About Me

I bridge functional safety and product security — the rare engineer who can run an ISO 21434 TARA in the morning and exploit the ECU it was meant to protect in the afternoon. I turn CRA, ISO 21434 and IEC 62443 into automated compliance architecture, so your engineers keep shipping.
About Me

The short version

I’m the person you bring in when a regulation — the CRA, ISO 21434, IEC 62443 — collides with a shipping deadline. The usual compliance auditors don’t understand your C/Rust stack; your developers don’t want to write a TARA. I sit in the gap between them.

That gap is where almost nobody lives: functional safety and offensive security, in the same head. I can facilitate a threat analysis in the morning and prove the exploit against the ECU it was supposed to protect in the afternoon. It’s an unusual combination, and it’s exactly what mid-size machine builders and Tier-1/Tier-2 suppliers need right now.

What I actually do

I act as the iron dome for engineering teams. I take the regulatory incoming and turn it into automated compliance architecture — docs-as-code traceability, TARA tooling, hardened product boundaries — so your engineers can stay focused on shipping deterministic code instead of drowning in Word documents.

  • Functional safety + security. CMSE® and CEFS certified; Automotive SPICE (ASPICE) assessor; years of ISO 26262 and ISO 21434 series development. I speak SIL and CAL in the same sentence.
  • Offensive depth. OSCP and OSWE. Fifteen years finding and exploiting critical flaws — from OS kernels and messaging apps to real-time communication stacks and embedded ECUs. I know what an attacker actually does, so my threat models aren’t theatre.
  • Low-level engineering. C, C++, Rust, Assembly. I build the tooling — fuzzers, program analysis, TARA generators, zero-copy IPC — not just the reports.
  • Industrial and automotive. CRA and IEC 62443 for connected machines; ISO 21434 and ASPICE for vehicle suppliers. Two regulated worlds, one advisor.

How I work

Simplicity is a security control. Complexity is the enemy — of safety, of security, and of any auditor trying to trust your system. I don’t hunt for intricate detail; I try to eliminate it. You can’t certify what you can’t understand.

I’m based in the Heilbronn-Franken region — the densest cluster of hidden-champion machine builders in Europe — and I work on-site, in German or English. For Mittelstand teams that are wary of remote or foreign consultants, that matters.

Background, briefly

  • 15+ years writing, designing, securing and breaking software across automotive, industrial and mission-critical domains.
  • Security assessments for German companies in finance, automotive and healthcare — embedded, infrastructure and application layers.
  • 15+ years in open source, including contributions to widely used projects (Go, Docker, Hugo, MongoDB, Linux, Cobra).
  • Built and led cross-functional engineering organisations.

Off the clock

Volleyball, mountain biking, and a bit of farming.