Profile

M.Sc. in IT-Security from TU Darmstadt, specialising in penetration testing, vulnerability research and secure system design. I co-founded a software consultancy where I run client projects end to end — requirements, architecture, development, deployment and client communication. Combining offensive security with full-stack engineering gives me a practical view of how systems get exploited and how to build them so they do not. I publish research at ICIS and ECIS and am equally comfortable talking to engineers and to non-technical stakeholders.

Experience

Walter Dibbern GbR

03/2024 – Present

Founder & Full Stack Developer

Part-time / strategic advisor

  • Founded and operate an independent software consultancy, delivering 5 client projects for municipalities, SMEs and private clients — owning the full engagement lifecycle from architecture and development through deployment and ongoing support.
  • Architected and deployed serverless AWS applications for three client engagements (Lambda, API Gateway, Amplify, CloudFront edge functions, Route53, IAM) with a security-first mindset: hardened API design, access control and infrastructure provisioning from day one.

Technical University of Darmstadt — Software & AI Business

10/2025 – 02/2026

TensionAI — decision support for SMEs

Research assistant · third paper (ECIS 2026)

  • Architected a multi-tenant decision-support tool that surfaces organisational tensions through an interactive dashboard: Vertex AI (Gemini 2.0 Flash reasoning, Vertex AI Search RAG), shipped serverless on Cloud Run with Firestore and Firebase Auth.
  • Designed and implemented the multi-tenant security and data-isolation architecture: Firebase Auth, per-tenant data isolation, API hardening.
  • Led two student developers through the build via code reviews and technical roadmap definition.

03/2025 – 09/2025

SustAIn — from prototype to field study

Research assistant · second paper (ICIS 2025)

  • Evolved the SustAIn application into the study platform behind "Understanding the Environment: How Generative AI Reshapes Organizations' Sensemaking in Sustainability Reporting" (ICIS 2025).

10/2024 – 02/2025

SustAIn — GenAI for sustainability reporting

Research assistant · sole developer · first paper (ECIS 2025)

  • Started as the sole developer: built a LangGraph-based conversational agent with persistent memory over DNK sustainability-reporting data (FastAPI, PostgreSQL, React/TypeScript, Docker on GCP).
  • The system became "SustAIn": Designing Generative AI to Support Environmental Sensemaking (ECIS 2025).

Deutsche Telekom Technik GmbH

10/2021 – 02/2022

Bachelor's Thesis

Monitoring & Data Analytics

  • Designed and deployed a Kubernetes cluster for the distributed monitoring & analytics platform (VictoriaMetrics cluster, Prometheus, Grafana, Alerta).

03/2021 – 08/2021

Working Student

Monitoring & Data Analytics

  • Built out the platform's frontend and API layer (Angular, Express.js) in an agile SCRUM team.

10/2020 – 03/2021

Practical Semester

Monitoring & Data Analytics

  • Joined the monitoring & data analytics team and started work on the platform in an agile SCRUM setup.

06/2018 – 07/2018

Internship

Robert Bosch GmbH

10/2019 – 06/2020

Working Student

  • Developed tooling for runtime measurement of cryptographic security algorithms (signature generation & verification).
  • Migrated the measurement infrastructure from Renesas to a Lauterbach debugger and implemented graphical runtime visualisation.

Projects

05/2025 – 11/2025

Master's Thesis (Grade 1.0) — TU Darmstadt

Designing Adaptive and Explainable Anomaly Detection for Sustainable Security Systems

  • Adaptive, explainable anomaly detection system optimised for resource efficiency in security monitoring.
  • Derived 13 design principles and a functional prototype via Design Science Research and 16 expert interviews, balancing detection accuracy against energy efficiency.

04/2024 – 07/2024

Penetration Testing Internship — usd AG

  • Identified and exploited security vulnerabilities with industry-standard tooling across multiple CTF rounds.
  • Responsibly disclosed a SQL injection vulnerability (CWE-89, CVSS 8.8 High) in an open-source CMS: Python PoC demonstrating time-based blind SQL injection with full database exfiltration potential, reported via GitHub Private Security Advisory.
  • Toolset: Kali Linux, Burp Suite, Nmap, Metasploit, Wireshark.

Education

10/2022 – 03/2026

Technical University of Darmstadt

Master's Degree — IT Security

Final grade 1.7

Specialisation in penetration testing, vulnerability research and secure system design.

09/2023 – 02/2024

Universidad Politécnica de Madrid (UPM)

Semester abroad (Master's) — Computer Science

10/2018 – 08/2022

University of Applied Sciences Heilbronn

Bachelor's Degree — Applied Computer Science

Final grade 1.7

Cloud computing project: containerised Go application on AWS, fully provisioned via Terraform.

Skills

🛡️ Penetration Testing

Exploit Development (PoC)SQL Injection (CWE-89)Responsible DisclosureOWASP Top 10CTF

⚒️ Security Tools

Kali LinuxBurp SuiteMetasploitNmapWiresharkKeycloakGobuster

👨🏼‍💻 Programming & Scripting

PythonJavaScript/TypeScriptGoJava/KotlinRubyBash/Shell

☁️ Cloud & Infrastructure

AWS (Lambda, API Gateway, Amplify, IAM, Route53)GCP (Cloud Run)TerraformDocker

💬 Languages

German (native)English (fluent)Spanish (conversational)

Publications

Designing GenAI-Enabled Tension-Aware Systems for Sustainability Strategizing

ECIS 2026 · with N. Brune, M. Gräf

"Gads": A DSR Approach to Designing Green Anomaly Detection Systems, Driving Security into Resource Efficiency

2026 · with N. Brune

Understanding the Environment: How Generative AI Reshapes Organizations' Sensemaking in Sustainability Reporting

ICIS 2025 · with N. Brune, O. Vetter, P. Buxmann

"SustAIn": Designing Generative AI to Support Environmental Sensemaking

ECIS 2025 · with N. Brune, O. Vetter, P. Buxmann