Security, engineered into the pipeline.
I work where software meets security — building defenses into the development pipeline, and increasingly into the architecture and EU regulation that decide whether they hold at scale.
What I work on
01 / FOCUSThreat models that survive contact with the code.
Threat modelling, secure code review, and API security — including OpenAPI-driven analysis of REST surfaces.
Security that lives inside the pipeline, not after it.
Security gates in CI/CD: SAST, secret scanning, SBOM, and dependency/image scanning, wired to fail fast.
Regulation as a design input, not an afterthought.
Controls that satisfy real-world EU frameworks — NIS2, DORA, the AI Act — without slowing teams down.
Selected work
02 / WORKA containerized static portfolio on AWS EC2, fronted by nginx with a Let’s Encrypt cert, deployed through a GitHub Actions pipeline that builds, scans the image, and rolls out over SSM. Full case study on the infra, the security choices, and where it’s going.
From the blog
03 / WRITINGA bit more
04 / BACKGROUNDRight now I’m an application security engineer in the Public Sector, where I own a centralised CI/CD security pipeline across an air-gapped, on-premise estate — the kind of place where every scanner, SBOM, and policy gate has to work without ever touching the open internet.
I came up through DevOps before moving fully into AppSec. Vulnerability management at scale, secret and dependency scanning wired into CI, and software supply-chain integrity — SBOMs, artifact signing, the unglamorous plumbing that decides whether a release can be trusted.
I’m finishing an MSc in Cybersecurity at KU Leuven, with a thesis on using the OpenAPI specification to harden REST APIs. Outside the day job I speak about API security and play the occasional CTF, usually with more enthusiasm than sleep.
“Make security something that happens inside the pipeline rather than bolted on after it.”