DP — BRUSSELS 50.85°N 4.35°E
Dimitrios Papadimas — Application Security Engineer

Security, engineered into the pipeline.

I work where software meets security — building defenses into the development pipeline, and increasingly into the architecture and EU regulation that decide whether they hold at scale.

loc  Brussels, Belgium
edu  MSc Cybersecurity, KU Leuven
reg  NIS2 · DORA · AI Act
now  ● open to interesting problems
Get in touch →

What I work on

01 / FOCUS
No. 1 — AppSec

Threat models that survive contact with the code.

Threat modelling, secure code review, and API security — including OpenAPI-driven analysis of REST surfaces.

No. 2 — DevSecOps

Security that lives inside the pipeline, not after it.

Security gates in CI/CD: SAST, secret scanning, SBOM, and dependency/image scanning, wired to fail fast.

No. 3 — Architecture

Regulation as a design input, not an afterthought.

Controls that satisfy real-world EU frameworks — NIS2, DORA, the AI Act — without slowing teams down.

Selected work

02 / WORK
Case study
How this site is built — and hardened.

A containerized static portfolio on AWS EC2, fronted by nginx with a Let’s Encrypt cert, deployed through a GitHub Actions pipeline that builds, scans the image, and rolls out over SSM. Full case study on the infra, the security choices, and where it’s going.

Read the case study →
runtime
Docker
host
AWS / EC2
edge
nginx + TLS
deploy
GitHub Actions
scan
Trivy
access
SSM, no SSH
live — you are looking at it

From the blog

03 / WRITING
27·05·26 Vulnerability Discovery Is No Longer the Bottleneck AppSec · Vuln management · Triage ↗ 30·06·26 My Server Has No SSH Port AWS/SSM · Hardening · Attack surface ↗
All posts on the blog ↗

A bit more

04 / BACKGROUND

Right now I’m an application security engineer in the Public Sector, where I own a centralised CI/CD security pipeline across an air-gapped, on-premise estate — the kind of place where every scanner, SBOM, and policy gate has to work without ever touching the open internet.

I came up through DevOps before moving fully into AppSec. Vulnerability management at scale, secret and dependency scanning wired into CI, and software supply-chain integrity — SBOMs, artifact signing, the unglamorous plumbing that decides whether a release can be trusted.

I’m finishing an MSc in Cybersecurity at KU Leuven, with a thesis on using the OpenAPI specification to harden REST APIs. Outside the day job I speak about API security and play the occasional CTF, usually with more enthusiasm than sleep.

“Make security something that happens inside the pipeline rather than bolted on after it.”
05 / Contact

Open to interesting problems in application security — wherever they live in the stack.