Nils Klawitter
Vulnerability Management and Secure SDLC
Experience
Vulnerability Management and Secure SDLC
DB InfraGO AG
- Successfully implemented vulnerability management with DefectDojo
- Advised on and implemented technical and procedural aspects of vulnerability management with DefectDojo
- Provided guidance on implementing a secure software development lifecycle
- Skills: GitLab, DefectDojo, Vulnerability Management, SCA, SAST, DAST, Python, Kubernetes, Argo CD, Docker, AWS, Azure, WhiteSource/Mend, Greenbone
Threat Modeling with STRIDE
Festo SE & Co. KG
- Conducted threat and risk analyses (TARA) for industrial products
- Advised clients on the threat modeling process
- Performed STRIDE-based threat modeling using the Microsoft Threat Modeling Tool
- Skills: STRIDE, TARA, Microsoft Threat Modeling Tool
Application Security Specialist
ITZBund
- Advised and reviewed development teams on application security and secure coding in a large federal project
- Promoted a DevSecOps culture, shift-left approach, and security-by-design principles
- Implemented tools for a secure software development lifecycle
- Skills: AppSec, DevSecOps, SCA, OWASP ZAP, Tekton, Azure DevOps, OpenShift Advanced Cluster Security, OWASP Dependency-Track, SonarQube
Freelancer in Application Security and DevSecOps
SecuredBytes
- Application security (AppSec) and DevSecOps
- Secure software development lifecycle (Secure SDLC)
- Security and cryptographic concepts
- Cryptography engineering, PKI, and cryptographic protocols
Lab for Secure Hardware and Software Development
Technische Hochschule Lübeck
- Set up a secure software development lifecycle using GitLab for students for practical testing and learning in software engineering
- Implemented CI/CD pipelines with various security tools, such as SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), and dependency scanners
- Taught threat modeling, risk assessments, and incident management in a hands-on course
- Skills: GitLab, SCA, SAST, DAST, TARA, Incident Management
Research Associate
Lübeck University of Applied Sciences
- Setting up and supporting a lab for secure hardware and software development
- Teaching in cryptography, secure software development, and IT security
- Research and supporting professors in IT security
Development of a proof of concept for a security application gateway for industrial machines
TRIOVEGA GmbH
- Conceptualizing, defining requirements, and building a proof of concept for a security application interface for industrial machines
- Creating a security concept, developing the software and related tools, and organizing a penetration test for the proof of concept
- Assessing feasibility and presenting the results from the proof of concept case study
- Skills: Docker, Podman, Embedded Systems, Bash, Rust, Python, Threat Modeling, Secure SDLC
Implementation of DevSecOps/AppSec Processes
TRIOVEGA GmbH
- Setting up the IT security team within software development
- Developing policies for internal and external software projects with regard to secure software development lifecycle (SSDLC)
- Training and raising awareness on secure software development
- Evaluating and implementing a DevSecOps process and tools like SCA, SAST, DAST, threat modeling, etc.
- Skills: GitLab, Secure SDLC, Project Management, Threat Modeling, SCA, Dependency-Track
Application Security Engineer
TRIOVEGA GmbH
- Setting up the IT security team in software development
- Project management and planning in security-relevant system development
- Evaluating and introducing a DevSecOps process and tools
- External consulting and assessment of system/software architectures regarding IT security
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Information Technology, Education, Manufacturing, Transportation, and Government and Administration.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Product Development, Research and Development, Project Management, and Quality Assurance.
Summary
I'm Nils, a dedicated freelancer specializing in AppSec and DevSecOps. I focus on securing software and implementing robust security practices in software development.
Skills
- Api Security
- Application Security
- Cloud Security
- Code Audit
- Cryptography
- Dast
- Data Privacy
- Devsecops
- Identity And Access Management (Iam)
- Owasp
- Sast
- Sca
- Secure Architecture Design
- Secure Coding Practices
- Secure Sdlc
- Threat Modeling
- Vulnerability Assessment
- Web Application Security
It Security
- Bsi Standard 200 + Basic Security
- Bsi Technical Guidelines
- Iso 2700x
- Owasp
- Nist 800-218
- Owasp (M)asvs + Standards / Samm
- Cve & Cvss
- Cwe & Cwss
- Common Criteria
- Cis Benchmarks
- Stride
Methods
- Secure Risk Assessments
- Threat Modeling (Stride)
- Code Audits
- Penetration Testing
- Sca
- Sast
- Dast
- Dependency Scanning
- Container Security
- Secure Deployment
- Sboms
- Threat Monitoring
- Vulnerability Management
- Incident Response Management
- Infrastructure Scanning & Hardening
Security Tools
- Owasp Zap
- Sonarqube
- Synk
- Checkmarx
- Veracode
- Gitlab Ci/cd
- Burp
- Trivy
- Whitesource/mend
- Greenbone
- Gitlab Sast & Dast
- Owasp Dependency-track
- Cyclonedx
Programming Languages
- Rust
- Java
- Python
- C
- C#
- Bash
Project Management Methods
- Scrum
- Kanban
- Agile Methods
- V-model
- Safe
Tools
- Intellij
- Eclipse
- Visual Studio
- Vs Code
- Gitlab
- Ansible
- Terraform
- Github
- Docker
- Podman
- Kubernetes
- Openshift
- Ms Office 365
- Atlassian Jira/confluence/bitbucket
Cloud
- Amazon Aws
- Microsoft Azure
- Gcp
Operating Systems
- Linux
- Windows
Languages
Education
Universität zu Lübeck
Master of Science in Computer Science — IT Security and Reliability · Computer Science — IT Security and Reliability · Lübeck, Germany
Universität zu Lübeck
Bachelor of Science in Computer Science — IT Security and Reliability · Computer Science — IT Security and Reliability · Lübeck, Germany
Certifications & licenses
TeleTrust Professional for Secure Software Engineering (T.P.S.S.E.)
TeleTrust e.V.
TeleTrust Information Security Professional (T.I.S.P.)
TeleTrust e.V.
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Nils based?
What languages does Nils speak?
How many years of experience does Nils have?
What roles would Nils be best suited for?
What is Nils's latest experience?
What companies has Nils worked for in recent years?
Which industries is Nils most experienced in?
Which business areas is Nils most experienced in?
Which industries has Nils worked in recently?
Which business areas has Nils worked in recently?
What is Nils's education?
Does Nils have any certificates?
What is the availability of Nils?
What is the rate of Nils?
How to hire Nils?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Vulnerability Management and Secure SDLC
Nearby freelancers
Professionals working in or nearby Lübeck, Germany