close
Skip to content

Latest commit

 

History

18 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

Ciao, I'm Marco 👋

Cloud Platform & AI Security Engineer
I make production AI systems secure, and the cloud platforms they run on resilient.

Website LinkedIn Credly Email Open to work


💻 $ whoami

Cloud Platform & AI Security Engineer. My clients already run a live system they can't afford to stop, and most of them have shipped an AI feature into it that nobody has threat modeled yet.

  • 🔭 Proof of work: marcobellingeri.dev audits itself. The Security section reads its own response headers back out of the live response, the A+ links to a Mozilla Observatory scan anyone can re-run, and every merge to main deploys through CI.
  • 🤖 AI security is what I do most days: OWASP LLM Top 10 applied to production RAG systems, prompt injection defense for external content flows, LLM-as-a-judge evaluation gates in CI, EU AI Act art. 50 transparency requirements, and MITRE ATLAS as a threat modeling reference.
  • 🔐 Every deploy ships a CycloneDX SBOM and a keyless OIDC provenance attestation. Dependencies are pinned by SHA, zizmor reads the workflows, gitleaks reads the whole history.
  • 🖥️ There's a hidden CRT terminal on the site. ⌘K is one way in. There's another.

📅 Book 30 minutes: free, no commitment


🛠️ Tech Stack

Python FastAPI Astro TypeScript

Claude API Model Context Protocol RAG with pgvector Langfuse

OWASP LLM Top 10 Sigstore CycloneDX SBOM CodeQL

AWS Cloudflare Docker GitHub Actions

PostgreSQL and PostGIS Supabase Redis MongoDB

OpenTelemetry Prometheus Grafana Sentry Linux


📦 Things I've built

llm-council agentic-os marcobellingeri.dev TorinoParking

🌐 Live right now: marcobellingeri.dev vetreriamonferrina.com
running on infrastructure I operate myself


📊 Activity

Contribution graph

GitHub streak


📜 Certifications

Ten of them, the same ten the site shows and in the same order. They reinforce the same direction: AI security, secure software supply chain, and cloud security practices.

Certification Issuer
AI Security & Governance Securiti Education · 2026 verify
Foundations of AI Security AttackIQ Academy · 2026 verify
Secure AI/ML-Driven Software Development OpenSSF · Linux Foundation · 2026 verify
Securing Your Software Supply Chain with Sigstore Linux Foundation · 2026 verify
Automating Supply Chain Security: SBOMs & Signatures OpenSSF · Linux Foundation · 2026 verify
Understanding the EU Cyber Resilience Act (CRA) OpenSSF · Linux Foundation · 2026 verify
Introduction to Zero Trust Linux Foundation · 2026 verify
Anthropic Academy Anthropic · 15 courses · 2026
AI, RAG & Security MongoDB · 8 courses · 2026 verify
GitHub Foundations GitHub · 2025 verify

The other 35 are on Credly. Badges you can click are worth more than badges you can claim.


guest@bellingeri:~$ exit
© Marco Bellingeri, tutti i diritti e nessun bug in produzione (si spera).

About

👋 Marco Bellingeri · Cloud Platform & AI Security Engineer · Python · FastAPI · Claude API & MCP · OWASP LLM Top 10 · signed supply chain · AWS · Cloudflare

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors