resume profile picture
Professional Experience
Penetration Tester, ETAS GmbH

Conducting penetration tests and reverse engineering on mobile/web apps, APIs, cloud environments, enterprise systems, and embedded devices for medium to large clients in the mobility sector. Involved throughout the entire process, including customer consultation, proposal preparation, project planning, assessment execution, detailed technical reporting, and providing remediation advice on both strategic and technical levels.

2022 – presentMunich, Germany

Performed manual source code audits in C, C++, Java/Kotlin, and JavaScript, with a focus on identifying vulnerabilities in security-critical components and recommending improvements. Expertise ranges from low-level authentication mechanisms in resource-constrained embedded systems to validation and quality-of-service (QoS) checks in protocol-rich application-layer systems with fundamentally different architectures and use cases.

As Mobile Security Topic Lead, I am responsible for advancing the mobile security testing service by developing and applying new testing methodologies. I ensure alignment with industry standards such as OWASP MSTG, conduct in-depth security assessments and reverse engineering. Test results and newly discovered techniques are contributed back to the OWASP MSTG, helping to improve and evolve the industry standard.

Topic lead for an internally developed Capture-the-Flag (CTF) workshop. Responsible for both strategic and technical development, including customer acquisition, planning, and hands-on delivery of workshops.

Working student Penetration Testing / Red Teaming, Siemens

Enhanced a password-cracking platform based on Hydra and John the Ripper with features like automatic hash identification, optimized configurations, intelligent wordlist/rule selection, result visualization, and performance improvements.

2020 – 2022Munich, Germany

Red teaming campaign for a critical infrastructure client, including the execution of a spear phishing operation to achieve initial compromise.

Working student Security Analysis, Siemens

For my bachelor's thesis, I worked on a device to simplify the forensic process of disk imaging for mobile devices. The goal was to convert an inexpensive and portable single-board computer into a performant and reliable forensic duplicator.

2019Munich, Germany
Internship and working student, MVI SOLVE-IT GmbH

Creating risk assessments and security concepts as Security Manager in Process (SMP) in the automotive context. Working as Software Developer mainly on Java backend components.

2017 – 2019Munich, Germany
Education
Master of Science, Technical University of Darmstadt
2019 – 2022Darmstadt, Germany
Bachelor of Science, HM Hochschule München University of Applied Sciences
2015 – 2019Munich, Germany
Skills
Mobile Security

Android and iOS with a focus on native app frameworks

Security Analysis

Reverse Engineering, Binary Analysis, Malware Analysis with JADX, Ghidra, Radare and Frida

Software development

Python, C++, C, Java/Kotlin, Go

Web Security

Backend, Cloud, Web App, API with BurpSuite, Bruno and more

Embedded Security

Hardware, IoT, Automotive

Security Audit

QNX, Linux, Cloud (Azure), Webserver

Certificates