Web Application Firewall Implementation for Citizen Services (Imperva)
Deployed and tuned a reverse-proxy WAF protecting 47 citizen-services websites for a German federal state — zero-impact cutover, aligned to BSI Grundschutz.
ImpervaWAFBot & DDoS ProtectionPublic Sector
Engineering
✓ 47 government websites secured; zero-impact cutover, no major incidents since launch
2013
Security GAP Analysis — Prioritized by Budget and Time
A GAP analysis built on the team's own cost/effort delivery data, so recommendations could be re-prioritized to match a client's real budget and headcount — not a generic checklist.
GAP AnalysisRisk PrioritizationISO 27001Maturity Scoring
Advisory
✓ Turned inconsistent, advisor-dependent GAP analyses into one reusable methodology — delivered ~45 times over three years, prioritized by real cost/effort data instead of gut feel
2019 – 2022
Firewall & VPN Consolidation for a Diocese in North Rhine-Westphalia
Consolidated site-to-site VPN and firewall policy for 250 locations onto Palo Alto Networks/Panorama, cutting the ruleset from ~5,000 to 850 rules with full App-ID enforcement.
Palo Alto NetworksPanoramaVPNApp-ID
Engineering
✓ Ruleset cut from ~5,000 to 850 rules, fully App-ID enforced across 250 sites
2012 – 2015
Airgapped Network Upgrade for Multinational Joint Operations
Led a multinational team through the design and rollout of upgrade procedures for a mission-critical airgapped network supporting joint operations across allied armed forces.
Palo Alto NetworksAirgapped NetworksSecurity ArchitectureTeam Leadership
Security Architecture
✓ Delivered on schedule; secure high-assurance connectivity re-established across the joint-operations network
2016 – 2019