AI & Security Engineer focused on agentic systems, Rust tooling, and Linux
Portfolio · Email · UseSecure · Madrid, Colombia
I build developer tools and production systems where reliability and security matter. My work spans agentic AI systems, Rust and TypeScript, Linux applications, static analysis, authentication and authorization, data platforms, and cloud delivery.
I use coding agents within a disciplined engineering workflow: scoped tasks, deterministic controls, automated checks, security review, reproducible evals, and human validation.
- Built SecureFlow, a local-first evidence platform that connects deterministic analysis, contextual security review, reproducible benchmarks, a versioned knowledge base, and offline API-inventory research. Human validation remains authoritative; the project does not claim autonomous vulnerability validation or human replacement.
- Built and published Secure Engine, a local-first Rust security analyzer for JavaScript and TypeScript that follows untrusted data across files and helpers, then emits reproducible source-to-sink evidence through CLI, desktop UI, JSON, and SARIF.
- Modernized a production travel platform while preserving indexed routes, content, metadata, and search visibility, then automated quotation and customer follow-up workflows that were previously manual.
- Discovered and responsibly disclosed GHSA-hc5h-gqhc-4h79, a Moderate integration CSRF vulnerability in Trigger.dev's Slack OAuth flow; credited as the reporter and fixed in version 4.5.12.
- Reported a security issue to RustDesk through coordinated private disclosure; the maintainers acknowledged the report and merged the related fix.
- Delivered an invited technical talk at the Max Planck Institute for Security and Privacy on structural security risks in AI-assisted software systems.
| Project | Work and outcome | Evidence |
|---|---|---|
| SecureFlow | Local-first Rust platform combining deterministic scanning, human-reviewed evidence, advisory provenance, benchmark contracts, and offline Next.js/API inventory. v0.2.0 adds sealed Web scopes and synthetic API-risk corpus generation without network scanning. | Repository · v0.2.0 |
| UseSecure | Local-first Rust analysis, signed releases, performance engineering, and reproducible benchmark infrastructure | Engine v0.1.10-rc2 · Bench |
| Production platforms | Modernized customer-facing and operational systems across discovery, quotations, booking, publishing, authentication, PostgreSQL, and AWS-backed media | Mitiquete · Conociendo Colombia · TripEuropa |
| Open source | Small, reviewable fixes across Rust and Linux tooling, CLI behavior, desktop integration, CI, dependencies, and regression coverage | Contribution activity |
| CMS Nova | Reusable headless CMS foundation with schema-driven content, hybrid persistence, template tooling, and role-based administration | Repository |
- AI systems: agent orchestration, task scoping, evals, guardrails, human-in-the-loop validation, AI-assisted delivery
- Languages: Rust, TypeScript, JavaScript, Python, SQL, shell
- Platforms: Linux, Next.js, React, Node.js, PostgreSQL, Prisma, Docker, GitHub Actions, Nix, AWS, Vercel, Hetzner
- Security: authentication, authorization, tenant isolation, secrets, storage, webhooks, static analysis, and coordinated disclosure
I lead software architecture and AI-assisted engineering at Mitiquete SAS while contributing to open-source tooling and developing public security tooling and evaluation infrastructure.
Spanish is my native language, and I work professionally in English.


