Profile

About me

I combine offensive security with many years of software development so that technical findings become realistic and implementable decisions.

I have a degree in computer science and work as a freelance offensive security consultant. I support management, IT managers, consultants and development teams in understanding real attack paths and sensibly prioritizing security measures.

What my experience means for your project

  • Long years of software development: Recommendations take architecture, code, release pressure and actual feasibility in the team into account.
  • Offensive security and own vulnerability research: I evaluate not just checklist items, but realistic attack chains, prerequisites and business impacts.
  • Security-sensitive projects: From the military environment, I am familiar with structured releases, clear communication and the responsible handling of sensitive information. My extended security check with security investigations (Ü3), completed in 2025, may be relevant for projects with special confidentiality requirements. The responsible authorities will clarify whether and to what extent it can be used for a specific application.
  • Bachelor of Laws (LL.B.): The legal background helps me to classify technical findings in the context of releases, data protection, governance and contractual framework conditions. This does not provide legal advice.
  • Specialist certifications: They demonstrate technical depth and continuous training. However, the project-specific analysis remains crucial.

Experience and qualifications

My goal is not only to secure companies and organizations through tests, but also to sustainably enable them to firmly integrate security into development, operational and corporate processes.

My three professional focuses:

  • Penetration testing for web applications and APIs: Check real attack routes and prioritize risks in a comprehensible manner
  • Secure development and security reviews: Threat modeling, focused code reviews and pragmatic security gates
  • Developer security training: Empower development teams based on real attack patterns and findings

I also bring in experience in vulnerability disclosure, bug bounty processes, reverse engineering and forensic analysis if it is relevant to the project.

Evidence before certifications

Five published vulnerabilities in JetBrains TeamCity document experience from in-depth analysis to responsible disclosure. These include path traversal, arbitrary file writing, stored cross-site scripting and the disclosure of sensitive backup content. The CVE write-ups and selected technical articles are publicly available.

A full synthetic sample report also shows how I translate technical findings into decisions and concrete actions. The most important certifications deliberately follow later; further evidence remains available for review.

Values and ways of working

  • responsible: no tests without permission
  • precise and realistic: focus on risks that really count
  • didactically strong: convey complex topics in an understandable way
  • in partnership: collaboration at eye level
  • Safety and ethics oriented

Track record

Certifications

The most important credentials are placed in their professional context. Logos link directly to the relevant validation pages or certificate records.

View additional certifications

Penetration Testing

Reverse Engineering & Malware

Operational Technology

Attack Simulation / Red Teaming

Additional Certifications