Experience

Track record

I work discreetly. That is why I present verifiable areas of experience instead of confidential customer names.

Selected evidence of experience

The following evidence is publicly verifiable. Confidential customer projects, systems and findings remain protected.

Published TeamCity CVEs

These vulnerabilities demonstrate not only tool knowledge, but the entire chain from analysis and reproduction to impact assessment and responsible disclosure.

Public bug bounty track record

These public postings demonstrate practical experience with real-world applications, reproducible reporting, and coordinated disclosure. Experiences from private programs are incorporated into my work, but are neither mentioned as customer references nor published with confidential details.

Technical publications

For more technical posts and CVE write-ups, see the blog. As a publicly verifiable open-source project, I develop and maintain htb-operator, a Python command-line tool for automating workflows on Hack The Box.

Example of an actionable deliverable

The full synthetic sample report shows how I structure overall risk, technical findings and subsequent decisions. It does not contain customer, contact or production data.

Typical areas of responsibility

Security assessments for digital products

I test web applications and APIs with understandable risk classification and prioritized recommendations for management, IT management and development.

Secure development and security reviews

I support teams in architectural decisions, threat modeling, code reviews and the integration of meaningful security checks into development processes.

Developer security training

I conduct practical security training for development teams. Using real attack patterns and findings, teams learn to identify risks earlier and deal with them effectively in everyday development.