Rafael Tinoco is an experienced open-source software engineer with a deep focus on Linux internals, runtime security and eBPF, blending over two decades of systems work with 11 years in senior engineering roles. He helped shape core projects like Aqua Security’s Tracee and the libbpfgo ecosystem, and currently leads development of Jibril, a query-driven eBPF runtime-security tool designed for low overhead at scale. Rafael’s background spans kernel debugging, virtualization, storage and performance tuning from roles at Canonical, IBM, Linaro and Sun, giving him a rare combination of production troubleshooting and upstream kernel patchcraft. He’s comfortable across the stack—from writing C/eBPF probes and Go bindings to packaging and distribution for Ubuntu—and has repeatedly optimized event processing and protocol capture for high-throughput environments. Based in Ramat Gan, Israel, he pairs pragmatic engineering with open-source stewardship, often surfacing subtle kernel-level fixes that prevent large-scale regressions. Beyond coding, Rafael’s physics and business studies hint at a methodical, data-driven approach to solving complex operational problems.
11 years of coding experience
21 years of employment as a software developer
Bachelor's degree, Business Administration, Bachelor's degree, Business Administration at COC Ribeirão Preto/SP
Bachelor's degree, Physics, Bachelor's degree, Physics at USP - Universidade de São Paulo
Contributions:3 releases, 237 reviews, 56 commits in 1 year 4 months
Contributions summary:Rafael primarily focused on adding and modifying eBPF (Extended Berkeley Packet Filter) examples for the `libbpfgo` library, specifically related to probing kernel functions. Their work included the implementation of a TCP connect example, including both C and Go implementations, showcasing how to use `libbpfgo` (or `libbpf`) to probe kernel functions and retrieve data. They also contributed to the library by adding support for external BTF files and running lint tools and fixing related issues. Additionally, the user added initial BTF information and refactored the OSInfo to improve the API.
Contributions:1 release, 1997 reviews, 302 commits in 1 year 5 months
Contributions summary:Rafael's primary contribution involved enhancing the security and functionality of the tracee-ebpf project. They implemented and modified eBPF code to improve network traffic capture, including support for various protocols like ICMP and DNS. They also focused on improving the performance and efficiency of the code by optimizing event processing and addressing compilation warnings.
ebpflinuxsecuritybpfgolang
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.