Skip to content
View Salkimmich's full-sized avatar

Block or report Salkimmich

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
salkimmich/README.md

Hi, I'm Sal Kimmich

Security architect · Developer advocate · Open source community builder

I work at the intersection of AI infrastructure, digital sovereignty, and the communities that build on both. My career has been about one thing: translating complex systems into things engineers actually want to engage with. Open source projects, keynotes, curricula, writing, community programmes. I care deeply about who controls the infrastructure AI runs on, and I build tools and spaces to help engineers think clearly about that.

Right now I'm Technical Director at Gadfly AI LLC, working on AI governance tooling for high-stakes sectors. I helped found the OpenSSF AI/ML Working Group and I'm still actively mentoring a community of security engineers through OpenSSF.

My Github/Codeberg contributions were lower than usual in 2025 because I sat down and wrote Code, Chips and Control (Leanpub, 2025). It was worth the time, and it is worth the read.


🔧 What I'm Building

An open source analysis of tribal sovereignty posture with data, software and hardware attestation. It uniquely closes a gap between compliance documentation and operational reality because it was originally built for Pueblo and Tribal governments: where the stakes around data sovereignty, jurisdictional provenance, and attestation are higher than anywhere else in the regulatory landscape. That discipline now extends to engineers navigating the EU AI Act, DORA, NIS2, and beyond. The tool verifies that technical implementations actually satisfy their stated controls that anyone can use, and a version built for easy use by tribal community structures of consent and sovereignty.


🎤 Speaking

Keynotes

Panels & Talks


✍️ Writing


🌍 Community

  • Co-founder and contributor, OpenSSF AI/ML Working Group: helped establish the working group and continue contributing to Security Scorecard and AI Risk Management guidance
  • Co-Maintainer, CHAOSS Data Science Working Group: open source metrics for project health, sustainability, and security posture
  • OpenUK International Ambassador (2021 to 2025): co-authored AI for Public Good report delivered to the House of Lords
  • Community organiser: founded Nightmare Before Coding in London; currently building Immutable
  • Director, OurWorlds Inc.: cybersecurity and privacy governance for an extended-reality platform serving Indigenous communities

🎧 Podcasts & Media


🏆 Recognition

  • 2025: Top 100 Women in AI Ethics™
  • 2024: Security Woman of the Year, Security Excellence Awards (Shortlisted)
  • 2023: Most Innovative Tech Leader, Innovation in UK Business Awards
  • 2023: UK Top 50 Open Source Contributor, OpenUK + ARM Exhibition
  • 2020: CodeWorks Code Educator Award

🌱 Maintainer Mentorship

I mentor a small cohort of developers and early-career researchers working at the points and intersections of cybersecurity, high performance compute and open source goverance. If that sounds like you, reach out and tell me about the open source project you are building, who you are building it for, and why.


Connect

LinkedIn · salkimmich.com · HackerNoon


Before you go: a poem I come back to when I need reminding to build with both resilience and wonder. The Pragmatist's Guide to Magic.

Pinned Loading

  1. memorysafety memorysafety Public

    Resources to understand Memory Safety Across Languages

    1

  2. workload_identity workload_identity Public

    Notes on the basics of Workload Identity with SPIFFE and SPIRE

    Go 1

  3. temporal-security-scanner temporal-security-scanner Public

    Python

  4. chaoss/wg-data-science chaoss/wg-data-science Public

    CHAOSS Data Science Working Group: collaborate and improve open source project health using data science-based approaches

    Jupyter Notebook 28 25