whoami --verbose
Cloud & DevOps engineer at a cybersecurity product company in Donostia: R&D in exposure management and offensive security on a product that ships and runs in production. Before that, five years at an industrial scale-up shipping product to production —full stack (ML, WebRTC, PostgreSQL/Redis)— and platform work on Kubernetes, Ansible, GitHub Actions and Terraform on Azure.
AI offensive security came through the academic route: my master's thesis on adversarial campaigns against models, RAG systems and agents is the origin of NORN, an LLM red-teaming CLI framework with its taxonomy mapped to OWASP Top 10 for LLM, MITRE ATLAS and NIST AI RMF.
Everything I build ends up on GitHub: NORN and OSINT-OA are open source —sole developer on all three— and NAM was my final degree project. The thesis behind NORN is published, with its attack taxonomy, the campaigns and the metrics. I write code that ships and break code that should not.