About me
I am a Security Consultant at Xebia Security with experience as an offensive security specialist and information security officer. I like to combine technical skills on offensive security with a risk-based approach to maximise business value of security solutions. On the defensive side, I can assist in automating security checks in the CI-pipeline to get direct feedback to developers or review code to identify vulnerable functionality. Next to this, I am a Google Cloud Certified Professional Cloud Security Engineer.
Having my roots in Aerospace Engineering, I have a broad interest in advanced technology and I am quick to grasp new concepts. I like tinkering with systems and solving complex puzzles with a goal-oriented approach.
My storyline

Nederlandse Spoorwegen – Product Owner Security
Responsible for a team of quality assurance engineers including security specialists, performance specialists and software developers. During my time at NS I assisted the sub-organisation responsible for commerce and IT to migrate their customers to a Customer Identity & Access Management solution.
Mollie – Engineering Manager
I helped Mollie grow a security organisation in the first line of defense. Being a company going through hypergrowth while being regulated as a financial institution, this high-dynamic environment provided me with a lot of challenges in building and empowering a team of security engineers. We focused on threat modelling with the DevOps teams, engaging developers in security in CI and providing security measures in a cloud migration program to ensure the maximum level of security for Mollie customers.


Computest – Chief Information Security Officer
At Computest I helped the organisation secure its assets in the form of data, devices and customer-facing applications. An interesting challenge with a large team of highly skilled hackers around you. I was able to bridge the gap between business requirements and technical security capabilities. During this period I helped the organisation obtain the ISO-27001 certification for information security.
Computest – Ethical Hacker
As an ethical hacker I was able to develop myself on a technical level with regard to web applications, the underlying infrastructure (on-prem and cloud) and office automation networks. I had the opportunity to learn from the best and dig deep into web technology. This knowledge continues to support me in helping companies defend against hackers.


Contact
Do you have a security challenge that you want to address? From a personal or professional perspective? Don’t hesitate to reach out! Let’s have a cup of coffee.