Profile
About me
I combine offensive security with many years of software development so that technical findings become realistic and implementable decisions.
I have a degree in computer science and work as a freelance offensive security consultant. I support management, IT managers, consultants and development teams in understanding real attack paths and sensibly prioritizing security measures.
What my experience means for your project
- Long years of software development: Recommendations take architecture, code, release pressure and actual feasibility in the team into account.
- Offensive security and own vulnerability research: I evaluate not just checklist items, but realistic attack chains, prerequisites and business impacts.
- Security-sensitive projects: From the military environment, I am familiar with structured releases, clear communication and the responsible handling of sensitive information. My extended security check with security investigations (Ü3), completed in 2025, may be relevant for projects with special confidentiality requirements. The responsible authorities will clarify whether and to what extent it can be used for a specific application.
- Bachelor of Laws (LL.B.): The legal background helps me to classify technical findings in the context of releases, data protection, governance and contractual framework conditions. This does not provide legal advice.
- Specialist certifications: They demonstrate technical depth and continuous training. However, the project-specific analysis remains crucial.
Experience and qualifications
My goal is not only to secure companies and organizations through tests, but also to sustainably enable them to firmly integrate security into development, operational and corporate processes.
My three professional focuses:
- Penetration testing for web applications and APIs: Check real attack routes and prioritize risks in a comprehensible manner
- Secure development and security reviews: Threat modeling, focused code reviews and pragmatic security gates
- Developer security training: Empower development teams based on real attack patterns and findings
I also bring in experience in vulnerability disclosure, bug bounty processes, reverse engineering and forensic analysis if it is relevant to the project.
Evidence before certifications
Five published vulnerabilities in JetBrains TeamCity document experience from in-depth analysis to responsible disclosure. These include path traversal, arbitrary file writing, stored cross-site scripting and the disclosure of sensitive backup content. The CVE write-ups and selected technical articles are publicly available.
A full synthetic sample report also shows how I translate technical findings into decisions and concrete actions. The most important certifications deliberately follow later; further evidence remains available for review.
Values and ways of working
- responsible: no tests without permission
- precise and realistic: focus on risks that really count
- didactically strong: convey complex topics in an understandable way
- in partnership: collaboration at eye level
- Safety and ethics oriented
Track record
Certifications
The most important credentials are placed in their professional context. Logos link directly to the relevant validation pages or certificate records.
Selected certifications
OSCE³
OffSec Certified Expert
Advanced expertise in web security, exploit development and penetration testing.
OSWE
OffSec Web Expert
Relevant to in-depth web and API assessments, authentication logic and complex vulnerabilities.
OSEP
OffSec Experienced Penetration Tester
Relevant to realistic attack chains, evasion techniques and complex assessments.View additional certifications
Penetration Testing
OSCP
OffSec Certified Professional
A broad practical foundation for penetration testing in networks and system environments.
GWAPT
GIAC Web Application Penetration Tester
Relevant to structured assessments of modern web applications and common vulnerability classes.
GPEN
GIAC Penetration Tester
Demonstrates a methodical approach to penetration testing and reporting.
GMOB
GIAC Mobile Device Security Analyst
Relevant to mobile applications, device platforms and mobile attack surfaces.
OSWP
OffSec Wireless Professional
Additional expertise for wireless security assessments and attack surfaces.
OSED
OffSec Exploit Developer
Relevant to exploit development and the technical assessment of complex vulnerabilities.
GXPN
GIAC Exploit Researcher and Advanced Penetration Tester
Advanced expertise in exploit research, penetration testing and technical attack chains.Reverse Engineering & Malware
Forensics & Incident-Related Expertise
Operational Technology
Attack Simulation / Red Teaming
Additional Certifications
GPYC
GIAC Python Coder
Supports technical automation, tooling and reproducible analysis.
HTB CWES
Hack The Box Certified Web Exploitation Specialist
Additional practical evidence for web exploitation and modern vulnerability classes.
CompTIA PenTest+
Broad methodological evidence for planning, delivering and documenting penetration tests.
CPSA-F
Certified Professional for Software Architecture – Foundation Level
Relevant to architecture discussions, technical decision paths and secure system design.
ITIL v3 Certificate
Supports alignment with operational processes, service management and organisational interfaces.