The short version
I’m the person you bring in when a regulation — the CRA, ISO 21434, IEC 62443 — collides with a shipping deadline. The usual compliance auditors don’t understand your C/Rust stack; your developers don’t want to write a TARA. I sit in the gap between them.
That gap is where almost nobody lives: functional safety and offensive security, in the same head. I can facilitate a threat analysis in the morning and prove the exploit against the ECU it was supposed to protect in the afternoon. It’s an unusual combination, and it’s exactly what mid-size machine builders and Tier-1/Tier-2 suppliers need right now.
What I actually do
I act as the iron dome for engineering teams. I take the regulatory incoming and turn it into automated compliance architecture — docs-as-code traceability, TARA tooling, hardened product boundaries — so your engineers can stay focused on shipping deterministic code instead of drowning in Word documents.
- Functional safety + security. CMSE® and CEFS certified; Automotive SPICE (ASPICE) assessor; years of ISO 26262 and ISO 21434 series development. I speak SIL and CAL in the same sentence.
- Offensive depth. OSCP and OSWE. Fifteen years finding and exploiting critical flaws — from OS kernels and messaging apps to real-time communication stacks and embedded ECUs. I know what an attacker actually does, so my threat models aren’t theatre.
- Low-level engineering. C, C++, Rust, Assembly. I build the tooling — fuzzers, program analysis, TARA generators, zero-copy IPC — not just the reports.
- Industrial and automotive. CRA and IEC 62443 for connected machines; ISO 21434 and ASPICE for vehicle suppliers. Two regulated worlds, one advisor.
How I work
Simplicity is a security control. Complexity is the enemy — of safety, of security, and of any auditor trying to trust your system. I don’t hunt for intricate detail; I try to eliminate it. You can’t certify what you can’t understand.
I’m based in the Heilbronn-Franken region — the densest cluster of hidden-champion machine builders in Europe — and I work on-site, in German or English. For Mittelstand teams that are wary of remote or foreign consultants, that matters.
Background, briefly
- 15+ years writing, designing, securing and breaking software across automotive, industrial and mission-critical domains.
- Security assessments for German companies in finance, automotive and healthcare — embedded, infrastructure and application layers.
- 15+ years in open source, including contributions to widely used projects (Go, Docker, Hugo, MongoDB, Linux, Cobra).
- Built and led cross-functional engineering organisations.
Off the clock
Volleyball, mountain biking, and a bit of farming.
