Identity & AI Infrastructure Security

Hardening Identity.
Securing AI.
Defending Infrastructure.

Active Directory Domain Services Tier Model implementation, ADCS vulnerability remediation, Privileged Access Workstation deployment, and air-gapped LLM, RAG, and AI agent architectures — protecting the identity layer attackers target first, and the AI layer they target next.

28+ Years in Infrastructure Security

Identity & AI Infrastructure
Security Architect

Over 28 years securing enterprise infrastructure — from on-premises Active Directory Domain Services (ADDS) forests to hybrid Azure environments. I architect, harden, and recover the identity systems that underpin every organization's security posture.

My work centers on eliminating identity attack paths: misconfigured ADCS templates exposing ESC1–ESC8 vulnerabilities, missing administrative tier boundaries allowing lateral movement from Tier 2 to Tier 0, credential exposure through Kerberoasting and Pass-the-Hash, and unmonitored privileged access without PAW enforcement.

The same discipline now applies to AI: isolated LLM platforms with no internet egress, RAG pipelines that inherit ADDS and Entra ID permissions instead of bypassing them, and AI agents treated as what they are — privileged non-human identities that belong inside the Access Model. Threat models follow the OWASP Top 10 for LLM and Agentic Applications and MITRE ATLAS.

Engagements span federal agencies under BSI IT-Grundschutz elevated protection, global banks under PCI DSS and BAIT, international law firms, and manufacturing groups — including direct collaboration with Microsoft's Compromise Recovery Security Practice (CRSP) for ADDS breach containment and forest recovery.

Background

  • Computer Science — FernUniversität Hagen
  • Civil Engineering — TU Darmstadt
  • Independent Consultant since 2001

Languages

  • German — Native
  • English — Fluent
  • French — Basic

Based in

Hofheim am Taunus, Germany
Available across DACH & Europe

Infrastructure Security Services

Infrastructure Security Stack

Selected Engagements

Harden Your
Infrastructure

Whether you need ADDS compromise recovery, Tier Model implementation, ADCS remediation, PAW deployment, an air-gapped LLM platform, secure RAG design, or an AI threat model — let's discuss your environment.

[Click to reveal email]