Identity & AI Infrastructure Security
Hardening Identity.
Securing AI.
Defending Infrastructure.
Active Directory Domain Services Tier Model implementation, ADCS vulnerability remediation, Privileged Access Workstation deployment, and air-gapped LLM, RAG, and AI agent architectures — protecting the identity layer attackers target first, and the AI layer they target next.
Identity & AI Infrastructure
Security Architect
Over 28 years securing enterprise infrastructure — from on-premises Active Directory Domain Services (ADDS) forests to hybrid Azure environments. I architect, harden, and recover the identity systems that underpin every organization's security posture.
My work centers on eliminating identity attack paths: misconfigured ADCS templates exposing ESC1–ESC8 vulnerabilities, missing administrative tier boundaries allowing lateral movement from Tier 2 to Tier 0, credential exposure through Kerberoasting and Pass-the-Hash, and unmonitored privileged access without PAW enforcement.
The same discipline now applies to AI: isolated LLM platforms with no internet egress, RAG pipelines that inherit ADDS and Entra ID permissions instead of bypassing them, and AI agents treated as what they are — privileged non-human identities that belong inside the Access Model. Threat models follow the OWASP Top 10 for LLM and Agentic Applications and MITRE ATLAS.
Engagements span federal agencies under BSI IT-Grundschutz elevated protection, global banks under PCI DSS and BAIT, international law firms, and manufacturing groups — including direct collaboration with Microsoft's Compromise Recovery Security Practice (CRSP) for ADDS breach containment and forest recovery.
Background
- Computer Science — FernUniversität Hagen
- Civil Engineering — TU Darmstadt
- Independent Consultant since 2001
Languages
- German — Native
- English — Fluent
- French — Basic
Based in
Hofheim am Taunus, Germany
Available across DACH & Europe
Infrastructure Security Services
Infrastructure Security Stack
Selected Engagements
Harden Your
Infrastructure
Whether you need ADDS compromise recovery, Tier Model implementation, ADCS remediation, PAW deployment, an air-gapped LLM platform, secure RAG design, or an AI threat model — let's discuss your environment.