Let security fully blend into development and team culture.
Seek simple solutions for complex problems, for their power lies in easy application.
Empower customers, teams, and the community by sharing knowledge and tools.


With over 15 years of hands-on experience in application security, I help organizations build secure software through a combination of offensive testing, security training, and strategic consulting. Based in Cologne, Germany, I work with development teams and security professionals across Europe and beyond.
My work spans the full security lifecycle: I conduct thorough penetration tests of web applications, APIs, cloud environments, and container platforms — combining automated scanning with deep manual testing to find vulnerabilities that tools miss. Through my Web Security Bootcamp and Pentesting Training, I’ve trained thousands of developers and software engineers, emphasizing hands-on exercises from both attacker and defender perspectives. I also help organizations integrate security into their development pipelines through DevSecOps coaching and Agile Threat Modeling workshops.
I’m an active member of OWASP and the Chaos Computer Club (CCC). Eager to present security topics, I regularly speak and give open trainings on major national and international conferences.
A web-based tool for creating and analyzing attack trees, using a scenario-driven approach for top-down threat modeling.
Try it outAn open-source, agile threat modeling toolkit that generates risk reports from YAML-based architecture definitions.
Try it outA real-time collaboration platform I built to enhance interactivity in my security trainings and workshops.
Try it outAs a speaker with international conference experience (Black Hat Arsenal USA, DEF CON AppSec Village USA, RSA Conference USA, Oracle JavaOne, Black Hat Arsenal Europe, Black Hat Arsenal Asia, DeepSec, BruCON, OWASP AppSecEU, OWASP AppSec Days, DevOpsCon Berlin/Munich/London/Singapore, JAX, Heise DevSec, Heise Sec-IT, Heise Herbstcampus, RuhrSec, JCon, JavaLand, Internet Security Days, IT-Tage Frankfurt, OOP, and others) I’m definitely enjoying to speak, present keynotes, and train about IT-Security topics.
From time to time I write articles in IT-Security journals about topics like DevSecOps automation and vulnerability research. The most recent ones include:
As part of my security research I have found and reported security vulnerabilities, leading to over 30 CVE (the highest rated one with CVSS score 10.0) and a bug bounty payout from Google for identifying a vulnerability inside the Google Chrome browser.
Low-volume newsletter to announce new trainings, services, and conference talks (about six mails per year)