I'm a security engineer interested in backend, platform, and infrastructure engineering, with a focus on Linux, automation, and reproducible systems.
I enjoy writing software, particularly backend services, developer tooling, and infrastructure automation. I work on APIs, development environments, CI/CD workflows, and declarative infrastructure, treating configuration, pipelines, and policies as code: versioned, reviewable, and reproducible.
My academic and research work has also involved RISC-V, hardware security, systems programming, and Linux kernel development.
I hold an MSc in Cybersecurity Engineering from Politecnico di Torino.
Languages and backend
Systems and infrastructure
Security testing suite for eBPF/XDP kernel programs based on ISO/IEC TS 17961. Includes XVTLAS, a Go tool that automates vulnerability patch injection, program loading, and Linux verifier analysis.
C Go eBPF/XDP Linux KVM/QEMU
Modular, multi-host configuration for NixOS workstations and home servers. It combines NixOS and Home Manager modules, declarative provisioning, self-hosted services, local and off-site backups, encrypted secrets, overlay networking, and a filtered public mirror.
Declarative systems Self-hosting Automated backups Secrets management Reverse proxy Private networking Reproducible deployment
Attendance system built around a Django REST API and PostgreSQL, with QR-based check-ins and institutional SAML2 authentication brokered through Keycloak. Its development and deployment environments are reproduced with Nix and devenv.
Python Django PostgreSQL SAML2 Keycloak Nix devenv
Open educational resources built reproducibly as Nix derivations and published through GitLab CI/CD, with membership automation running on Cloudflare Workers.
Nix devenv GitLab CI/CD Cloudflare Workers

