Stanislaus Stelle

Security Consultant

Stanislaus Stelle
Monheim am Rhein, Germany

Experience

Dec 2023 - Present
1 year 5 months

Security Consultant

Rohde & Schwarz AG

Work on FPGA enhanced network encryption device with secure boot, TPM2.0 and smart card integration for BSI approved usage with post quantum cryptography

Linux driver development and audits

Collaboration with GitLab, Gerrit, Confluence and Jira

C, C++, secure boot

Jan 2022 - Dec 2023
1 year

Security Consultant

Miele & Cie. KG

Analysis and review of existing processes

Threat modeling of processes

Threat analysis and correction measures

Design, implement and rollout PKI

Secure boot, Bluetooth LE

Dec 2022 - Jan 2023
2 months

Security Consultant

SICK AG

Analysis and review of existing code

Present plan to update architecture to state of the art security mechanics

C, C++, secure boot

Jan 2021 - Nov 2022
11 months

Security Consultant

Telekom AG

Security analysis of white labeled and Yocto based router software based on RDK

Secure boot on Broadcom chipsets based on Broadcom SDK

Code review and reporting to management

Planning and implementation of automated security tests in GitLab

PKI handling with HSMs and PKCS#11

C, C++, Yocto, secure boot

Aug 2021 - Dec 2021
5 months

Security Consultant and C++ Developer

IBM GmbH

Microservice development in C++ for „elektronische Patientenakte“ by Gematik

Kubernetes deployments

Security based development to fulfill Gematik requirements

Low level OpenSSL development

Utimaco HSM handling

C, C++, Kubernetes, Docker

May 2021 - Dec 2021
8 months

Security Consultant

Erweka GmbH

Operating system port from Ubuntu to Yocto

Secure boot on iMX8MM

Penetration testing of secure boot

PKI setup

C, C++, Yocto, secure boot

May 2021 - Jul 2021
3 months

C++ Developer

Rohde & Schwarz GmbH

Microservices for Docker cluster

High throughput Kafka setup

Distributed systems

C, C++, conan, Kafka

Jan 2020 - Mar 2021
3 months

Security Consultant

Resado GmbH

HSM development based on Yocto

Development of update strategies for high security embedded devices

Penetration test planning for FIPS certification

C, C++, Yocto, Bitbake and Bash

Jul 2017 - Mar 2021
3 years 9 months

Security Consultant

Telekom AG

Security lead and development support for the smart speaker

SoC analysis and vulnerability research

Planning and setup of HSM based PKI (ncipher)

Documentation of processes

Design and implementation of secure boot chain

Design of Linux access control and enforcement of separation of concerns

Code reviews in international teams

Amazon Alexa device certification security compliance

Coordination, planning and review of OEM deliveries

Hardware security integration of the CAAM from NXP

C, C++, Python, Ghidra, Yocto, Bitbake and Bash

Apr 2015 - Sep 2016
1 year 6 months

Lead Mobile Developer and Security Consultant

Seal One AG

Planned, designed and implemented the Seal One apps for Android and iOS

Designed the Bluetooth Low Energy protocol for fast data transmission in use

Analyzed Bluetooth Low Energy traffic to determine proper functionality on low level

Microcontroller development on secure tokens

IDA Pro, C, Java, ObjC, HTML and Javascript

Apr 2014 - Mar 2015
1 year

Lead Mobile Developer and Security Consultant

nextmarkets GmbH

Consulting and training on security matters regarding real time data communication

Implementing and hardening of the nextmarkets mobile app for Android and iOS

Consulting on the infrastructure in place and performing penetration tests

Java, ObjC, HTML and Javascript

Apr 2014 - Mar 2015
1 year

Lead Mobile Developer and Security Consultant

stapp GmbH

Prototyped and implemented a fashion and lifestyle app for Android and iOS

Consulting on the infrastructure in place and performing penetration tests

Java, ObjC, HTML and Javascript

Sep 2013 - Dec 2014
4 months

Lead Android Developer and Security Consultant

Seal One AG

Consulting on secure protocols for authorization

Hardening for a variety of brands

Development of the Best Sign Android component for Postbank

Java

Mar 2013 - Mar 2014
1 year 1 month

Lead Android Developer

Telekom AG

Implementing features and resolving bugs for the Tolino eReader

Maintaining a white label solution for 7 partners on the Google Play store

Integrating and upstreaming of the Readium SDK

Coordinating and leading a near shore team in Romania

C++ and Java

May 2012 - Jan 2013
9 months

Master Thesis

CASED

Developed CrowdApp, an Android application for multi hop tethering based on the Batman mesh protocol

Operated an Android smartphone on promiscuous mode and forwarded TCP packets based on digital signatures

Designed and implemented an anonymous multi hop tethering community platform which can be traced in case of misuse

Published CrowdApp - Secure Mobile Ad-Hoc Resource Sharing on Android: Sharing internet connections mobile with multi hop technology

C, Bash and Java

Feb 2012 - Apr 2012
3 months

Working Student

CASED

Android OS penetration testing

Broadcom Linux driver analysis

mdk3 toolkit extension for IEEE 802.11 management frame injection

C

Oct 2010 - Jan 2012
1 year 4 months

Working Student

CASED

Development of a symmetric key material deployment tool for the Contiki operating system

Planning, designing and implementing of a Java based GUI for symmetric key generation

ZigBee and WiFi communication implementation on low power IoT devices

Presenting the findings and research results at ARES 2012

C and Java

Mar 2010 - May 2010
3 months

Bachelor Thesis

SAP AG

Concept, analysis and development of UI/UX operations

Invent and prototype a new drag&drop concept for group activities on wall sized displays

Perform A/B testing with leading interaction paradigms and own prototype as well as scientific evaluation of findings

C#

Jun 2009 - Sep 2009
4 months

Research Internship with EU Research Project Texo

SAP AG

Fraud assurance in service oriented business applications

Contributions to the TEXO research project Maestro

Ensured segregation of duty for the participating entities (four eye principle in sensitive tasks)

Java

Jan 2009 - Mar 2009
3 months

Research Internship with Linux Lab

SAP AG

Network monitoring with Nagios 3

Aggregating server information with phpEquimon to ease administration

Development of the open source Nagios SAP CCMS plugin

C, Bash, XML and PHP

Aug 2008 - Sep 2008
2 months

Research Internship with Defense

SAP AG

Analysis and prototyping of joint common operational picture for NATO

Close cooperation with NATO‘s NC3O research facility

Aggregating data from SOAP based web services

Java, ABAP and SOA paradigm

Oct 2007 - Dec 2008
3 months

Research Internship with Deployment

SAP AG

Writing tests for J2EE based automated SAP ERP deployment server

Extending functionality and optimizing hotspots

J2EE and Perforce

Summary

Before finishing his studies, Mr Stelle was involved in numerous international client projects while working for SAP. After graduating from TU Darmstadt with a Master in IT Security and a strong focus on Mobile Security, he was working as an IT freelancer since 2013, refining his expertise in a broad field ranging from mobile development, protocol design, hardening schemes for IoT devices and servers alike and client development work. All the while covering either the role of a Security Architect, Technical Lead, System Architect or Lead Developer. Clients trust him to finish the job while using up to date technologies and methodologies and coordinating work with internal and external work forces.

Languages

German
Native
Russian
Native
English
Advanced
French
Elementary

Education

Oct 2010 - Jun 2013

TU Darmstadt

M.Sc. · IT Security · Darmstadt, Germany

Oct 2007 - Jun 2010

DHBW

B.Sc. · Applied IT · Karlsruhe, Germany

Certifications & licenses

CEH

CISSP

Machine Learning