Lead AI Security Consultant at amiconsult, Germany.
I spend most of my time on enterprise IAM and on the mess AI agents make of it: what an agent is allowed to do, who owns it, and how anyone proves afterwards what it did. Large DACH enterprises, so the answers have to survive an auditor and a sceptical CFO.
I came from ML rather than security — master's in CS, thesis on performance prediction for software architectures — which is why half the repos here are models and the other half are identity plumbing.
- IAM-consultant-assessment — the technical challenge I hand to IAM consultant candidates. Two Rust services, an HR system and a SCIM 2.0 provisioning target, so people integrate against something real instead of talking about integration on a whiteboard.
- intern-trial-day-assignment-mcp — the same idea for interns: an MCP server over Keycloak's admin API. The solution I expected them to reach is checked in next to the skeleton they start from, which turned out to be the useful part.
- palladio_approximator — master's thesis. Surrogate models that predict system performance from architecture specifications, so you can skip the simulator. Paired with TPCM-generator, which produced the training data.
- nixos-config — workstation and home server, declarative. The repo here I actually maintain.
- .doom — Doom Emacs. org-roam is where the real work lives; this is the machinery around it.
Rust and Python for most things, Nix for anything that has to come back identical, Emacs for the rest.
