Specializing in secure software delivery, automation, and sustainable software infrastructure. Advocate for open source, digital sovereignty, and transparent software supply chains. Contributor to ISO 5230:2020 and ISO 18974:2023 via theLinux Foundation’s OpenChain Project, the ZenDiS/BSI SSDLC initiative, Bitkom’s Open Source Guidelines, and the PostgreSQL community.
Computer Scientist from HSNR.
Sovereign Infrastructure & DevSecOps: Since 2024, part of the founding team at ZenDiS, developing sovereign software supply chains for Germany. Currently serving as Technical Product Manager at openCode, focusing on security infrastructure, SBOMs, CVE & VEX/CSAF workflows, attestations, legal documentation, and compliance-as-code for OSS delivery at scale.
Audit, Compliance & Secure Delivery: At PwC, scaled enterprise OSS audit and strategy frameworks. Integrated license compliance, security, and quality-control into regulated industries, M&A, and enterprise open source adoption.
Engineering & Infrastructure Automation: At credativ, focused on PostgreSQL, high-availability and general High-Performance OSS Data infrastructure. Built tooling for automated deployments, backup orchestration, and observability.
Primary author of the whitepaper on secure software delivery, co-published by ZenDiS and BSI.
Co-author of the Bitkom "Open Source 3.0" guide, contributing primarily to the "Use" section.
Contributor to international standards for OSS compliance and vulnerability disclosure (Tooling Group & Audit Practices).
VITAKO-Workshop: Einheitlicher kommunaler Standard für Cybersicherheit
Building an Open Source Ecosystem for the public administration
Deutschlandstack – Mehr Chance als Risiko – eGovernment Podcast
Reliable openness for the public administration
OSS Compliance Data Management
Lecture: Balancing Scrutiny and Collaboration - Making OS Work for the Public Administration
Lieferketten und SBOMs – Die neuen Maßstäbe für Open Source Integration
OSS Compliance Audit - What to Expect In and From an Audit
Power on Power