AI & Cloud Security Architect. I founded and chair an enterprise AI Security Program, and I publish the methods I use as open frameworks. Agentic AI red-teaming paired with governance that maps to real standards. Malaga, Spain. EN / FR / ES.
- Agentic AI red-teaming: direct and indirect prompt injection, tool-use authorization, MCP security, IAM blast-radius scoping for agents, guardrail design (Garak, Promptfoo, PyRIT).
- AI governance engineers can actually run: NIST AI RMF, ISO/IEC 42001, EU AI Act, CSA AICM, OWASP LLM and Agentic Top 10, MITRE ATLAS.
- Cloud security at scale: multi-cloud (AWS, Azure, GCP), CNAPP, IAM at scale, landing zones, detection and incident response.
- The Model Trust Gate : "should we trust this model, for this use?" A 7-layer, fail-fast, auditable decision gate that composes NIST, ISO/IEC 42001, CSA AICM, OWASP, and MITRE ATLAS, and ends in a signed Model Trust Record.
- EU AI Act Blueprint : 79 controls mapped across 6 frameworks, with a threat model and a live compliance tracker.
- AI Red-Team Orchestrator : a fully-local, 3-layer red-team harness for LLMs and MCP servers (no cloud, no API keys).
Essays and deep-dives on AI security at manzambi.com/writing.
manzambi.com · LinkedIn · joseph@manzambi.com



