Find vulnerabilities, assess them, fix them

Security testing has been part of my work since 2011. Thirteen years in software delivery taught me how a finding actually makes it into a release.

Federal Diploma, Cyber Security OSCP+ BSCP CISSP Associate
Alexander van der Berg, information security in Zurich
Alexander van der Berg at work

I'm Alexander van der Berg

Security testing has been part of my work since 2011. As a tester I found cross-site scripting and an SQL-based denial of service in production web applications, later verified PSD2 compliance at an online bank, and assessed and prioritised the findings of an external penetration test.

Between 2022 and 2026 I formalised that practice: the Federal Diploma of Higher Education as a Cyber Security Specialist, whose competence areas include vulnerability and patch management as well as security assessment of ICT infrastructure, together with OSCP+ and BSCP as practical, proctored exams that require exploiting vulnerabilities in provided lab environments.

Thirteen years in agile development teams, in my later positions with accountability for release sign-off. Carrying that responsibility teaches you why one finding gets fixed and another sits in the backlog, and how to change that. Raised in Hamburg, I have lived in Zurich since 2022 and speak fluent German, English and Spanish.

Qualifications

  • Cyber Security Specialist, Federal Diploma of Higher Education (2023)
  • OffSec Certified Professional+ (OSCP+, 2025)
  • Burp Suite Certified Practitioner (BSCP, 2024)
  • OffSec Kali Linux Certified Professional (KLCP, 2024)
  • ISC2 CISSP Associate (2024)
  • CompTIA Security+ (2023)
  • ISTQB Certified Tester (CTFL)
  • Certified ScrumMaster (CSM) · Certified Scrum Product Owner (CSPO)
  • Certified Professional for Requirements Engineering (CPRE)
  • Diploma in Business Informatics (University of Applied Sciences)

My focus areas

A finding is only done when it is fixed. The work in between is what interests me: assessing, prioritising, staying on it.

Vulnerability and patch management

Assessing criticality, prioritising, agreeing treatment with the responsible teams and following remediation through. A competence area of the Federal Diploma.

Web application security testing

Cross-site scripting, injection and related classes. Found in production applications and the fix verified on retest. Certified by the Burp Suite Certified Practitioner.

System security assessment

Clarifying scope and objectives, selecting tools, running tests and reporting findings so they can be acted on. Demonstrated in practice through OSCP+.

Decisions under risk

Years of accountability for final release sign-off: go or no-go, under deadline pressure, owning the consequences. Plus risk-based prioritisation of defects and incidents.

Regulatory work and evidence

Verification of PSD2 compliance in a banking context and testing of a GDPR-compliant tracking implementation. I know the difference between a requirement and the evidence for it.

Analysis and secure SDLC

Working through log files and event records, with further study in Splunk, Autopsy and Sysmon. Plus code review and running CI/CD pipelines.

What sets me apart

Findings and fixes

I can assess a vulnerability and I also know how a development team actually gets a fix into a release. Usually you only find one of the two.

My own findings and external reports

Cross-site scripting and an SQL-based denial of service found myself, during release approval before going live, with the fixes verified afterwards. Equally, assessing and prioritising the findings of an external penetration test.

Regulated settings

PSD2 at an online bank, GDPR at a digital provider. I know the difference between a requirement and the evidence for it.

Calm under pressure

Dependable in difficult situations and with overdue releases under time pressure, and I keep a clear head.

A Swiss federal qualification

Cyber Security Specialist with a Federal Diploma of Higher Education, with vulnerability and patch management as a competence area.

Multilingual

German as a native language, fluent English and Spanish.

Career

Thirteen years of software delivery in agile product teams, most recently at a regulated online bank. In the later positions I was accountable for release sign-off. That teaches you quickly which findings block a go-live and which can wait. Security was part of the ongoing work. Since 2022 my focus has moved fully to information security.

Career transition · 2022–2026

Information security

  • Cyber Security Specialist, Federal Diploma of Higher Education (2023): vulnerability and patch management, security assessment of ICT infrastructure, threat intelligence, security incidents, digital forensics
  • OSCP+ (2025) and BSCP (2024): practical, proctored exams requiring the exploitation of vulnerabilities in provided lab environments
  • Further study of incident response and Windows forensics: Splunk, Autopsy, analysis of Sysmon and Windows event logs
  • Moved from Berlin to Zurich (2022)

Banking · 2019–2021

Online bank for the self-employed

  • Verification of PSD2 compliance
  • Assessment and prioritisation of findings from an external penetration test
  • Security testing as part of test design
  • Accountability for final release sign-off
  • Mentoring of junior engineers

Weather service & digital media · 2018–2021

Web and mobile products with tracking

  • Testing of the GDPR-compliant tracking implementation
  • Accountability for final release sign-off
  • Testing of websites, Android and iOS apps before go-live

Big data / market research · 2015–2018

Big data analytics platform

  • Configuration and administration of the CI/CD pipeline
  • Code review of automated tests
  • Test design, testing and test automation of web applications

Media & e-commerce · 2013–2015

Mobile apps & payment systems

  • Security testing of a new comment feature: cross-site scripting found and the fix verified on retest
  • Test design and testing of online payment systems
  • Testing and test automation for Android and iOS apps and mobile websites

Further positions since 2009, including the first security finding in 2011: cross-site scripting and an SQL-based denial of service at a photo printing provider. Full career history on LinkedIn →

From employment references

Extracts from written references issued by former employers, translated from the German originals. The formal register is a convention of the Swiss and German Arbeitszeugnis.

“Mr van der Berg works with absolute reliability even in difficult situations and under time pressure, maintains a clear head throughout and always meets deadlines.”

Head of Development Operations

“We came to know Mr van der Berg as a very reliable professional. He always completed the tasks assigned to him to our complete satisfaction.”

Managing Director

“Mr van der Berg possesses extensive and broad expertise across all areas of software QA, complemented by an excellent knowledge of agile development processes.”

IT Manager

“Mr van der Berg has extensive specialist knowledge, a very focused and prudent approach to work, and a high degree of independence.”

Commercial Director

Let's talk

Whether it is an open role, a question about my profile, or a professional conversation: I would be glad to hear from you.

Open to new roles in information security in the Zurich area.

What interests me most is vulnerability management and security assessment, alongside business continuity and supplier assurance. My concern in all of it is the fix, not the report.

* Required fields. I typically respond within 48 hours.