Product security for regulated medical software. Biomedical engineer turned security specialist - I turn STRIDE threat models into concrete, traceable security requirements and back them with SBOM-driven SCA, static analysis, and black-box dynamic testing.
Currently QA/RA & Security Specialist at Hermes Medical Solutions in Stockholm, working on secure SDLC for medical devices, FDA premarket cybersecurity and IEC 81001-5-1, AppSec, and the AI governance that increasingly wraps around them. Building toward product and application security engineering.
13 merged pull requests into 7 security and medical-imaging projects:
| Project | Merged | What |
|---|---|---|
| fo-dicom | 3 | DICOM parsing hardening (bounded decompression) |
| syft | 2 | SBOM generation |
| grype | 2 | Vulnerability matching correctness |
| fo-dicom.Codecs | 2 | JPEG/JPEG-2000 decoder crash fixes |
| DefectDojo | 2 | Vulnerability-management platform |
| presidio | 1 | PII detection |
| stereoscope | 1 | Container image analysis |
Open PRs under review at checkov (Terraform OIDC trust-policy checks), pydicom, cartography and purl2cpe.
- subvectors - cited, versioned conformance
vectors for CI/CD OIDC trust decisions: does subject S satisfy trust condition C,
and is C safe? Covers GitHub/GitLab issuers against AWS/Azure/GCP consumers.
On PyPI (
pip install subvectors) with the full corpus in the wheel. - subcheck - decodes and validates GitHub Actions
OIDC token claims against an expected-claims policy. A CI gate against trust-policy
drift, differentially tested against the pinned subvectors corpus.
On PyPI (
pip install subcheck) and usable as a GitHub Action. - portfolio-site - full-stack personal site (Vue 3 + TypeScript, FastAPI) with GitHub OAuth, analytics and an admin CMS.
- sysadmin-toolkit - Windows/Linux administration automation: maintenance, infrastructure setup, monitoring, DevOps.
- CompTIA Security+ (2026)


