I build AI systems and software tools end-to-end: multi-agent pipelines, LLM integrations, Python backends, REST APIs, and automation workflows. My background is in cybersecurity, which shapes how I think about reliability, failure modes, and systems that have to work unsupervised.
Finishing MSc in Information Technology at the University of Turku (Robotics and Autonomous Systems; multidisciplinary AI minor). Master's thesis planned in robotics and AI.
Portfolio code quality and security auditor built on RAG, LLM agents, and vector search. FastAPI backend with async Python, pgvector semantic search over 20,875 embeddings from 8 security books, LangGraph ReAct agent with custom tools, Pydantic validation, prompt-injection checks, and CI/CD via GitHub Actions. Evaluation suite with 15 OWASP and clean-code test cases (7/15 passing with diagnosable failures in progress).
4-agent LangGraph pipeline built for the AMD Developer Hackathon 2026. Converts MITRE ATT&CK techniques into Sigma detection rules, SOC response guidance, and validation scores. Public Hugging Face Spaces deploy (Docker, nginx); demo mode for reliability with a vLLM/ROCm inference path on AMD Instinct MI300X.
Multi-agent infrastructure audit system. A configuration agent inspects Terraform IaC for missing guardrails, a metrics agent analyzes operational data, and a supervision agent calls the Anthropic API to synthesize findings into an actionable audit report. Built with Python, Streamlit, and the Anthropic SDK.
Fully local voice assistant built from scratch. faster-Whisper for speech recognition, Ollama for LLM inference, Piper TTS for voice output, FastAPI web interface with browser microphone support. No cloud APIs. Supports custom fine-tuned models via Ollama Modelfiles.
FastAPI backend with SQLAlchemy, cursor-based sync, async httpx with retry/backoff, SSE live feed, input validation, and CI smoke tests on every push.
Paying client delivery; client identity remains private, repo published with permission. FastAPI + SQLite system linking work orders to pipe and material inventory. Tracks consumption, scrap, and reusable remnants with a full audit trail. Deployed on Linux with nginx and systemd. Includes authentication, CSRF protection, and a full handover package.
ShodanLookup · VirusTotal-Lookup · AbuseIPDBCheck · Windows-Security-Event-Log-lookup Lightweight extensions for IOC validation and infrastructure intelligence. Privacy-first, no data collection.
Bug-bounty-pocs - sanitized PoCs from web security research: CORS misconfigurations, OS command injection, cryptographic weaknesses.
- Agentic AI systems and multi-agent orchestration
- LLM integration and local inference pipelines
- Python backend development and REST APIs
- Security-aware software engineering
Website: ztothez.com LinkedIn: linkedin.com/in/roosayoruusu
Open to AI and software engineering roles.



