Secure Coding · DevSecOps · AppSec · Cloud Security · Automation
I am a final-year IT specialist for application development (Fachinformatiker Anwendungsentwicklung) specializing in Secure Coding & DevSecOps.
My strong programming foundation allows me to understand how applications and APIs are built from the inside out. I apply this knowledge to build secure-by-design systems and integrate automated security gates directly into the development cycle (Shift Left).
I am a self-driven, independent learner who loves building practical labs, hardening systems, and mastering cloud infrastructure.
A realistic overview of my technical stack as a junior developer:
I am actively expanding my skillset at the intersection of software development and IT security:
- Fundamentals & Operations: Linux CLI, Git, Shell Scripting, secure networking concepts.
- Secure Backend Development: Building robust APIs with Python & FastAPI, input validation (Pydantic), and database security (PostgreSQL).
- Web Application Security: Deep dive into the OWASP Top 10 using the PortSwigger Web Security Academy (business logic flaws, JWT, API security).
- Infrastructure & Container Hardening: Containerized deployments via Docker, host hardening (SSH, UFW, fail2ban), and Infrastructure-as-Code (IaC) with Terraform.
- DevSecOps & Automation: Automating security gates in pipelines (Shift Left via GitHub Actions, Semgrep, Trivy, GitLeaks, pip-audit) and monitoring with Prometheus & Grafana.
- Cloud Security & Identity: Microsoft Azure fundamentals, identity management (IAM) and role-based access control (RBAC) via Microsoft Entra ID.
- Emerging Tech (AI Security): Hardening AI interfaces and securing LLM applications (OWASP Top 10 for LLMs, Prompt Injection, Secure AI Gateway).
A series of local-first web applications designed to help apprentices prepare for their IHK examinations (AP1, AP2 FIAE, AP2 FISI). Over 2900 flashcards, running entirely offline with LocalStorage and zero user tracking.
- Stack: HTML5 · CSS3 · Vanilla JavaScript · Tailwind CSS · LocalStorage
- Web-Apps: AP1 Tracker | AP2 FIAE Tracker | AP2 FISI Tracker
- Repositories: ap1-tracker | ap2-tracker | ap2-fisi-tracker
A secure REST API designed to showcase backend hardening and defensive coding practices.
- JWT Authentication, bcrypt password hashing, Pydantic input validation, and rate limiting.
- Automated API testing with Pytest and secure Docker deployment.
- Stack: Python · FastAPI · PostgreSQL · Docker · Pytest
- Status: 🔄 In Progress
My capstone project: A secure proxy gateway for Large Language Models (LLMs) to mitigate modern security risks.
- Prompt injection protection, PII data filtering, rate limiting (Redis), and encrypted audit logs.
- CI/CD deployment with GitHub Actions and SAST/SCA security scans.
- Stack: Python · FastAPI · Redis · PostgreSQL · Docker · GitHub Actions
- Status: ⏳ Planned Capstone
- ISC² Certified in Cybersecurity (CC) (Optional / Planned)
- Microsoft Security Fundamentals (SC-900) (Planned)
I am aiming to step into roles that combine software engineering with modern security practices:
- Secure Software Developer (Python / Backend)
- Junior DevSecOps Engineer (CI/CD, Automation)
- Junior Application Security (AppSec) Specialist
- Junior Cloud Security Specialist



