Sales Engineering & Field Technical Leadership · Cybersecurity
Bridging deep technical security expertise and boardroom-ready strategy.
VP Global Sales Engineering, Hamburg, Germany · Open to remote EMEA
About
I've spent the last twenty years on the technical front line of cybersecurity — first as a hands-on consultant and engineer, then leading the teams that help the world's security leaders separate real risk from noise.
Today I lead Global Sales Engineering at Pentera, the company that pioneered automated, continuous penetration testing. My work is helping CISOs and their teams move from point-in-time assessments to continuous validation of their actual security posture — and translating that shift into language that resonates at board level, not just in the SOC.
Before Pentera, I built the same technical-to-executive bridge at Recorded Future (threat intelligence), Tenable and Qualys (vulnerability management), and nearly a decade at indevis, a German IT security consultancy, where I ran the northern-Germany regional office. Trained originally in bioinformatics at LMU Munich, and a graduate of K1 Investment Management's Advanced Management Program, I've always been drawn to translating dense technical systems into something people can act on — security has just turned out to be where I've spent my career doing it.
Track record
Leading the global SE organization for the world's first fully automated, agentless penetration testing platform.
Extended the technical pre-sales leadership remit from EMEA into APAC as the company scaled.
Took on regional SE leadership for EMEA, promoted to Senior Director within the same remit.
Joined as an individual-contributor Sales Engineer, promoted into regional leadership within a year.
Threat intelligence — helping enterprises operationalize threat data into their security programs.
Vulnerability management at enterprise scale.
Cloud-based security and compliance.
Nine years building technical consulting expertise, then leading the northern-Germany regional office.
Insights
For decades, "are we secure?" was answered once or twice a year, by a pentest report that was stale before the ink dried. That model made sense when infrastructure changed slowly. It doesn't anymore.
Cloud environments, identity sprawl, and constant code deployment mean your attack surface today isn't your attack surface next Tuesday. The organizations getting this right have stopped treating validation as a project and started treating it as a continuous process — automated, always-on, and integrated into how they prioritize remediation.
The hard part isn't the technology. It's the operating model change: security teams built around quarterly reporting cycles need to rethink how they consume continuous signal without drowning in it.
Most security leaders present risk the way they were trained to think about it: CVEs, exploitability scores, patch cadence. Most boards don't have the context to act on any of that.
What boards want is simpler and harder: what's our exposure, in business terms, and what are we doing about the things that matter most. That means translating technical findings into a small number of prioritized, well-evidenced statements — not a dashboard of severity scores.
The security leaders who get promoted into board-facing roles are usually the ones who've already been doing this translation work informally for years, inside their own organizations, before anyone gave them the title.
Offensive AI is getting real attention right now — funding rounds framed around "AI vs. AI" security, autonomous attack simulation, agentic red-teaming. That's not hype; the tooling is genuinely getting better at finding paths through defenses faster than manual testing ever could.
But the more interesting shift is on the defensive side: AI-assisted validation lets under-resourced security teams run continuous testing that used to require a large, specialized team. That's a democratizing force — mid-market companies can now validate their posture the way only the largest enterprises could a few years ago.
The organizations that will struggle aren't the ones without AI. They're the ones still running their security program on an annual cycle while both attackers and defenders around them move to continuous.