Senior Systems Engineer — Rust, C++, storage and OS internals · Barcelona, remote (CET)
20+ years in C and C++, and for the last 8+ in production Rust. I work close to the machine: storage data paths and recovery, kernel and operating-system internals, and distributed systems where throughput and availability are the job rather than a nice-to-have.
I have written Linux device drivers from scratch, an SPDK bdev module for NVMe-oF, and block-level firmware for encrypted storage where power loss mid-write was the normal case and a partial write still had to leave something recoverable. I moved a production hot path from epoll to io_uring. Before that, a detection service in Rust handling millions of events per interval across fourteen regions.
PhD in Computer Science — algorithms, systems, applied cryptography. IACR-published.
🟢 Open to work — senior, staff or principal systems engineering. Remote, and I am in Spain.
- Languages: C/C++ (20+ yrs) · Rust (8+ yrs, production) · Go · Python
- Storage & OS: block layer and I/O paths · SPDK / NVMe-oF · Linux device
drivers · io_uring · correctness under power loss and partial writes ·
no_stdand bare metal - Distributed systems: sustained throughput over unreliable substrates · availability and fault tolerance · concurrency · Tokio and axum
- Debugging & measurement: gdb, perf, and reading somebody else's source to the bottom when the symptom does not explain itself
- Security: applied cryptography · digital signatures · PKI/HSM · reverse engineering · browser-security engineering (Chromium, C++)
- signalscreen-checker —
Authenticode signature checker in pure Rust, on
crates.io. Reads the signature
out of a PE file and grades it. Documents two defects the obvious
implementation shares: the signer certificate is chosen by
SignerInfo.sidand not by position, and timestamps come in two incompatible encodings. - pqc-embedded — what post-quantum
secure boot actually costs, in flash and RAM, measured on hardware. LMS/HSS
verification in
no_stdRust with no allocator, weighed against ML-DSA, FN-DSA, SLH-DSA, ECDSA and Ed25519 across four bare-metal targets and real silicon. Every number carries its provenance, and estimates are kept visibly separate from measurements. - relaysight — self-hosted VMS for camera fleets. Outbound-only edge gateway, ONVIF discovery, WebRTC live, fMP4 archive, HTTP plugins. (plugins · site)
- condition-control — Rust firmware on an M5StickC Plus2 that speaks to a Baxi/AUX air conditioner over Wi-Fi. Web UI, MQTT, Home Assistant.
- retina —
#137: some Dahua firmware
writes the same SSRC as hex in
Transportand decimal inRTP-Info, which killed a session that had set up cleanly. Found by pointing a gateway at real hardware for the first time. - capa-rs — Rust port of Mandiant's capability-detection engine (co-author)
- smda-rs — Rust recursive disassembler (co-author)
- dnfile-rs — .NET binary parser in Rust (co-author)
- Themis — cross-platform cryptographic library (C/C++/Go), built at Cossacklabs
HERMES — a cryptographically assured access-control and data-security framework, where storage and transport cannot read plaintext by construction · IACR ePrint 2018/200 · adopted by 20+ enterprises and audited in Fortune-100 environments.
- 3ig.dev · andrey@3ig.dev
- LinkedIn: linkedin.com/in/andrey-mn
I care about correctness, total functions over panics, and systems that stay legible — to the next engineer and to the AI agents I now build alongside every day.




