM04commit to the best one

[01]ToT-Nav · Robot Navigation with a Tree of Thoughts

In submission
PurSec Lab · since 2024

Turning a plain-language instruction into a robot route, with a language model comparing possible routes side by side.

Imagine telling a robot to go past the red car, turn left, and stop at the blue building. ToT-Nav turns that sentence into a route without any navigation training data, because a language model reads the instruction, a vision model finds the places it mentions on a map, and a Tree-of-Thoughts search compares possible routes side by side until only the one that really follows what you said is left. I built the system end to end and evaluated it in indoor homes and on outdoor streets against LM-Nav, the system it extends.

GPT-4o · CLIP ViT-L/14 · Tree-of-Thoughts beam search · Matterport3D R2R · Python

typed instruction map images stored map LLM parser vision grounding LLM route ranker goal route prompt injection adversarial image tampered map
where untrusted input reaches a decisionthe route that was asked for

[02]ToT-Nav Security · Attacking the Navigator

Ongoing
PurSec Lab · since 2026

Looking at the navigator I built through an attacker's eyes, to find where untrusted input can steer it.

Once ToT-Nav worked, the natural next question was how someone could break it. So I'm now looking at the system through an attacker's eyes, mapping every point where untrusted input reaches a decision, from the instruction a user types to the images stored in the map, and designing attacks that could send the robot somewhere it was never told to go. It's still early work, and the goal is to understand these risks well enough to defend against them.

threat modeling · adversarial ML · prompt injection · vision-language models

change the scene model drives simulate judge propose next automated search edited control
the change being testedthe car driven by the modelthe loop that decides what to try next

[03]Red-Teaming Vision-Language Driving Models

Ongoing
PurSec Lab · since 2026

A framework that searches for the everyday street situations where AI driving models fail.

Self-driving cars are starting to be driven by vision-language models, so I built a framework that searches for the everyday situations where they fail. Instead of invisible pixel noise it changes things that really happen on a street, like a pedestrian in a hi-vis vest or someone in a bear costume, then lets the model drive through the scene in simulation, judges whether it acted unsafely, and compares every run against the same scene without the change, so a failure only counts when the change caused it. The framework is built, and finding those failure cases is what I'm working on now.

NVIDIA AlpaSim · Alpamayo · 3D Gaussian splatting · Gemini · Python

one index, shared by two tenants tenant B lives here attacker times its own writes before after write latency →
the attacker's dataanother tenant's data

[04]Timing Side Channels in Vector Databases

Exploratory study
PurSec Lab · Aug – Dec 2025

Whether timing alone can leak what other customers store in a shared vector database.

Many AI apps keep their knowledge in vector databases, and to save money several customers often share the same index behind the scenes. Building on a classic attack against shared search engines, I studied whether timing alone could leak what other customers store, because an attacker can time their own writes, and those writes may slow down when someone else's data sits nearby in the index. I compared how Qdrant, Milvus and Chroma keep tenants apart and built a harness in Qdrant to measure those delays.

Qdrant · HNSW · sentence embeddings · side-channel analysis · Python

04Selected Projects
[01]Legible

Legible grew out of the part of security work I enjoy most, which is explaining a finding to the person who has to decide about it. It measures what survives when a technical finding gets retold for a board, a regulator or a customer, using a corpus of 3,727 real findings paired with the summaries professionals wrote from them, a rubric with two axes that are never averaged, and three instruments on top, a search for how others retold a similar finding, a benchmark that measures what a model loses when it writes a briefing, and a reviewer that checks a draft against its source as you type.

See a preview of Legible

Courses · next class, next due, standing
Grade center · what is secured and what a target needs
Notes · an agent proposes, I confirm
[02]Semester OS

A personal dashboard that keeps a whole semester in one place, from the next class and the next deadline to where each grade actually stands. It pulls my calendars, syllabi and course platforms together, works out how much of every grade is already secured and what I would need on the rest to reach a target, and lets me type a note like "the quiz moved to Friday" so a Claude Code agent proposes the exact changes and waits for me to confirm them.

FastAPI · SQLite · React · TypeScript · Claude Code agents · Google Calendar API

Screens use invented courses.

[03]Unix Shell (C / C++)

A Unix shell written from scratch in C++ that behaves like a small bash. It parses each command line with a Flex and Bison grammar, runs programs with fork and exec, and connects pipes, background jobs and every kind of input, output and error redirection through dup2. On top of that it handles Ctrl-C without dying, runs builtins like cd, source and printenv, expands tildes (including other users' home directories), environment variables and wildcards, and comes with its own line editor with cursor movement and command history.

C++ · C · Flex · Bison · POSIX processes and signals

Illustrative session.

[04]J.P. Morgan Cybersecurity Simulation

Performed fraud analysis on payment services, built a Django OTP system, and developed an ML-based BEC phishing classifier.

05Teaching

This past summer I taught an AI course for incoming college freshmen, because I think they're the people who can get the most out of it right before they start university. The goal was to help them use AI to learn better from day one, so we covered how large language models work, how to prompt them well, and how to go further with MCPs, agents and automation, always alongside how to use AI responsibly and safely. Teaching it pushed me to make genuinely technical ideas clear to people starting from zero, which is the part I enjoy most.

06Organizations

Blue Team @ Purdue B01lers CTF SHPE (Leading Hispanics in STEM) AI Safety Purdue