Facundo Tuesca

Security Engineer at trailofbits

Amsterdam, North Holland, Netherlands
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
Facundo Tuesca is a Security Engineer based in Amsterdam with 11 years of hands-on experience securing and automating back-end systems. He blends security engineering and DevOps practices, contributing to high-profile open-source projects like PyPI, Node.js, and the pyca/cryptography library—work that spans OIDC publisher integrations, dependency-vulnerability automation, and cryptographic primitive support. Comfortable across Python, Rust, and CI/CD automation, he’s implemented test vectors, hardened crypto backends, and automated dependency updates using GitHub Actions. Notably, his contributions include production-focused fixes such as case-insensitive path handling in OIDC flows and performance improvements for NVD vulnerability checks, reflecting a pragmatic focus on reliability and measurability.
code11 years of coding experience
github-logo-circle

Github Skills (38)

dependency-manager10
dependency-management10
javascript10
github-ci10
pytest10
python10
dependency-analysis10
vulnerability-scanners10
django10
testing10
it-security10
oid10
ch10
cicd10
security10

Programming languages (15)

PowerShellC#C++RustCGoHTMLJupyter Notebook

Github contributions (5)

github-logo-circle
nodejs/node

Jun 2022 - Dec 2022

Node.js JavaScript runtime ✨🐢🚀✨
Role in this project:
userBackend & DevOps Engineer
Contributions:8 reviews, 31 commits, 9 PRs in 5 months
Contributions summary:Facundo primarily contributed to the Node.js project by developing and implementing scripts for dependency vulnerability checking and automation. They added features to utilize API keys for the National Vulnerability Database (NVD) to improve script performance. Furthermore, the user automated dependency updates for libraries like base64, acorn, libuv, and OpenSSL using GitHub Actions, streamlining the project's maintenance. These contributions focus on security, automation, and dependency management within the Node.js ecosystem.
windowsnode-jsjavascriptlinuxruntime
pypi/warehouse

Jan 2024 - Feb 2025

The Python Package Index
Role in this project:
userBack-end Developer & DevOps Engineer
Contributions:124 reviews, 56 PRs, 212 comments in 1 year 1 month
Contributions summary:Facundo primarily worked on improving the functionality and maintainability of the Python Package Index (PyPI) warehouse project. They addressed documentation issues, particularly regarding build instructions and contributing patches. The user implemented GitLab OIDC trusted publisher functionalities, including adding associated tests and metrics. Further contributions include adding a task for purging expired OIDC macaroons and fixing case-insensitive project path comparisons within the GitLab OIDC implementation.
python-packagepythonpackage-indexindexpackage-registry
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial