I write software since the nineties, work as a freelance software developer since 1997, focus on Java since 1999 and on IT security since 2005.
Aside from the traditional software engineering tasks I support clients in the field of IT security. This includes penetration testing, security audits, architectural reviews, and web application hardening. Several times a year I conduct inhouse training courses on topics like web application security (focussing on Java) as well as on SecDevOps concepts for bringing security into agile projects.
Sometimes I enjoy writing articles about web application security and speak/train at conferences about web application hardening (WJAX 2009, JAX 2010, O...