01 / About
I work in product security at Siemens, where I'm part of the PSIRT team handling coordinated vulnerability disclosure for industrial and enterprise products. I also coordinate the team's conference monitoring service — staying close to leaders, researchers, and strategic partners while tracking the research that may impact our products.
My technical focus is on OT/ICS security — the security of operational technology and industrial control systems, where the constraints are different: long asset lifespans, legacy protocols, and consequences that extend beyond data loss into physical systems.
Outside of work I co-lead OWASP Leiria and I'm finishing an MSc in cybersecurity and forensics. I'm interested in the infrastructure layer of vulnerability management — how disclosures get coordinated, how data quality compounds over time, and what better tooling for the ecosystem might look like.
Core competencies