Skip to content
View josephManzambi's full-sized avatar

Block or report josephManzambi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
josephManzambi/README.md

Joseph Manzambi

AI & Cloud Security Architect. I founded and chair an enterprise AI Security Program, and I publish the methods I use as open frameworks. Agentic AI red-teaming paired with governance that maps to real standards. Malaga, Spain. EN / FR / ES.

What I work on

  • Agentic AI red-teaming: direct and indirect prompt injection, tool-use authorization, MCP security, IAM blast-radius scoping for agents, guardrail design (Garak, Promptfoo, PyRIT).
  • AI governance engineers can actually run: NIST AI RMF, ISO/IEC 42001, EU AI Act, CSA AICM, OWASP LLM and Agentic Top 10, MITRE ATLAS.
  • Cloud security at scale: multi-cloud (AWS, Azure, GCP), CNAPP, IAM at scale, landing zones, detection and incident response.

Open frameworks

  • The Model Trust Gate : "should we trust this model, for this use?" A 7-layer, fail-fast, auditable decision gate that composes NIST, ISO/IEC 42001, CSA AICM, OWASP, and MITRE ATLAS, and ends in a signed Model Trust Record.
  • EU AI Act Blueprint : 79 controls mapped across 6 frameworks, with a threat model and a live compliance tracker.
  • AI Red-Team Orchestrator : a fully-local, 3-layer red-team harness for LLMs and MCP servers (no cloud, no API keys).

Writing

Essays and deep-dives on AI security at manzambi.com/writing.

Reach me

manzambi.com · LinkedIn · joseph@manzambi.com

Popular repositories Loading

  1. eu-ai-act-blueprint eu-ai-act-blueprint Public

    A working technical blueprint for EU AI Act compliance — for Providers and Deployers. 79 controls mapped to 6 frameworks, threat model included.

    1

  2. ai-redteam-orchestrator ai-redteam-orchestrator Public

    Single-file, fully-local three-layer AI red-team smoke test for LLMs + MCP servers — honest, CI-ready, not a compliance tool.

    Python 1

  3. Secure-By-Design-Agentic Secure-By-Design-Agentic Public

    Educational project: build, secure, and red-team an AI agent with MCP tools — aligned with OWASP, NIST, and CSA frameworks

    Python

  4. model-trust-gate model-trust-gate Public

    A fail-fast, layered decision gate for deciding whether to trust an AI model for a specific use. A methodology that composes existing standards (NIST, ISO 42001, CSA AICM, OWASP, MITRE ATLAS) into …

    Python

  5. josephManzambi josephManzambi Public

    Profile