Skip to content
View cwillam's full-sized avatar

Block or report cwillam

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cwillam/README.md

Hi, I'm Christoph 👋

Final-Year FIAE | Secure Developer & DevSecOps Engineer

Secure Coding · DevSecOps · AppSec · Cloud Security · Automation

LinkedIn XING TryHackMe Email


👨‍💻 About Me

I am a final-year IT specialist for application development (Fachinformatiker Anwendungsentwicklung) specializing in Secure Coding & DevSecOps.

My strong programming foundation allows me to understand how applications and APIs are built from the inside out. I apply this knowledge to build secure-by-design systems and integrate automated security gates directly into the development cycle (Shift Left).

I am a self-driven, independent learner who loves building practical labs, hardening systems, and mastering cloud infrastructure.


🛠️ Tech Stack & Focus

A realistic overview of my technical stack as a junior developer:

🐍 Core Developer Stack

Python Bash Git Linux

🌐 Web Technologies (for my Exam Prep Trackers)

HTML5 CSS3 JavaScript

🛡️ Actively Learning & DevOps Focus

Docker FastAPI PostgreSQL GitHub Actions PortSwigger Academy TryHackMe Labs


🎯 DevSecOps & Secure Coding Learning Path

I am actively expanding my skillset at the intersection of software development and IT security:

  • Fundamentals & Operations: Linux CLI, Git, Shell Scripting, secure networking concepts.
  • Secure Backend Development: Building robust APIs with Python & FastAPI, input validation (Pydantic), and database security (PostgreSQL).
  • Web Application Security: Deep dive into the OWASP Top 10 using the PortSwigger Web Security Academy (business logic flaws, JWT, API security).
  • Infrastructure & Container Hardening: Containerized deployments via Docker, host hardening (SSH, UFW, fail2ban), and Infrastructure-as-Code (IaC) with Terraform.
  • DevSecOps & Automation: Automating security gates in pipelines (Shift Left via GitHub Actions, Semgrep, Trivy, GitLeaks, pip-audit) and monitoring with Prometheus & Grafana.
  • Cloud Security & Identity: Microsoft Azure fundamentals, identity management (IAM) and role-based access control (RBAC) via Microsoft Entra ID.
  • Emerging Tech (AI Security): Hardening AI interfaces and securing LLM applications (OWASP Top 10 for LLMs, Prompt Injection, Secure AI Gateway).

📂 Highlight Projects

📚 IHK Exam Prep Trackers (Shipped & Used by Hundreds)

A series of local-first web applications designed to help apprentices prepare for their IHK examinations (AP1, AP2 FIAE, AP2 FISI). Over 2900 flashcards, running entirely offline with LocalStorage and zero user tracking.

🔑 Secure API Gateway (FastAPI Backend with JWT Auth)

A secure REST API designed to showcase backend hardening and defensive coding practices.

  • JWT Authentication, bcrypt password hashing, Pydantic input validation, and rate limiting.
  • Automated API testing with Pytest and secure Docker deployment.
  • Stack: Python · FastAPI · PostgreSQL · Docker · Pytest
  • Status: 🔄 In Progress

🤖 Roadmap Flagship: LLM Security Proxy (Secure AI Gateway)

My capstone project: A secure proxy gateway for Large Language Models (LLMs) to mitigate modern security risks.

  • Prompt injection protection, PII data filtering, rate limiting (Redis), and encrypted audit logs.
  • CI/CD deployment with GitHub Actions and SAST/SCA security scans.
  • Stack: Python · FastAPI · Redis · PostgreSQL · Docker · GitHub Actions
  • Status: ⏳ Planned Capstone

🎓 Target Certifications

  • ISC² Certified in Cybersecurity (CC) (Optional / Planned)
  • Microsoft Security Fundamentals (SC-900) (Planned)

🎯 Target Roles

I am aiming to step into roles that combine software engineering with modern security practices:

  • Secure Software Developer (Python / Backend)
  • Junior DevSecOps Engineer (CI/CD, Automation)
  • Junior Application Security (AppSec) Specialist
  • Junior Cloud Security Specialist

📫 Let's Connect

Email LinkedIn XING

Pinned Loading

  1. ap1-tracker ap1-tracker Public

    Ein moderner, lokaler Fortschritts-Tracker für die Fachinformatiker Abschlussprüfung Teil 1. Keine Anmeldung. Kein Tracking. Deine Daten gehören dir.

    JavaScript 16 2

  2. ap2-tracker ap2-tracker Public

    Ein moderner, lokaler Fortschritts-Tracker für die Fachinformatiker Abschlussprüfung Teil 2 (FIAE). Keine Anmeldung. Kein Tracking. Deine Daten gehören dir.

    JavaScript 7 4

  3. ap2-fisi-tracker ap2-fisi-tracker Public

    Ein moderner, lokaler Fortschritts-Tracker für die Fachinformatiker Abschlussprüfung Teil 2 (FISI). Keine Anmeldung. Kein Tracking. Deine Daten gehören dir.

    JavaScript 5 2

  4. portfolio-website portfolio-website Public

    HTML 1