IT-Consulting

Timo Pagel

Timo Pagel

DevSecOps Consulant

Freelancer

Biography

Timo Pagel is a security architect, located in Hamburg.

He has been in the IT industry for over fifteen years. After a career as a system administrator and web developer, he now advises clients on DevOps security with the focus on security test automation for software and infrastructure. In his freetime he teaches “Security in Webapplications” at the University of Applied Sciences Kiel or starting in 2019 at the University of Applied Sciences Wedel.

Interests

  • (Agile) Secure Development Lifecycle
  • DevSecOps
  • Threat Modeling

Education

  • Master of Science, 2016

    University of Applied Sciences Kiel

  • Bachelor of Science, 2014

    University of Applied Sciences Kiel

  • Qualified IT specialist for system integration, 2009

    Ennit AG and IHK, Kiel

DevSecOps

Embrace the full DevSecOps-toolchain and culture to enhance the security of your cloud and applications.

Projects

Assessment of the current DevOps security status, planning of activities and check of the effectivness.

Train developers web threats and how to develop secure code.

Train developers web threats and how to develop secure code.

Review of complex IT systems like cloud, webapplications and mobile

Conception and implementation of vulnerability scanners and vulnerability management.

Introduction into cloud security, continuous vulnerability scanning and DevOps culture.

Conduction of a docker security workshop to show the threats by operating Docker.

Quick security check of web applications to identify threats in running applications for common pit falls.

Conduction of a structured analysis to identify threats in IT systems.

Informationssicherheits-Schulung für Mitarbeiter von kleinen bis großen Organisation.

Härtung von WordPress

Assessment of the overall security status, planning of activities and check of the effectivness.

Introduction into modern methods to integrate security into the development lifecycle.

Recent & upcoming Talks

Continuous Lifecycle London

OWASP Stammtisch Hamburg

Sep 15, 2018

Kieler Open Source und Linux Tage

OWASP Stummit

Kieler Open Source und Linux Tage

DiWiSH-Fachgruppe Open Business: 2. Kieler Open Source Business Konferenz

Experience

August 2018 – Present

Hamburg, Germany

DevSecOps Consultant

Leading finanz- and insurance software development company (NDA)

  • Development of concepts to integrate security into the development lifecycle
  • Conception and implementation of continuous security tests in the build pipeline
  • Security review of complex IT Systems like OAuth, multi factor authentication, webserver and Java applications
  • Training of internal security experts

February 2017 – Present

Hamburg, Germany

DevSecOps Consultant

SIGNAL IDUNA Gruppe

  • Development of concepts to integrate security into the development lifecycle
  • Conception and implementation of continuous security tests in the build pipeline
  • Security review of complex IT Systems like OAuth, multi factor authentication, webserver, OpenShift clusters and Java applications
  • Training of internal security experts

March 2016 – May 2016

Kiel, Germany

Websecurity Consulant

Web Agency (NDA)

  • Automation of static and dynamic security tests in the build pipeline
  • Conduction of security trainings

January 2016 – June 2016

Kiel, Germany

DevSecOps Consultant

Startup (NDA)

Evaluation and implementation of DevOps strategies to enhance the security of webapplications

March 2015 – December 2018

Kiel, Germany

CTO

August 2014 – November 2014

Hamburg, Germany

Webdeveloper with security background

Iteratec GmbH

  • Evaluation and implementation of dynamic security tests as a prototype for SecureCodeBox.io

June 2014 – June 2018

Kiel, Germany

Fullstack Developer

Lengalia

  • Development and maintenance of a web vocabulary trainer in PHP and JavaScript

August 2012 – June 2013

Kiel, Germany

IT-Referent

AStA of the University of Applied Sciences Kiel

Vulentary development of a ‘Rückerstattungssoftware’ with PHP, MySQL and JavaScript

August 2009 – September 2013

Kiel, Germany

Webdevelopment and system administration (work student)

ennit interactive GmbH

  • Development of hotel booking engines in PHP and JavaScript
  • Administration of webservers like Apache or OpenStreetMap

February 2006 – June 2010

Kiel, Germany

Qualified IT specialist for system integration

TNG AG (now Ennit AG)

Teaching

April 2019 – present

Wedel, Germany

Lecturer for Security in Webapplications

University of Applied Sciences Wedel

  • Conception of the module Security in Webapplications for master students
  • Conduction of the course

October 2018 – present

Hamburg, Germany

Conduction of Docker Security Workshop

iteratec GmbH

  • Conduction of one day docker security trainings

July 2018 – present

Nürnberg, Germany

Conduction of  a DevSecOps Workshop

Leading tax software development company (NDA)

  • Conduction of a two days DevSecOps and Agile Secure Development Lifecycle training for the head of security

September 2016 – January 2017

Kiel, Germany

Lecturer for IT-Infrastructure

Schleswig-Holstein Business Academy

  • Conception of the module IT-Infrastructure for bachelor students
  • Conduction of the course
  • Conception and implementation of a virtual IT infrastructure with Virtualbox

June 2014 – September 2014

Kiel, Germany

Lecturer for Security in Webapplications

University of Applied Sciences Kiel

  • Conception of a teaching concept and the module Security in Webapplications for bachelor students
  • Conduction of the course
  • Conception and implementation of a virtual IT infrastructure to learn how to conduct IT security audits

Contact