DevSecOps Consulting
DevSecOps problems are not tool problems. They are decision problems. I help teams make the right decisions — before they get expensive.
What I do
Pipelines & supply chain
Hardening CI/CD pipelines — your pipeline is the biggest attack surface in your company. Plus supply chain security from dependencies to signatures and SBOMs.
Container & Kubernetes
Security architecture for the entire development and operations cycle: container hardening, Kubernetes security, secure build and deploy processes.
Audits & incident follow-up
Security audits of build and deploy processes and incident follow-up — including the uncomfortable questions afterwards. Also available as an external second opinion on existing concepts.
How I work
I look at how your team actually works — before changing anything. DevSecOps problems are decision problems, not tool problems.
No 80-page reports nobody reads. You get concrete, prioritised steps — developed with the team rather than over its head.
What I recommend, I have built and operated myself. Implementation happens with your team — so the knowledge stays in-house.
Security as a craft,
not compliance theatre.
For development teams and mid-sized companies that want to make the right decisions before they get expensive. A short message is enough — I will get back to you personally.
Typical triggers
- Pipeline assessment: your CI/CD has grown organically and nobody can say any more who is allowed to deploy what.
- Supply chain hardening: a compromised package hit you — or you would rather not wait until one does.
- Container and Kubernetes security: the cluster runs, but hardening got left behind during the move.
- Incident follow-up: the incident is over. The question of why it was possible is still open.
How I work
I start with your actual stack, not with a checklist. What I find comes back prioritised: what hurts right now, what is structural, what can wait — each with an estimate of what fixing it costs.
No 80-page reports nobody reads. One document your team can start working through on Monday, and if you want, I implement the first items together with you.
How to check my work before hiring me
You can see how I think and build before you commit. On the blog I take security incidents and advisories apart in public — with affected versions, mitigation, and what I actually rolled out for my own clients. Under Open Source you will find the code of the building blocks I use in projects.
23 years of development, 14 of them self-employed. The kind of operation I talk about is the one I run myself.