Software Security Engineer β DevSecOps Β· Zero Trust Β· Cloud Security Β· Kubernetes
I design and build secure distributed systems β from Zero Trust architectures and Kubernetes hardening to developer-facing security tooling. I care about making security a first-class engineering concern, not an afterthought.
π mfuchs.dev Β· π Blog
I'm a Software Security Engineer with roots in SRE and software engineering. My work sits at the intersection of distributed systems and security, where reliability, trust, and resilience aren't trade-offs but design goals.
I've architected Zero Trust network models, hardened Kubernetes clusters, and built developer-facing security tooling that doesn't slow teams down. I've led IAM and OAuth2/OIDC integrations at scale, using Keycloak and custom authorization policies to enforce least-privilege access across microservice meshes.
I believe security belongs in the delivery pipeline, not bolted on at the end β threat modeling early, shifting left with SAST/DAST, and treating every deployment as an opportunity to reduce attack surface.
- π Focus Areas: Security Β· Cloud
- π οΈ Primary Stack: Go Β· Kotlin Β· Java
- π§ Expertise: Zero Trust Β· IAM Β· Kubernetes
- π‘ Background: SRE Β· Software Engineering
π Security
Threat modeling, Secure Development Lifecycle, secure coding, security awareness.
Zero Trust OAuth2 / OIDC Keycloak SAST / DAST mTLS WAF OWASP Top 10 Secrets Management
βοΈ Cloud & Infrastructure
Kubernetes-native security, cloud hardening, IaC, observability.
Kubernetes Helm Terraform AWS GCP OPA / Rego Istio Prometheus OpenTelemetry
βοΈ DevSecOps
Shift-left security, CI/CD hardening, policy-as-code.
GitHub Actions Trivy Snyk Cosign SBOM Supply Chain Security Policy as Code GitOps ArgoCD
ποΈ Architecture
Distributed systems design, microservices, resilience patterns.
Microservices Event-Driven Go Kotlin Quarkus Java Spring Boot Gin Keycloak Shibboleth API Gateway Service Mesh
- Rescue Smart β Website for a first aid training provider offering DGUV-compliant occupational first aid courses, refresher training, and AED/emergency scenario instruction.
Next.jsTypeScriptTailwind CSSResendVercel - B&K Arbeitsschutz β Corporate site for a DEKRA-certified workplace safety consulting firm near Munich.
Next.jsTypeScriptTailwind CSSResendVercel - Kreisjugendfeuerwehr Starnberg β Regional platform coordinating 43 youth fire brigades and 600+ members, with a password-protected member area and secure PDF downloads.
Next.jsTypeScriptTailwind CSSResendVercel
Plus professional work spanning e-commerce platforms on GCP/StackIT, university IAM platforms (Keycloak & Shibboleth), fullstack client projects, and Zero Trust research at a university SecLab.
- 2026 Β· Meetup Munich β Zero Trust with Keycloak: How to Securely Integrate IAM into Microservices Architectures
- 2025 Β· heise devSec β Zero Trust with Keycloak: Securely Integrating IAM into Microservice Architectures
- 2023 Β· UniNow β Zero Trust Architecture & Passkeys: The Duo Against Lateral Movement
- 2023 Β· ZKI IAM β Passkeys: The Future of Authentication in Shibboleth with privacyIDEA
- 2023 Β· ZKI IAM β Security and Convenience: How Tailscale Reimagines Admin Access
- 2022 Β· heise devSec β Beyond OAuth 2.0 and OpenID Connect: Hidden Features in Keycloak
- 2022 Β· Meetup Munich β DevSecOps - Securing Your Web App in Three Simple Steps



