I build AI systems and software tools end-to-end: multi-agent pipelines, LLM integrations, Python backends, REST APIs, and automation workflows. I use AI coding tools by default and make their output prove itself with tests, evidence, and clear system boundaries. My background is in cybersecurity, which shapes how I think about reliability, failure modes, and systems that have to work unsupervised.
Finishing MSc in Information Technology at the University of Turku (Robotics and Autonomous Systems; multidisciplinary AI minor), expected 2027-2028. Master's thesis planned in robotics and AI. Based in Turku, Finland.
Open-source MCP server and deterministic quality gate for AI-built UI. Turns product intent, interface truth, information hierarchy, accessibility, and browser evidence into enforceable, evidence-backed contracts. 20 scoped MCP tools, automated repository audits, browser verification, and 168 automated tests.
Browser-based demoscene builder for beginners, designed and built solo in 20 hours. Onboarding, 21 learning paths, real-time effects, empty and error states, and offline export. TanStack Start, React 19, TypeScript, and Canvas API, no backend. 2nd place at the Assembly Summer 2026 Fix It Competition. Source is not public; see the live app on my website.
Portfolio code quality and security auditor built on RAG, LLM agents, and vector search. FastAPI backend with async Python, pgvector semantic search over 20,875 embeddings from 8 security books, LangGraph ReAct agent with custom tools, Pydantic validation, prompt-injection checks, and CI/CD via GitHub Actions. Evaluation suite with 15 OWASP and clean-code test cases (7/15 passing with diagnosable failures in progress).
4-agent LangGraph pipeline built for the AMD Developer Hackathon 2026. Converts MITRE ATT&CK techniques into Sigma detection rules, SOC response guidance, and validation scores. Public Hugging Face Spaces deploy (Docker, nginx); demo mode for reliability with a vLLM/ROCm inference path on AMD Instinct MI300X.
Paying client delivery; client identity remains private, repo published with permission. FastAPI system linking work orders to pipe and material inventory. Tracks consumption, scrap, and reusable remnants with a full audit trail. Deployed on Linux with nginx and systemd. Includes authentication, CSRF protection, and a full handover package.
Multi-agent infrastructure audit system. A configuration agent inspects Terraform IaC for missing guardrails, a metrics agent analyzes operational data, and a supervision agent calls the Anthropic API to synthesize findings into an actionable audit report. Built with Python, Streamlit, and the Anthropic SDK.
FastAPI backend with SQLAlchemy, cursor-based sync, async httpx with retry/backoff, SSE live feed, input validation, and CI smoke tests on every push.
Fully local voice assistant built from scratch. faster-Whisper for speech recognition, Ollama for LLM inference, Piper TTS for voice output, FastAPI web interface with browser microphone support. No cloud APIs. Supports custom fine-tuned models via Ollama Modelfiles.
ShodanLookup · VirusTotal-Lookup · AbuseIPDBCheck · Windows-Security-Event-Log-lookup Lightweight extensions for IOC validation and infrastructure intelligence. Privacy-first, no data collection.
Independent bug bounty researcher on HackerOne, Intigriti, and Bugcrowd (2018 to 2026). Bug-bounty-pocs contains sanitized PoCs from web security research: CORS misconfigurations, OS command injection, cryptographic weaknesses.
- Agentic AI systems and multi-agent orchestration
- AI-assisted development with verification: MCP tooling, evidence-gated quality, automated tests
- LLM integration and local inference pipelines
- Python backend development and REST APIs
- Security-aware software engineering
Website: ztothez.com LinkedIn: linkedin.com/in/roosayoruusu
Open to AI and software engineering roles.



