06.02.2026 aktualisiert

**** ******** ****
verifiziert
100 % verfügbar

Enable Security in Products: CRA / IEC62443

Traunstein, Deutschland
Deutschland +1
info: Deutschland, Österreich
M. Sc. in Software Engineering
Traunstein, Deutschland
Deutschland +1
info: Deutschland, Österreich
M. Sc. in Software Engineering

Über mich

Industrial product security specialist for CRA and IEC 62443. Supporting manufacturers with SBOM implementation and robust vulnerability management to secure connected machinery and OT software.

Skills

AutomatisierungSoftwaredokumentationIngenieurwesenFirmwareIsa99Vulnerability ScanningProdukt ManagementTechnologie-RoadmapCloud-ServicesRisikoanalyseSoftware Asset ManagementSoftwareentwicklungSchwachstellenanalyseVulnerability ManagementWorkflowsIEC 62443Risikoeinschätzung
I specialize in enabling secure, compliant, and resilient industrial products across the entire software lifecycle. With a strong focus on the EU Cyber Resilience Act (CRA), IEC 62443 and modern secure-development practices, I support manufacturers, OEMs, and software suppliers in transforming regulatory requirements into practical, scalable engineering workflows.

My work centers on helping engineering and product teams build security directly into their development and operational processes. This includes creating transparency in complex supply chains, establishing repeatable security controls, and ensuring that organizations can continuously manage risk in fast-moving industrial environments.

Core areas of expertise include:

• Product Security for Industrial & OT Systems
Extensive experience securing machinery software, embedded systems, industrial connectivity solutions, and IIoT platforms. I help teams design and implement product security concepts that meet both regulatory and customer expectations.

• Cyber Resilience Act (CRA) Readiness & Implementation
Hands-on guidance to interpret CRA obligations and translate them into structured processes: secure development, vulnerability handling, documentation, conformity assessment, incident reporting and lifecycle security.

• IEC 62443 Integration
Practical implementation of IEC 62443-4-1 and -4-2 requirements in engineering organizations, including security design, secure coding, robustness testing, and supplier management.

• SBOM Strategy & Tooling
Building end-to-end SBOM processes that seamlessly integrate into development pipelines. Selection and integration of tools, normalization of SBOM formats, supplier requests, automated generation, and SBOM-driven risk analysis.

• Vulnerability Management for Products
Establishing vulnerability handling processes that meet CRA expectations and industrial requirements. This includes triage workflows, coordinated vulnerability disclosure (CVD), patch strategies, automation, and integration with product roadmaps.

• Secure Development Lifecycle (SDL)
Implementation of CI/CD-integrated controls: static analysis, dependency scanning, threat modeling, secure coding standards, risk assessments, and artifact hardening.

• Supply-Chain Security
Addressing risks in third-party libraries, firmware components, cloud services, and platform dependencies. Creating transparency and governance for complex industrial ecosystems.

• Transformation & Engineering Enablement
Working closely with development, product management, and compliance teams to build repeatable, efficient processes. I help companies move from “theoretical requirements” to operational security practices that engineers can work with.

Enable organizations to build secure industrial products at scale — with clarity, transparency, and processes that actually work in practice.

Sprachen

DeutschMutterspracheEnglischverhandlungssicher

Zertifikate

Certified Scrum Master

Scrum Alliance

2022

Certified Scrum Developer

Scrum Alliance

2022

Cisco CCNA

Cisco

2010


Kontaktanfrage

Einloggen & anfragen.

Das Kontaktformular ist nur für eingeloggte Nutzer verfügbar.

RegistrierenAnmelden