- Work across authorization, owner isolation, fail-closed behavior, token scoping, path confinement, model routing, OAuth, CI, and regression coverage.
- Review high-risk changes by reconstructing invariants across code, state, tests, persistence, and authorization boundaries; reproduce failures and probe the smallest safe fix.
- Build specifications and review tooling that make security-sensitive work evidence-bound, resumable, and safer to execute.
Systems / software / security
Rares P.
Systems-Oriented Software Engineer
Profile
Systems-oriented software engineer and open-source maintainer who turns ambiguous problems into operable systems. Work spans Python services, Linux hosts, rootless containers, application security, applied AI, desktop software, and games. Default rhythm: spike iterate stabilize.
Experience
- Build and release cross-platform desktop, ML, local-agent, native C, and Godot projects from rough prototype through tests, specifications, automation, and public artifacts.
- Operate supporting Linux hosts, rootless Podman workboxes, SSH/Tailscale access, systemd recovery, cloud GPU experiments, and release flows.
Selected projects
Review Ops
Python · Podman · Git · securityPrivate resumable review harness: pinned Git ranges, hashed evidence, hostile-input handling, bounded subprocesses, secretless offline probes, and human-controlled publication.
Cross-platform meeting, playback, transcript, and AI chat application with persistent configuration, component previews, smoke tests, and tagged releases.
Dataset generation and validation, model training, top-k and legality metrics, inference, local play, and RunPod/Vast lifecycle orchestration.
Playable indie game taken from unusual premise to working core loop, cross-platform builds, public devlogs, and a browser release.