Hi, I'm Scott!
I'm a software developer from the United States currently living in Germany. I studied computer science at the University of Minnesota with an emphasis in security. I enjoy writing code, writing technical articles, learning new things, and solving problems.
Over a decade of experience building APIs and microservices with Golang, PHP, and Java in large-scale event-driven systems. Many years of experience in backend development of websites in PHP and Go as well as frontend development with HTML/JavaScript/CSS.
Experience developing responsive websites for large media companies and for small personal web pages.
I have a university degree in computer science with an emphasis in security and many years of practice in penetration testing, cyber incident response, forensic investigations, and application security.
Here is a short list of my major accomplishments

Developed new features for Oracle's Retail Invoice Matching Software and developed. Performed static code analysis with Fortify and implemented extensive security measures and patches. Worked with Java Development Frameworks, e.g. Spring and Struts, and JSP to develop web applications.

Launched a self-owned and operated website called Halls of Valhalla. The site expanded over time to eventually include news, articles, code snippets, a forum, education challenges, and more. All backend development, frontend development, design, and system administration is handled by myself.

Backend and frontend development for websites for idea contests in PHP, JavaScript, and HTML/CSS. Performed penetration tests on Hyve's various platforms to ensure they were up to standards. Proofread English texts. Gave presentations on security and testing (i.e. unit and integration tests).

Backend (primarily PHP) for one of Germany's largest app advisors. Also did backend development for one of the largest price comparison sites in the country.
Backend (primarily PHP) and frontend (HTML, JavaScript, CSS) development for the largest download portal in Germany. Completely rebuilt the downloads section, both backend and frontend. Additionally worked on Chip's downloader application for the desktop. Performed security reviews and implemented numerous fixes and standards for frontend security issues.

Created microservices and APIs in Go using an eventsourcing architecture and asynchronous techniques for Sixt's CRM components. Worked with focus on concurrency, performance, and test-driven development.
Architected and implemented the backend (in Golang microservices) for Sixt's Fastlane product, allowing customers to select their vehicle, start their rental, and unlock the car using the Sixt app. Served as the architect for the Reservation team working to modernize the product.
Architected and implemented the backend (in Golang microservices) for Sixt's new third party API, allowing external partners to integrate with Sixt's rental products. Regularly represented Sixt towards external business partners, serving as the technical contact person. Served as the technical lead and architect for the digital checkout initiative. Helped to drive a new security community of practice while designing and developing frameworks for common security patterns such as rate limiting. Together with other tech leads, developed organization-wide backend NFRs.
Architect for multiple development teams. Led a new application security team, designing security best practices, performing vendor evaluations, providing frameworks, and performing security consultations and penetration tests. Designed and built in-house automated security scanners to proactively and automatically detect common security issues such as insufficient access controls and hardcoded credentials.
Independently deliver and collaborate on high-impact, complex engineering efforts while improving and maintaining the software ecosystem. Actively mentor engineers and provide deep technical guidance to Directors, VPs, and the CTO through design and implementation work. Create and drive application and product security initiatives, including secure code reviews, threat modeling, vulnerability analysis, and remediation; proactively identify and mitigate risks, and participate in security incident detection and response. Implement, scale, and operate application and product security frameworks and tooling, integrating security controls into development workflows, CI/CD pipelines, and runtime environments.
Here is some information about a few of my larger projects
IT Website
Command-Line Security Tool
A very easy-to-use library for building a custom brute-force requester for QA purposes
Networking Information Website
Fiction Author Website
An API surface intelligence tool that reconstructs real-world endpoints from logs, archives, and specs and generates high-quality test inputs for security analysis
Fiction Author Website
Website for the AI HEART Project
Send me an email at [email protected]