About

I’m Giovanni, a security engineer interested in backend, platform, and infrastructure engineering, with a focus on Linux, automation, and reproducible systems.

I build backend services, APIs, development environments, deployment workflows, and declarative infrastructure. I like applying an Everything as Code approach to infrastructure, system and application configuration, CI/CD pipelines, policies, and development environments, keeping them versioned, reviewable, and reproducible.

I use Nix and NixOS across development environments, system configuration, deployments, and self-hosted infrastructure, with a particular interest in declarative configuration and functional programming.

I also have a background in RISC-V, hardware security, systems programming, and Linux performance analysis, developed through academic and research projects.

Background Link to heading

  • MSc in Cybersecurity Engineering, 110/110 cum laude, from Politecnico di Torino, March 2026 — thesis on a reproducible design and verification workflow for integrating a TRNG into a RISC-V SoC
  • Research Assistant at the SMILIES research group, DAUIN, Politecnico di Torino, November 2024–December 2025 — development of a Linux kernel module exposing custom RISC-V performance counters through perf for a CPU simulated with gem5
  • BSc in Computer Engineering from Politecnico di Torino, March 2023
  • Full Stack Developer at Casamorana, March 2020–March 2023 — backend and frontend development for an e-commerce platform, including payment integration, data protection, and performance optimization

What I work with Link to heading

  • Languages: C, C#, Rust, Python, Go, Java, Nix, Bash, SQL
  • Backend: ASP.NET Core, Django, REST APIs, PostgreSQL, authentication and authorization
  • Systems and platform: Linux, NixOS, systemd, containers, networking, reverse proxies, self-hosted services
  • Infrastructure and delivery: Nix, Terraform, Kubernetes, Docker, GitHub Actions, GitLab CI/CD, Cloudflare
  • Observability: Prometheus, Grafana, Loki, metrics, logging, service monitoring
  • Security and configuration: SOPS, secrets management, OAuth 2.0, OpenID Connect, SAML2, Keycloak, eBPF
  • Reproducibility and supply chain: declarative configuration, pinned dependencies, reproducible and isolated builds, signed binary caches
  • Low-level background: RISC-V, Linux perf, hardware security, systems programming

See my CV →