Lead Solutions Architect at XBOW. 20+ years securing software at scale. Author, conference speaker, and occasional code reader — helping security and engineering teams actually work together.
Mastering the Art of Application Security Testing — a practical guide for development managers, DevSecOps leads, and CISOs evaluating SAST, DAST, SCA, and container security tools.
Read more →I speak at international conferences on AppSec program design, DevSecOps transformation, and AI in security testing. Next up: MCTTP Munich (September 2026).
See my talks →20+ years building and leading solutions architecture teams at Veracode, Deny All, and across DACH, EMEA, and APAC. Available as PDF download.
View my career →A TLPT engagement runs nine to fourteen months end to end — then nothing happens for three years. Seven months after publishing the guide to that cycle, the same supervisor told the same banks the attacker's cycle is measured in hours.
Read on LinkedIn →The ECB has told every bank it supervises to prepare for AI attackers working at machine speed, with plans due 31 October. It is detailed on making defences faster — and silent on how you validate them against that attacker.
Read on the XBOW blog →I've just started a new chapter as Lead Solutions Architect at XBOW — bringing 20+ years of application security experience to a new challenge.
Before joining XBOW, I spent nearly a decade at Veracode as Senior Principal Solution Architect, leading teams across EMEA and APAC. Most recently, I worked closely with the product management team to help shape the direction of our products — turning field insights and customer realities into roadmap decisions that actually stick.
In 2026 I published Mastering the Art of Application Security Testing — a practical guide for development managers, DevSecOps leads, and CISOs navigating SAST, DAST, SCA, and container security tools. I'm also a regular speaker at international conferences on AppSec, DevSecOps, and the evolving role of AI in security testing.
On the technical side: I would never call myself a developer — but I can read, write, and occasionally survive code, which apparently puts me in a very niche and dangerous category.
New chapter, day one. Bringing 20+ years of AppSec expertise to XBOW — where the work is just getting interesting.
A practical guide for managers and security leaders evaluating SAST, DAST, SCA, and container security tools. Foreword by Chris Wysopal.
Regular speaker at DevOpsCon, Enterprise:CODE, BSides, and OWASP events. Next up: MCTTP Munich (September 2026).
Led EMEA/APAC solution architecture and worked closely with the PM team to shape product direction. Scaled APAC from 0 to 27 engineers.