Software Engineer | Rust Security Tooling | Linux & Open Source | Application Security
Portfolio · Email · UseSecure · Madrid, Colombia
I build security tooling, Linux infrastructure, and production web systems. My work combines upstream open-source contributions, local-first static analysis, reproducible engineering, and hands-on ownership of authentication, authorization, data, and deployment boundaries.
I use coding agents as engineering tools: scoped tasks, typed contracts, automated verification, security review, and human validation. The objective is reliable software with evidence behind it—not code generation for its own sake.
| Project | What I work on | Evidence |
|---|---|---|
| Codex Desktop Linux | Linux reliability, Rust updater inputs, per-user browser integration, CI hardening, native dependencies, and regression coverage | Merged contributions |
| UseSecure | A local-first Rust analyzer, independently frozen security benchmarks, and a reusable workflow for evidence-backed review | Engine v0.1.8 · Bench |
| CMS Nova | A reusable headless CMS foundation with schema-driven content, hybrid persistence, template tooling, and role-based administration | Repository |
| Production platforms | Architecture and delivery across booking, B2B operations, publishing, localization, authentication, PostgreSQL, and AWS-backed media | Mitiquete · Conociendo Colombia · TripEuropa |
I contribute focused fixes to actively maintained projects, primarily across Rust, TypeScript, JavaScript, shell tooling, Nix, and GitHub Actions.
- Repaired updater fallback inputs and per-user browser-integration socket discovery in Codex Desktop Linux.
- Hardened privileged CI actions and vulnerable native-module build dependencies.
- Added regression coverage and validated changes through Rust tests, script tests, and Fedora package rebuilds.
- Perform evidence-backed security reviews and use private disclosure channels when a finding could affect users.
I prioritize projects with real contributor activity, responsive maintainers, reproducible issues, and changes small enough to review confidently.
- Built and published Secure Engine v0.1.8 with deterministic analysis, reproducible Fedora packaging, signed provenance, and local-first execution.
- Built Secure Bench around blinded holdouts, one-shot scanner campaigns, immutable evidence, independent verification, and corrected scoring contracts.
- Led authorization, tenant-isolation, secret-handling, and exposed-route hardening across production systems.
- Developed a capability- and invariant-centered review method for AI-assisted changes.
- Delivered an invited talk at the Max Planck Institute for Security and Privacy on structural security risks in AI-assisted software systems.
Benchmark results retain their lane boundaries and documented limitations. They support engineering decisions; they are not broad superiority claims.
- Languages: Rust, TypeScript, JavaScript, Python, SQL, shell
- Web and data: Next.js, React, Node.js, PostgreSQL, Prisma
- Systems and delivery: Linux, Fedora, Docker, Git, GitHub Actions, Nix, Vercel, Hetzner
- Security: authentication and authorization boundaries, tenant isolation, secrets, storage, webhooks, static analysis, evidence contracts
- Agent engineering: context construction, task decomposition, evaluation, failure-mode analysis, and verification-driven workflows
I lead software architecture and AI-assisted engineering at Mitiquete SAS while contributing to open-source Linux tooling and developing public security-review infrastructure.
Spanish is my native language, and I work professionally in English.


