Consulting Area
Michael is a seasoned expert in the technical aspects of information security, with a particular emphasis on conducting thorough penetration tests across diverse computing environments. His expertise encompasses:
– Web Application Security
– Mobile Application Security
– Infrastructure Security
– Spear Phishing Attack Simulations
– Source Code Security Audits
– Architecture Security Evaluations
– Software Assurance Maturity Model (SAMM) Evaluations
In addition to his hands-on consulting work, Michael spearheads the development of multiple in-house software tools, ensuring that they meet the highest security standards. Beyond coding, he is also an accomplished trainer and speaker, providing training sessions and lectures on secure application development, APIs, and microservices.
Michael is also one of the co-founders of sec4dev, SBA Research’s premier security conference and training event tailored for developers.
Research Interests
Michael’s research is deeply rooted in the pursuit of secure, sustainable, and privacy-focused software. His key areas of interest include:
– Green and Sustainable Software Development
– Secure and Maintainable Software Engineering
– Privacy-Enhancing Technologies
– Functional Programming
In December 2022, Michael delivered a TEDx talk on the environmental ramifications of inefficient software and the consequential loss of control. He is also an active contributor to the field, having authored articles for leading technical magazines and journals on topics such as web application security, secure software development methodologies, and the implications of AI-generated code.
Bio
Michael holds a master’s degree in “Software Engineering and Internet Computing” from the TU Wien, where his thesis explored “Object Capabilities and Their Benefits for Web Application Security.” He has earned several prestigious certifications, including:
– Offensive Security Certified Professional (OSCP)
– Certified Information Systems Security Professional (CISSP)
– Certified Secure Software Lifecycle Professional (CSSLP)
– GIAC Web Application Penetration Tester (GWAPT)