Application security specialist · Bergen, Norway

Application Security & Secure Software Architecture

I help engineering teams design secure APIs, manage software-supply-chain risk, implement practical DevSecOps controls, and build secure cloud applications using Rust, Python, React and Azure.

Security capabilities

Security that engineering teams can implement and verify

Secure architecture and threat modelling

Identify assets, trust boundaries, abuse cases and security controls before implementation. Translate threats into architecture decisions teams can act on.

STRIDE · attack paths · trust boundaries · security ADRs

API security, OAuth 2.0, OIDC and Entra ID

Design authentication and authorization for browser, service-to-service, Power Platform and partner integrations without confusing identity with access control.

OAuth 2.0 · OIDC · Microsoft Entra ID · APIM · Zero Trust

Secure SDLC and security requirements

Make security part of planning, design, pull requests, delivery and operations through testable requirements and proportionate assurance.

OWASP ASVS · abuse cases · acceptance criteria · security gates

Software supply-chain security

Connect dependency and SBOM findings to deployed services, runtime exposure, ownership and explicit remediation decisions.

CycloneDX · Dependency-Track · provenance · CI/CD hardening

Security-focused code review

Review authorization, input handling, data access, file processing, secrets, error paths and dependency changes in modern application stacks.

Rust · Python/FastAPI · React/Next.js · PostgreSQL · MS SQL

Cloud and platform security

Design practical cloud controls around identity, private connectivity, secrets, observability, workload isolation and incident readiness.

Azure · Key Vault · WAF · private endpoints · security telemetry

AI-assisted development security

Establish boundaries for coding agents and AI-enabled applications, including tool permissions, data exposure, prompt injection and human review.

least privilege · tool isolation · audit trails · review policy

Verification standard

Beyond awareness checklists

My application-security verification work is grounded in the OWASP Application Security Verification Standard. ASVS turns security expectations into testable requirements for web applications and APIs. It supports clearer scope, stronger engineering acceptance criteria and evidence-based assurance.

The OWASP Top 10 is valuable for awareness. ASVS is the more useful foundation when a team needs to specify what must be secure and verify whether the controls work.

Working method

From business risk to engineering evidence

01

Understand

Clarify the system, business constraints, sensitive assets, actors and realistic threat scenarios.

02

Design

Select proportional controls and document decisions, ownership, trade-offs and verification criteria.

03

Verify

Use ASVS-aligned requirements, automated checks, focused testing and evidence-based review.

04

Improve

Turn findings, incidents and dependency intelligence into owned engineering work and reusable controls.

Local and international

Application security expertise in Norway

Based in Bergen, I combine software engineering, technical leadership and academic research to make security decisions understandable and actionable across product, development and platform teams.

Applikasjonssikkerhet i Norge

Sikker programvarearkitektur i Bergen

Jeg hjelper utviklingsteam med sikker API-arkitektur, trusselmodellering, programvareforsyningskjeder, DevSecOps og praktiske sikkerhetskrav for moderne skybaserte løsninger.

Secure systems are designed, verified and improved

Need an engineering-led security perspective?

Start a conversation