Jose Lopez

Jose Lopez

I build AI systems that survive contact with production.


now

I am Head of AI at bunny.net, where I work on AI for edge infrastructure.

I like the part after the demo: identity, isolation, evaluation, observability and the boring decisions that let a system keep working when the model changes.

bio

I have been building software for twenty-five years, the last decade in machine learning, cybersecurity and large-scale infrastructure.

I started orchestrating agents in production at IriusRisk, where my team shipped a multi-agent simulation platform for secure-by-design engineering. Before that I built ML systems serving billions of predictions a day, led a company working on critical infrastructure, and founded a mobile software company.

where I have been

2025 →
bunny.net · Head of AIAI strategy, platform and security-by-design for edge infrastructure.
2024–25
IriusRisk · Head of AIBuilt the AI team and platform from zero; shipped Jeff, Bex and ASH inside the product.
2023
DTEK.ai · Head of AIVision-based automation and generative AI for retail.
2017–23
Mimecast · Big Data Specialist → Principal ML EngineerML infrastructure across ten services, computer vision and LLM-based phishing categorization.
2014–17
Zed · Lead ML / Big Data ArchitectDistributed graph engine processing billions of nodes and EU-funded graph ML research.
2013–14
ELIMCO Sistemas · CEOLed 150+ professionals in defense and critical infrastructure, including work with Lockheed Martin on the AEGIS combat system.
2011–13
MightyGate · Founder & CEO12+ mobile apps, 850K+ downloads, seed capital and a profitable exit.
2000–11
EarlierSoftware architecture and project management for government, telecom and industrial systems.

things I have built

The company systems below are in production now or have been in production.

Governed AI platform · bunny.net

One path for AI calls: multi-provider LLM routing, streaming, usage and cost control, PII detection and redaction, audit logging, guardrails and prompt-injection resilience.

Multi-agent engineering workspace · for development

A production workspace for coordinated agents with scheduled loops, persistent file-based memory, inter-agent messaging, receipts and human gates.

Jeff · threat-modeling agent · IriusRisk

Guided threat modeling inside the product, reducing onboarding from hours to minutes, around 90%.

ASH · secure-by-design attack simulation · IriusRisk

A digital-twin, multi-agent framework for simulating attacks and finding issues before development.

Multimodal retail assistant · DTEK.ai

A vision-language system for checkout and in-store flow automation, combining computer vision with a custom AI assistant.

NSFW detection · Mimecast

Computer-vision models trained from scratch to detect nudity and violence in images and run in production.

Brand and logo detection · Mimecast

Visual detection and classification of brands and logos in images for security and content analysis.

ML inference infrastructure · Mimecast

Production ML services handling more than 250 million predictions per day per service, with observability, latency and cost controls.

Synthetic data and model evaluation · Mimecast

Evaluation datasets and testing frameworks for drift and hard negatives, with model cards, automated benchmarks and audit trails.

Phishing email generation and categorisation · Mimecast

Large-scale email-generation frameworks using advanced language models to improve phishing categorisation.

Distributed graph engine · Zed Worldwide

A graph-processing engine built with Spark and MapReduce, capable of handling billions of nodes.

Social Baton · viral message system · Zed Worldwide

A marketing ML application that orchestrated artificial worldwide Twitter trending topics using graph-based algorithms.

AEGIS combat-system integration · ELIMCO

AEGIS combat-system integration with Lockheed Martin for the Spanish F-105 frigate.

Critical-infrastructure software · ELIMCO

Software for critical infrastructure, including a natural-gas plant, alongside defense and industrial programs.

Open source

Threat-modeling toolkit

Independent AI-powered threat modeling for Claude Code, with STRIDE, PASTA, compliance mapping and security verification.

Workspace for agents

A small environment for multi-agent teams: isolated workspaces, scheduled loops, memory and receipts.

writing

I write Disrupted AI, on secure and auditable enterprise LLM systems.

press & talks

misc

I live on the Spanish coast and work from there. The commute is excellent.

I would rather ship a boring system that stays up than a clever one that needs me awake.

If you are building something where AI has to be safe, useful and operational, we can talk.