>~/moritz

_

Security engineer based in Lindau, Germany. I build and operate production-grade applications with security built in from day one. Master's in Computer Science, experience in fintech and banking.

Moritz Nentwig - Software Developer and Security Engineer

Skills & Expertise

Development

JavaPythonTypescriptSQLReactNext.jsAngularDocker/Kubernetes & MicroservicesCI/CDGitAI DevelopmentVibe Coding

Enterprise Architecture

System Design & IntegrationSecurity ArchitectureZero Trust ArchitectureDefense in DepthData Protection StrategiesDORA ComplianceEnterprise Architecture Management

Security Engineering

Secure Software DevelopmentOWASP Top 10Cryptography and EncryptionApplication Security, API SecurityIdentity & Access Management (IAM)Vulnerability Assessment & Penetration Testing

Security Operations

Incident ResponseEndpoint Detection & ResponseThreat IntelligenceFirewall & Network SecurityVulnerability ScanningIntrusion Detection

Experience & Education

Software Engineer

Starting

LEAPTER GmbH · Germany

  • Full-stack development of an AI-native platform for code visualization and validation
  • Building and integrating AI agent workflows for transparent, executable blueprints
  • Developing features that transform AI-generated code into visual, verifiable models
  • End-to-end feature development from concept to production in a fast-paced startup environment
  • Collaborating with founders and design partners to shape product direction and architecture

Security Architecture Trainee

-

Liechtensteinische Landesbank AG · Vaduz, Liechtenstein

  • Developed security concepts, conducted portfolio assessments, and provided security consulting for projects
  • Developed and maintained CAM, ICT reference architecture, IT security strategy, and IT demand processes
  • Conducted analyses on SIEM, PAM, HSM, and encryption for internal policy creation
  • Created a Container Security Governance framework
  • Independently managed various IT demand requests
  • Participated in the LLB Young Talent Program

Network & Security Trainee

-

Liechtensteinische Landesbank AG · Vaduz, Liechtenstein

  • Analysis, handling and remediation of security incidents
  • Development of a container security policy
  • Implementation and automation of threat intelligence
  • Automation of various standard processes using Ansible and Python
  • Design and deployment of a new remote access client
  • Contribution to a company-wide Zero Trust Network Access initiative
  • Maintenance, standardization and further development of the firewall and proxy infrastructure
  • Participation in a "Young Talents" initiative to improve the online banking presence

Master Thesis Student

-

ACTICO GmbH · Immenstaad am Bodensee, Germany

  • Creating a concept for a zero trust architecture in container-based microservice application

Software Development Working Student

-

ACTICO GmbH · Immenstaad am Bodensee, Germany

  • Independent implementation of features and bug fixes in Java and Angular
  • Designing databases structures and migrating existing data
  • Supporting the testing process, including executing performance tests and implementing automated tests
  • Active participation in the agile Scrum process
  • Creating user and developer documentation

IT Security Analyst Internship

-

MOGWAI Labs GmbH · Ulm, Germany

  • Vulnerability analysis of web applications
  • Development of scripts and tools to exploit vulnerabilities (Java, Python, .NET)
  • OCR recognition
  • Penetration testing
  • Cloud software development
  • Android app reversing

M.Sc. Computer Science

-

University of Applied Sciences Weingarten · Weingarten, Germany

  • Specialization in IT Security
  • Masters Thesis: An Approach for Zero Trust in Container-Based Microservice Applications
  • GPA: 1.8

B.Sc. Computer Science

-

University of Applied Sciences Ulm · Ulm, Germany

  • Focus on IT Security and Business Administration
  • Bachelor Thesis: Establishment of a certifiable emergency management system at THU
  • GPA: 1.8

Side Projects

A selection of applications and security-focused tools built to solve real-world problems

TypeRush

2025

A fast-paced typing contest web app with randomized texts, multiple time modes, and a local leaderboard.

ReactVite
Local only
Leaderboard
English / German support
Random Word API

Youtube-2-AppleMusic

2025

A Chrome extension for macOS that allows you to open YouTube videos directly in Apple Music with one click.

JavascriptManifest v3
Title cleanup
Apple Music
Youtube

Work-Tracker

2025

Work Tracker is a modern web app for tracking time spent on projects. It features a timer, manual entry, statistics visualization, and project organization. Data storage uses a dual-layer approach: localStorage for offline-first UX + Supabase for persistent storage and multi-device sync.

ReactTypescriptTailwindSupabaseVercel
Multi-Device Sync
Authentication
Offline Support

PoC Zero Trust in Container based Applications

2023 - 2024

Proof of Concept of my master thesis about Zero Trust in container based Microservice Applications.

JavaSpring BootDocker
PKI
IAM
Client Posture

Encryptio

2023

Encrypt strings, decrypt files and determine encryption algorithm of encrypted files.

Python
Determine encryption algorithm

Aktiv App

2021

The app connects local organizations with their community: associations, public institutions, non-profits, and cultural providers can present themselves and their activities while actively engaging residents in shaping local community life. Following an initial testing phase, the customer assumes ownership and ongoing development of the platform.

DockerNodeJSFlutterNginx
Productive App

CarrierTracking

2021

Digital load carrier tracking solution using 3D modeling (Unity 3D), QR code positioning, and real-time synchronization between physical warehouse layouts and digital twins. Eliminates discrepancies between 2D planning and actual production floor configurations.

C#Unity
Productive App

Connect

I'm always interested in challenging security problems and new collaborations. Whether it's consulting, freelance work, or just talking shop about Zero Trust architectures — drop me a line.