Principal Engineer | Application Security | Agentic Engineering
I am a product-minded software engineer and security enthusiast based in Berlin, Germany. My work focuses on the intersection of application security, agentic engineering, usability, and automation. I'm passionate about clean code, interdisciplinary software development, and engineering leadership.
An identity broker designed for AI agents, featuring OAuth2 delegation and consent management.
Why it matters: As AI agents become more autonomous, securely managing their identities and permissions is critical. This project bridges the gap by providing robust OAuth2 delegation and consent management tailored specifically for agentic workflows.
As an Application Security professional, I actively research and responsibly disclose vulnerabilities to help secure the open-source ecosystem.
| Advisory ID / CVE | Target | Vulnerability / Details | Reference |
|---|---|---|---|
| GHSA-ff5v-67qw-84f5 | zalando-incubator/agentic-identity-broker |
Authorization codes never expire | Read Advisory |
| GHSA-55pc-c3c2-739c | zalando/skipper |
OAuth grant cookie cross-host suffix collisions | Read Advisory |
- AppSec & Identities: Exploring modern application security architectures and the evolving landscape of identity management.
- Agentic Engineering: Building frameworks and tools that enable secure and usable autonomous AI agent operations.
- Writing: I share my thoughts on security, engineering, and tech on my blog: Brennenstuhl on Security.
- Offline: When I'm not in front of a screen, you'll find me exploring Nordic nature, on a rainy hike, cycling, or enjoying a good cup of coffee. (I also document my hikes at Rucksackrebellen).