Skip to content
View Sebasalazaro's full-sized avatar
:octocat:
Per Aspera Ad Astra
:octocat:
Per Aspera Ad Astra

Highlights

  • Pro

Block or report Sebasalazaro

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Sebasalazaro/README.md
SHIKI
hacking gif

reach me →      


> whoami

shiki = {
    "role":     "Web Application Security Engineer @ Exfil Security (US · Remote)",
    "focus":    ["Web & API Pentesting", "AI-Powered Systems", "Full-Stack Dev"],
    "origin":   "Colombia 🇨🇴",
    "mindset":  "I know how it's built. That's why I know how it breaks.",
    "off-duty": ["Anime", "Medieval fantasy", "Gacha Gaming"],
    "crafts":   ["Clean UIs that actually feel good to use", "Systems that scale", "Code that doesn't embarrass me"],
}

I'm a security engineer with a developer's brain — and a designer's eye. Before moving into AppSec, I designed and shipped full-stack cloud-native applications end-to-end: architecture, backend, frontend, AWS deployment, the whole thing. That background is what makes my pentesting different: I don't just find the cracks, I understand exactly why they exist.

Currently performing enterprise web application security assessments — testing authentication flows, authorization logic, complex API chains, and cloud-native architectures across modern web stacks.

When I'm not breaking things, I'm building them. AI-powered systems, 3D web experiences, polished UIs. I care about how things look and feel as much as how they work.


> skills

🔐 Security

Core tooling

Burp Suite OWASP JWT eJPT

Web application & API pentesting · Authentication & authorization bypass · Business logic testing · Vulnerability chaining · Manual request manipulation · Thick-client testing (training) · Developer-friendly report writing · Syft/Grype (SBOM/CVE scanning) · Prompt injection & jailbreak detection

💻 Languages

⚙️ Backend

🎨 Frontend

Also using

GSAP Framer Motion

React Three Fiber · shadcn/ui · HeroUI

🗄️ Databases

Also using

BigQuery

☁️ Cloud & Infrastructure

Also using

Helm

ECS/Fargate · EKS · EC2 · S3 · Lambda · CloudWatch · IAM · VPC · EMR · KMS · Cloud Run · Cloud Build · Cloud Storage

🧠 AI & ML

Also using

LangChain OpenAI Anthropic Apache Spark spaCy

LangGraph · LlamaIndex · Pinecone · RAG pipelines · LSTM networks · SARIMAX · Fuzzy logic (skfuzzy) · Presidio

📊 Observability

Also using

OpenSearch

Loki · structlog

📡 Networking & Protocols

TCP/IP · MQTT · Berkeley Sockets API · RIPv2 · OSPF · PAT/NAT · VLSM · Cisco Packet Tracer

🛠️ DevOps & CI/CD

Docker Compose

🔧 Dev Tools

Also using

GitHub Copilot Swagger pytest Claude Code


> projects

🔒 Sentinel — Vulnerability Scanning Platform

A security-focused scanning platform built to detect and surface web application vulnerabilities. Designed with an AppSec-first mindset after hands-on pentesting experience with real enterprise targets.

Tech Stack: Python FastAPI Security Tooling

View Code

⚔️ DnD-AI — AI Dungeon Master (Premios Inventiva Winner!)

Over 10 million D&D sessions fail to happen each year because there's no Dungeon Master. DnD-AI replaces the DM with an AI that generates the story, enemies, and map in real time.

  • 🗺️ Real-time map visualization
  • 🎨 AI-generated scene imagery (OpenAI / HuggingFace)
  • 🧠 Natural language action interpretation via Google Gemini
  • ⚔️ Full game loop: characters, combat, inventory, campaigns

Tech Stack: Django Python Gemini API OpenAI API LangChain

View Code

🏗️ Poneglyph Reduce — Distributed MapReduce System

A Hadoop/Spark-inspired MapReduce system built from scratch across three heterogeneous languages. One Piece-themed architecture: Road-Poneglyph (Master · Java), Poneglyph (Workers · C++), Clover (Client · Python).

  • 📡 gRPC for Master ↔ Worker communication
  • 🔀 Full shuffle/partition pipeline with hash-based key routing
  • 📊 Real-time React dashboard with MQTT telemetry
  • 🔧 Fault tolerance: task timeouts, worker heartbeats, automatic re-queuing
  • 💾 Redis state persistence
  • 🐳 Full Docker Compose cluster

Tech Stack: Java C++ Python React TypeScript gRPC MQTT Redis Docker

View Code

🌍 3D Real Estate Platform

Immersive real estate exploration using 3D environments. Users can navigate and interact with properties through a rich visual experience, built with Three.js and Next.js.

Tech Stack: Three.js Next.js React GSAP

View Code

📰 Fake News Detection Pipeline

Distributed real-time fake news classification using streaming data infrastructure. Ingests articles via Kafka, processes with Spark, and indexes results into OpenSearch.

Tech Stack: Apache Kafka Apache Spark OpenSearch Python MLOps

View Code

🤖 More Projects
Project Stack Description
AI Travel Planner Python · FastAPI · LLM AI-powered itinerary generation
Parking Forecasting skforecast · GitHub Actions Time-series demand prediction with CI/CD
MLOps Iris Pipeline FastAPI · GCP · sklearn End-to-end ML pipeline on Google Cloud
E-commerce (Moto Detailing) NestJS · Next.js · PlaceToPay Full store with payment gateway
BIM Project Management Full-Stack System for electrical engineering firms
MQTT Broker from Scratch C Custom protocol implementation
WhatsApp/Messenger Chatbots Python · APIs Automated customer conversation flows

> stats

visitor counter

> contact

💼 LinkedIn sebastian-salazar-osorio
📫 Email sebasalazaro@gmail.com
🌎 Location Colombia · Open to Remote

"Security is about understanding systems — sometimes you need to explore the dungeon to find the flaw in the castle walls."

Pinned Loading

  1. SaSa SaSa Public

    🌱 Fight food waste, save money, help communities — A full-stack marketplace connecting businesses with surplus food to conscious consumers and charitable organizations

    JavaScript 1

  2. QuitoTactico/DnD-AI QuitoTactico/DnD-AI Public

    Project for the Integrated Project 1 course at EAFIT. Dungeons & Dragons game generator

    Python 22 4

  3. Youngermaster/Poneglyph-Reduce Youngermaster/Poneglyph-Reduce Public

    A minimal-yet-real MapReduce system inspired by Hadoop/Spark and designed to satisfy the GridMR assignment requirements

    Java 2

  4. Youngermaster/Weatheria Youngermaster/Weatheria Public

    A Hadoop MapReduce System for Medellín Temperature Analysis (2022-2024)

    Shell 2

  5. FakeNewsDetection FakeNewsDetection Public

    Real-time fake news detection using ML and streaming from Bluesky with Kafka, Spark, and OpenSearch

    Python 1