DC / Engineering
Software engineerColombia / remote

Daniel
Castrillon

I build security tooling, Linux infrastructure, and production web systems—with evidence behind every important change.

v0.1.8

Secure Engine stable release

Rust

local-first security tooling

Linux

upstream compatibility work

Invited

security research seminar at MPI-SP

A balanced view of what I build.

Security infrastructure, open-source engineering, reusable foundations, and production modernization—with direct evidence for each area.

Project

Open-source contributions

What I work on

Focused fixes across Rust and Linux tooling, structured-data serialization, CLI behavior, desktop integration, CI, dependencies, and regression coverage.

Project

UseSecure

What I work on

A local-first Rust analyzer, independently frozen security benchmarks, and a reusable workflow for evidence-backed review and disclosure.

Project

Security research & communication

What I work on

Delivered an invited technical talk to researchers at the Max Planck Institute for Security and Privacy on structural security failures in AI-assisted software systems.

Project

CMS Nova

What I work on

A reusable headless CMS foundation with schema-driven content, hybrid persistence, template tooling, localization, media workflows, and role-based administration.

Evidence

Project

Production platforms

What I work on

Modernization across booking, automated quotations, publishing, localization, authentication, PostgreSQL, AWS-backed media, and AI-assisted operations—while preserving search visibility and business continuity.

How I make complex work reviewable.

  1. 01

    Model boundaries before features.

    I start with ownership, trust, data flow, failure modes, and operational constraints. The interface comes after the system has a shape.

  2. 02

    Keep authorization close to the action.

    Authentication is not authorization. Every mutation, route, and storage path must preserve tenant, role, and ownership boundaries.

  3. 03

    Make AI output earn trust.

    Coding agents accelerate implementation, but generated changes still pass typed contracts, tests, security review, and human judgment.

  4. 04

    Ship evidence, not adjectives.

    Production behavior, reproducible measurements, reviewable changes, and explicit tradeoffs communicate more than inflated titles.

Work that can be inspected and challenged.

Upstream open source

I contribute small, reviewable fixes across actively maintained projects. Recent work covers Rust and Linux tooling, structured-data serialization, CLI detection, desktop and AppImage integration, CI hardening, dependencies, and targeted state-management bugs.

View contribution activity
Application security

Built Secure Engine and Secure Bench, and reported reproducible authentication and authorization issues through coordinated private disclosure channels.

Invited research seminar

Presented structural security failures in AI-assisted software systems to researchers at the Max Planck Institute for Security and Privacy.

Production first. Evidence throughout.

I am a Colombian software engineer working across product security, Rust and Linux tooling, platform architecture, and AI-assisted development. I care about systems that remain understandable after the demo is over.

Primary stack

Rust, TypeScript, JavaScript, Python, SQL, shell

Systems and delivery

Linux, Fedora, Docker, GitHub Actions, Nix, PostgreSQL, AWS

Working languages

Spanish native · professional English