About
I’m Giovanni, a security engineer interested in backend, platform, and infrastructure engineering, with a focus on Linux, automation, and reproducible systems.
I build backend services, APIs, development environments, deployment workflows, and declarative infrastructure. I like applying an Everything as Code approach to infrastructure, system and application configuration, CI/CD pipelines, policies, and development environments, keeping them versioned, reviewable, and reproducible.
I use Nix and NixOS across development environments, system configuration, deployments, and self-hosted infrastructure, with a particular interest in declarative configuration and functional programming.
I also have a background in RISC-V, hardware security, systems programming, and Linux performance analysis, developed through academic and research projects.
Background Link to heading
- MSc in Cybersecurity Engineering, 110/110 cum laude, from Politecnico di Torino, March 2026 — thesis on a reproducible design and verification workflow for integrating a TRNG into a RISC-V SoC
- Research Assistant at the SMILIES research group, DAUIN, Politecnico di Torino, November 2024–December 2025 — development of a Linux kernel module exposing custom RISC-V performance counters through
perffor a CPU simulated with gem5 - BSc in Computer Engineering from Politecnico di Torino, March 2023
- Full Stack Developer at Casamorana, March 2020–March 2023 — backend and frontend development for an e-commerce platform, including payment integration, data protection, and performance optimization
What I work with Link to heading
- Languages: C, C#, Rust, Python, Go, Java, Nix, Bash, SQL
- Backend: ASP.NET Core, Django, REST APIs, PostgreSQL, authentication and authorization
- Systems and platform: Linux, NixOS, systemd, containers, networking, reverse proxies, self-hosted services
- Infrastructure and delivery: Nix, Terraform, Kubernetes, Docker, GitHub Actions, GitLab CI/CD, Cloudflare
- Observability: Prometheus, Grafana, Loki, metrics, logging, service monitoring
- Security and configuration: SOPS, secrets management, OAuth 2.0, OpenID Connect, SAML2, Keycloak, eBPF
- Reproducibility and supply chain: declarative configuration, pinned dependencies, reproducible and isolated builds, signed binary caches
- Low-level background: RISC-V, Linux
perf, hardware security, systems programming