Skip to content

Security & AI Engineer

I build security tools, then try to break my own results

Supply-chain defence, phishing detection and vulnerability triage — shipped with tests, CI gates and strict typing, and measured honestly enough to report the number that hurts.

About

Johan David Rodriguez Castro
Bucaramanga, Santander, Colombia (remote-ready)

Security & AI Engineer | Detection Engineering · Supply-Chain Security · Applied ML

Final-semester Systems & Software Engineering student (UPB Bucaramanga), early-career — I ship real tools and measure whether they work.

I'm a final-semester Systems & Software Engineering student at UPB (Bucaramanga) who operates at an engineering level rather than a findings level. The thread running through my work is measurement: I build production-grade tools with tests, CI pipelines and strict typing, and then I check whether the number I just produced means anything. SlopGuard, my flagship, addresses slopsquatting — the attack surface where LLMs suggest package names that do not exist and attackers pre-register them with malicious code — with a 5-layer detection engine, zero runtime dependencies and frontends for CLI, pre-commit, GitHub Actions and a self-hostable SaaS. My phishing classifier found two independent label leaks in the dataset the literature reports 99 %+ on, and publishes the honest number instead: 70.5 % recall at a 1 % false-positive rate against phishing collected two years later. My vulnerability-prioritisation dashboard reproduced the 6.1× advantage everyone quotes for EPSS and then showed most of it is an artefact of scoring a forecaster against data it had already seen. Alongside that: mobile hardening with TOTP 2FA and OS-backed secure storage, and high-availability AWS infrastructure fully codified in Terraform. Verified C2 English (EF SET 80/100). Available for remote collaboration.

Let's work together

I'm open to security & engineering roles, remote-first. Tell me what you're building.

Get in touch