My Profile
From experienced autodidact to DevSecOps and infrastructure professional.
Technology ⇐ Interface ⇒ Organization⬤ Who I am
Self-taught in IT and cross-media projects since 1999 — web development, CMS, network administration, media production. Hands-on ops responsibility since 2016 at the same event venue with modular spaces — security-critical formats up to 2,500 m² / 1,000 endpoints, in some cases subject to regulatory approval — initially as freelancer, from 2020 to 2024 as Head of IT (server/client operations, network, security & backup concepts, high-load event and B2B/B2C setups). Since 2025 retraining as a Fachinformatiker (Application Development, FIAE/IHK).
My personal focus beyond the FIAE/IHK training: DevSecOps — bridging development, operations, and security, with operational requirements front and center (reproducibility, monitoring, backup/restore, documentation).
Most recently before retraining as a Fachinformatiker (Application Development), business and operational interface between management, team, customers and external service providers. Solution-oriented project steering in cross-functional teams, with responsibility for selecting and managing external collaborations.
Current DevOps projects — in self-operation, as of 04/2026
- Zero-Knowledge Secrets Broker — Python/FastAPI · 228 tests · 96 % coverage · 13 consumers in production · 97 % compliance across 9 standards (OWASP, GDPR, ISO 27001, NIS2 et al.)
- opendesk EU · Sovereign Workplace — 62 rootless containers · ~30 services · 6 segmented Docker networks · Keycloak SSO with 2FA
- Segmented Borg Backup System — 28 segments · 6 phases · 3 profiles · file- and block-level · restore-validated · in production since 01/2026
⬤ How I work
Methodical and iterative: ADRs for traceable decisions, tests as quality gates, wiki as living documentation, reproducible setups and deployments. Precision as a security principle — defense-in-depth and least-privilege also in the development process (gitleaks, bandit, CodeQL, Snyk, Renovate + cooldown, git-revert rollback via co-versioned image pin, rootless containers).
In the ongoing internship ahead of FIAE qualification: independent rebuild of a historically grown IT infrastructure (8 sites, 15+ years of legacy) single-handedly and without operational downtime — physical cabling, VLAN segmentation across 10 networks (UniFi) as the basis for identity-based access control (zones for infrastructure, machines/services, users, VoIP), backup system with offsite mirroring, central password management, staff training.
⬤ What I can do
Languages
Frameworks & Tools
AV Systems
Network
Storage
Security
Operating Systems
Versioning
Forge & CI/CD
Configuration Management & IaC
Containers & Virtualization
Selfhosted Stack
Supply Chain Security
Tests & Documentation
AI & Workflows
Print / Web
Still / Motion / Post
Photo