LUIS_WOOD

Hello there!

Luis Wood

I'm Luis Wood. These days I'm a Product Owner on a Platforms product at Critical TechWorks (CTW), a BMW Group company, supporting 20 million connected vehicles and processing 15 billion MQTT messages a day. I own the roadmap and drive strategic alignment across the teams building the CI/CD and backend infrastructure that keeps that scale running — a step, in May 2025, from hands-on security and cryptography engineering into a product and strategy-facing role.

The path here

Since an early age, I've always been involved and fascinated with technology. In the early days, I taught myself basic website development with HTML, CSS and JavaScript. Although my academic background is quite distant from the IT world, in 2017 I decided to make a career shift. I already knew the basics of programming, so I enrolled in a Java course. In this course we went through Java 2nd edition and JavaEE, as well as a recap on web development basics.

In November 2017 I took my first job as part of an Artificial Intelligence team at Critical Software. In this position, I worked on a Natural Language Processing (NLP) project, building an MVP. My first task was converting a Node.js prototype, written in a single week, into JavaEE — a bit challenging since I'd never worked with Node.js before, but a genuinely enriching experience. I had the opportunity to build, alongside a colleague, the backend of the web application, creating the API that would shortly after serve a frontend built on HTML, CSS and JS. In September 2018, I moved to my current company, within the Critical Group: Critical TechWorks (CTW).

On my first project at CTW, I had the opportunity to work on a budget management tool. The first couple of months were dedicated to moving the original application, developed in Spring Boot, to JavaEE. Once again I had the opportunity to learn a great deal, given the chance to work with a framework new to me. Alongside the backend in JavaEE, our frontend was initially built in HTML, CSS and JS, and a few months in we moved to AngularJS. This was the most challenging portion of the project, since this technology was new to everyone on the team, most of whom had a background purely in backend. Even facing those challenges, we were able to deliver a product that matched stakeholder expectations, soon used frequently by different teams.

In December 2019, I was asked to take on the Scrum Master role, alongside my developer role, on a Privileged Access Management (PAM) team. In the early days of this new cybersecurity cycle, I acted as team lead — helping more junior profiles develop their skills, supporting the team's growth not just in numbers but in maturity, and building connections to stakeholders and other teams across the company. The team's main work was building new extensions, connection components and plugins for our main PAM tool, CyberArk, and little by little we took on new responsibilities across the operational side of the product too. Throughout, I worked with Python, AutoIT, JavaScript and PowerShell, across both Windows and Linux, configuring and integrating Jenkins, running Ansible playbooks for server management, and getting to know ITSM and incident management along the way.

From August 2022 until February 2023 I was involved in two main topics: Detection as Code and Cyber Threat Intelligence (CTI). With the former, I used GitHub Actions and Ansible to orchestrate the handling and validation of Sigma rules before they were deployed to Splunk. With CTI, I was responsible for implementing proofs of concept for multiple tools, plus custom development in Python, centralizing sensitive reports from different data sources to make vulnerability management easier.

In June 2023 I took on a new challenge at CTW, working closely with CTW's CISO on internal cybersecurity strategy: business continuity planning and simulation exercises, threat intelligence tooling to track digital footprint and leaked credentials, ISO 27001 audit coordination, and running security awareness campaigns and phishing simulations.

From July 2024 until May 2025, I moved into a cybersecurity engineering role focused on cryptography services, building and maintaining them on Quarkus and Java — the last stop before the move into product.

Outside of work, that same pull toward building things shows up as a homelab full of Raspberry Pis, dashboards, and the occasional soldering iron — some of which you can see under Projects.

Feel free to reach me on LinkedIn.