About
About
Technology has been part of my life for as long as I can remember. A Game Boy at four. A self-built 486 at twelve, assembled from spare parts salvaged from my parents’ office, running DOS and Windows 95. As a teenager I ran the network infrastructure at my parents’ company and organised LAN parties with friends, long before any of us had a driver’s licence.
The passion was always there. Life had other plans.
I ended up in photography and committed to it fully. I finished my apprenticeship as the top graduate of my regional photographers’ guild, then earned a Bachelor of Arts with a final grade of 1.0. What kept me engaged wasn’t only the visual craft. Photography is a deeply technical profession that demands constant adaptation: evolving camera systems, complex colour science, and workflows built on specialised tools. Over the years I developed deep expertise in Adobe Photoshop, at the level of high-end retouching and multi-layer compositing where precision and an understanding of how the tool thinks are everything, and in Capture One, where colour, calibration, and RAW processing reward people who understand them at a fundamental level. Alongside still photography I moved into video production, audio engineering, and aerial cinematography, holding a certified EU drone pilot licence (class A2).
Since 2014 I’ve worked as a freelance commercial photographer for corporate clients across Germany and beyond. Precision, discretion, and delivering under pressure aren’t skills I’m still developing. They’re the foundation I bring with me.
In November 2025 I decided to stop ignoring where my instincts had always pointed and take my technical curiosity seriously, as a profession. Since then I’ve been learning consistently: evenings, weekends, alongside a full-time freelance career and a busy family life with a young child. Motivation was never the question.
What I’m working on
I passed the Security Analyst Level 1 (SAL1) certification on my first attempt with 850/1000, after completing TryHackMe’s SOC Level 1 path. On TryHackMe I’m in the top 1%, now working through threat intelligence, detection engineering, DFIR, and AI security. In parallel I’m finishing Google’s IT Support Professional Certificate on Coursera, with four of five courses done.
Tools I’ve built
I design, specify, and test-drive security tools, then publish them on PyPI. The implementation runs through an AI-assisted workflow with review gates; the architecture, specifications, test design, and security logic are mine.
- sift – an alert-triage summarizer with four LLM providers, a built-in prompt-injection scanner, and 1,145 tests
- vex – IOC enrichment against VirusTotal, STIX 2.1, MITRE ATT&CK, and WHOIS
- barb – a phishing-analysis tool that works offline by design, with opt-in OSINT enrichment when you want it
- sigmaforge (in progress) – an honest backtest harness for Sigma detection rules: it measures whether a rule actually fires on the attack it targets and how often it fires on normal activity. My first detection-engineering work sample.
Certifications
- SEC1 – Security Fundamentals (TryHackMe)
- SAL1 – Security Analyst Level 1, 850/1000 on the first attempt (TryHackMe, 2026)
- Google IT Support Professional Certificate – four of five courses done (Coursera)
- CompTIA Security+ – planned for Q3 2026
Why this blog
This blog documents the path: CTF writeups, learning notes, the tools I’m building, and honest reflections on what it takes to break into cybersecurity from a non-traditional background. If you’re on a similar path, I hope it’s useful. If you’re a recruiter or hiring manager, feel free to reach out.