I'm a cybersecurity practitioner working at the intersection of critical infrastructure operations, regulatory compliance, and executive-level security governance. As Security Officer at a Dutch passive fiber network operator subject to NIS2, my day-to-day work covers the exact responsibilities that frameworks like CCISO are built around: developing enterprise security policies from the ground up, managing third-party and supplier risk, aligning security strategy with business objectives, and translating technical risk into language the board can act on.
My background spans both deep technical work and strategic security governance. On the technical side, I've spent years administering enterprise systems including Microsoft 365, Azure, SQL Server, and Linux infrastructure — the kind of foundation that lets me speak to security from operations all the way up to strategy. On the governance side, I'm actively involved in NIS2 implementation, ISO 27001 alignment, GDPR/AVG compliance, supplier risk management, and building privacy-preserving AI workflows using tools like Microsoft Presidio.
What I bring to my courses is the practitioner's perspective: not just the textbook answer, but the executive reasoning behind it. The CCISO exam doesn't reward memorization — it tests how you'd handle real trade-offs as a security leader. My teaching style focuses on the "why" behind each domain so you can answer questions you've never seen before.
When I'm not working on enterprise security, you'll find me doing application security research on the Intigriti bug bounty platform, with a focus on mobile application testing. I believe the best security leaders never lose touch with how attackers actually think.