Vulnerability and patch management
Assessing criticality, prioritising, agreeing treatment with the responsible teams and following remediation through. A competence area of the Federal Diploma.
Information Security
Security testing has been part of my work since 2011. Thirteen years in software delivery taught me how a finding actually makes it into a release.
About me
Security testing has been part of my work since 2011. As a tester I found cross-site scripting and an SQL-based denial of service in production web applications, later verified PSD2 compliance at an online bank, and assessed and prioritised the findings of an external penetration test.
Between 2022 and 2026 I formalised that practice: the Federal Diploma of Higher Education as a Cyber Security Specialist, whose competence areas include vulnerability and patch management as well as security assessment of ICT infrastructure, together with OSCP+ and BSCP as practical, proctored exams that require exploiting vulnerabilities in provided lab environments.
Thirteen years in agile development teams, in my later positions with accountability for release sign-off. Carrying that responsibility teaches you why one finding gets fixed and another sits in the backlog, and how to change that. Raised in Hamburg, I have lived in Zurich since 2022 and speak fluent German, English and Spanish.
Expertise
A finding is only done when it is fixed. The work in between is what interests me: assessing, prioritising, staying on it.
Assessing criticality, prioritising, agreeing treatment with the responsible teams and following remediation through. A competence area of the Federal Diploma.
Cross-site scripting, injection and related classes. Found in production applications and the fix verified on retest. Certified by the Burp Suite Certified Practitioner.
Clarifying scope and objectives, selecting tools, running tests and reporting findings so they can be acted on. Demonstrated in practice through OSCP+.
Years of accountability for final release sign-off: go or no-go, under deadline pressure, owning the consequences. Plus risk-based prioritisation of defects and incidents.
Verification of PSD2 compliance in a banking context and testing of a GDPR-compliant tracking implementation. I know the difference between a requirement and the evidence for it.
Working through log files and event records, with further study in Splunk, Autopsy and Sysmon. Plus code review and running CI/CD pipelines.
Why me?
I can assess a vulnerability and I also know how a development team actually gets a fix into a release. Usually you only find one of the two.
Cross-site scripting and an SQL-based denial of service found myself, during release approval before going live, with the fixes verified afterwards. Equally, assessing and prioritising the findings of an external penetration test.
PSD2 at an online bank, GDPR at a digital provider. I know the difference between a requirement and the evidence for it.
Dependable in difficult situations and with overdue releases under time pressure, and I keep a clear head.
Cyber Security Specialist with a Federal Diploma of Higher Education, with vulnerability and patch management as a competence area.
German as a native language, fluent English and Spanish.
Experience
Thirteen years of software delivery in agile product teams, most recently at a regulated online bank. In the later positions I was accountable for release sign-off. That teaches you quickly which findings block a go-live and which can wait. Security was part of the ongoing work. Since 2022 my focus has moved fully to information security.
Career transition · 2022–2026
Banking · 2019–2021
Weather service & digital media · 2018–2021
Big data / market research · 2015–2018
Media & e-commerce · 2013–2015
Further positions since 2009, including the first security finding in 2011: cross-site scripting and an SQL-based denial of service at a photo printing provider. Full career history on LinkedIn →
References
Extracts from written references issued by former employers, translated from the German originals. The formal register is a convention of the Swiss and German Arbeitszeugnis.
“Mr van der Berg works with absolute reliability even in difficult situations and under time pressure, maintains a clear head throughout and always meets deadlines.”
“We came to know Mr van der Berg as a very reliable professional. He always completed the tasks assigned to him to our complete satisfaction.”
“Mr van der Berg possesses extensive and broad expertise across all areas of software QA, complemented by an excellent knowledge of agile development processes.”
“Mr van der Berg has extensive specialist knowledge, a very focused and prudent approach to work, and a high degree of independence.”
Contact
Whether it is an open role, a question about my profile, or a professional conversation: I would be glad to hear from you.
Open to new roles in information security in the Zurich area.
What interests me most is vulnerability management and security assessment, alongside business continuity and supplier assurance. My concern in all of it is the fix, not the report.