About
Hi, I'm Fernando Guisso.
I'm a Security Software Engineer at willbank where I lead the AppSec practice and its internal authentication platform.
I build solutions that make security a natural part of the developer workflow—helping engineers ship safely without losing speed. The best security is the one that ships with the code.
In my spare time I obsess over my home lab: explore experiments tagged home-lab or dive into the gritty details on my wiki.
featured projects
Projects I'm building right now
- Project
sfer.nvim
Lightweight Neovim plugin that displays SARIF files, perfect for CodeQL runs and my daily AppSec tooling.
open ↗ - Project
Dojo Shield
Hands-on exercise to train secure development through guided missions with real-time feedback.
open ↗ - Project
Home Lab
My home infrastructure running AppSec pipelines, ZFS storage, Kubernetes, and automations—full notes live on the wiki.
open ↗
new articles
Here's what I'm writing lately
-
OWASP Top 10 Update
Top 10:2025 is not just a list. It reflects how misconfigurations, supply chain, exception handling, and operational failures are breaking real businesses.
1,896 words · 9 min
Creative ler artigo ↗ -
Cmd+K for the IA Terminal
How to bring Cursor-style Cmd+K to any shell using an AI CLI as a suggester only.
937 words · 5 min
Idea ler artigo ↗ -
Open source site analytics
What I learned from self-hosting Tianji: PV/UV without cookies, campaigns, and reliability lessons.
1,113 words · 6 min
Lifestyle ler artigo ↗