Security & AI Engineer
I build security tools, then try to break my own results
Supply-chain defence, phishing detection and vulnerability triage — shipped with tests, CI gates and strict typing, and measured honestly enough to report the number that hurts.
About

Security & AI Engineer | Detection Engineering · Supply-Chain Security · Applied ML
Final-semester Systems & Software Engineering student (UPB Bucaramanga), early-career — I ship real tools and measure whether they work.
I'm a final-semester Systems & Software Engineering student at UPB (Bucaramanga) who operates at an engineering level rather than a findings level. The thread running through my work is measurement: I build production-grade tools with tests, CI pipelines and strict typing, and then I check whether the number I just produced means anything. SlopGuard, my flagship, addresses slopsquatting — the attack surface where LLMs suggest package names that do not exist and attackers pre-register them with malicious code — with a 5-layer detection engine, zero runtime dependencies and frontends for CLI, pre-commit, GitHub Actions and a self-hostable SaaS. My phishing classifier found two independent label leaks in the dataset the literature reports 99 %+ on, and publishes the honest number instead: 70.5 % recall at a 1 % false-positive rate against phishing collected two years later. My vulnerability-prioritisation dashboard reproduced the 6.1× advantage everyone quotes for EPSS and then showed most of it is an artefact of scoring a forecaster against data it had already seen. Alongside that: mobile hardening with TOTP 2FA and OS-backed secure storage, and high-availability AWS infrastructure fully codified in Terraform. Verified C2 English (EF SET 80/100). Available for remote collaboration.
- johan.rc2020@gmail.com
- GitHub
- CV
- C2 — EF SET 80/100 verify
Featured work
View all projects →Let's work together
I'm open to security & engineering roles, remote-first. Tell me what you're building.
Get in touch →