Skip to content
View nicobts's full-sized avatar

Block or report nicobts

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
nicobts/README.md
Nicolas Bossi — Compliance · Security · Cloud · Applied AI

Portfolio LinkedIn Email CV

Solution architect and project manager. I lead programs where compliance, security, cloud, and AI meet, and I build the systems myself: infrastructure, pipelines, integrations, and agents. ISO 27001 and ISO 42001 lead auditor, DevOps engineer by habit.

Now

Blackwall (formerly BotGuard): Project Manager & Solution Architect, since 2025

  • ISO 27001 program. Leading organization-wide certification end to end: ISMS scope, policies, control framework, risk assessment, and cross-functional execution toward the audit.
  • Cloud marketplace integration. Architecting custom APIs that connect our platform to an enterprise cloud commerce marketplace, turning existing infrastructure into a fully automated SaaS offering that provisions straight into client workflows.
  • Delivery. Multi-stakeholder initiatives with complex dependencies, run on timeline, scope, and budget.

ActBI: I work on the DevOps side of an AI-powered analytics assistant: cloud infrastructure, CI/CD and deployment automation, and security and compliance.

Open source

Shiproom: an adversarial AI council that stress-tests project ideas before you build them. Seven seats (CTO, CFO, VC, CMO, CEO, your customer, a Chair), each with a kill mandate and a sourced fact base, deliver a pre-committed verdict: INVEST, SHIP_AND_SEE, or SHELVE. Ships as an Agent Skill and a Claude Code plugin, so it runs in Claude Code, Codex, Cursor, Gemini CLI, OpenCode, and other skills-aware agents.

GitHub · Website

Shiproom CI status and license

Artifact Room: an open-source, self-hostable home for the interactive HTML that AI tools generate. Share an artifact through unbranded, per-recipient links you own, keep it sandboxed and access-controlled, and see what each recipient actually did with it: which sections they read, whether they came back, whether they forwarded it. Cookieless analytics, one small container. The Community Edition is AGPL-3.0.

GitHub (Community Edition) · Website

Artifact Room CE CI status and license

Track record

  • Onda TLC, Product Manager (2020–2024): took a telecom product from concept to market, owning strategy, team, and delivery. $10M+ first-year revenue and a $5M provider contract.
  • Red Jobs, IT & Security Administrator (2024–2025): ran the Fortinet security layer (firewalls, IDS/IPS, VPN), hybrid infrastructure across on-prem, AWS, DigitalOcean, and Cloudflare, and deployed agentic-AI workflows for internal automation.
  • heia, IT Project Manager (2024–2025): owned the e-commerce platform and its integrations, brought the first AI agents into operations, coordinated marketing and sales, and reported to shareholders.
  • Universität Klagenfurt (2021): 5G / cloud / fog computing research project.
  • Earlier (2017–2020): web development and IT infrastructure in Trieste and Ontario. Won the Contamination Lab Trieste best business plan award and represented the University of Trieste at the OurCrowd Global Investor Summit 2019.

Certifications

Area Certification Issuer Year
AI Generative AI Leader Google Cloud 2026
AI governance ISO/IEC 42001 Lead Auditor (AI management systems) — 2026
Compliance ISO/IEC 27001 Lead Auditor Dasa-Rägister 2025
Compliance Management System Audits (ISO 19011 / ISO 17021-1) Dasa-Rägister 2025
Delivery Operational Excellence Foundations PMI 2025
DevOps DevOps Professional Certificate PagerDuty 2024
Security Fortinet Certified Fundamentals — Cybersecurity Fortinet 2024
Security Career Essentials in Cybersecurity Microsoft 2024
Cloud Partner Solution PRO — Cloud Principles Intel 2024
Data Data Reskill Program EPICODE 2024

Toolbox

Google Cloud AWS Oracle Cloud Azure Terraform Kubernetes Docker Python TypeScript Fortinet

  • Compliance & audit: ISO 27001 / ISMS, ISO 42001 / AIMS, ISO 19011 audits, NIS2, GDPR, risk assessment, policy writing, control frameworks
  • Security: threat modeling, incident response, IAM, network security, WAF, Fortinet
  • Cloud & DevOps: GCP, AWS, Oracle Cloud (OCI), Azure, Terraform, Docker, Kubernetes, CI/CD, Proxmox, Linux and Windows Server, Active Directory
  • Applied AI: agentic systems, MCP, multimodal RAG, LangChain, LlamaIndex, Qdrant, n8n, Dify, Langflow, CrewAI
  • Engineering: Python, TypeScript, Node.js, React / Next.js, PostgreSQL, SQL
  • Delivery: Agile (Scrum, Kanban), budget and risk management, stakeholder management

Writing

Current focus

  • DevOps automation: infrastructure as code, CI/CD, and day-to-day platform operations, mostly on GCP and AWS.
  • Cloud and AI integrations: connecting LLM services and agents to existing cloud platforms, APIs, and business workflows.
  • AI agents for operations: using coding agents and agent harnesses (MCP servers, skills, hooks, guardrails) to automate DevOps and infrastructure work safely.

Studying and improving

  • Machine learning fundamentals and open-weight models: local inference, quantization, serving
  • LLM evaluation: golden datasets, LLM-as-judge, regression testing
  • Agent frameworks and deep agents: planning, sub-agents, memory, tool design

Klagenfurt, Austria · Trieste, Italy · Italian (native), English, German

Pinned Loading

  1. shiproom shiproom Public

    The go/no-go room for your idea - an adversarial AI council (CTO, CFO, VC, CMO, CEO, your customer, a Chair) that won't tell you it's great. Runs in any coding agent.

    HTML 1

  2. artifact-room-ce artifact-room-ce Public

    Open-source, self-hostable host for AI-generated HTML artifacts: share via unbranded per-recipient links and see what happened after you hit send. AGPL-3.0.

    TypeScript

  3. gapnext-wp gapnext-wp Public

    PHP

  4. nanoclaw-nb nanoclaw-nb Public

    Forked from nanocoai/nanoclaw

    A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs dir…

    TypeScript

  5. starter-nextjs-btt-nb1 starter-nextjs-btt-nb1 Public

    TypeScript

  6. yeasin2002/bulletproof-nextjs-starter yeasin2002/bulletproof-nextjs-starter Public template

    A production-ready Next.js boilerplate with modern tooling, comprehensive testing, and enterprise-grade features.

    TypeScript 231 51