Product Owner for Regulatory & Security Compliance and AI. I build the AI agents, dashboards, and traceability systems that collapse compliance work from months of paperwork into minutes of reviewable output — without cutting corners on ISO 21434, UN R155, China GB 44495, ISO 27001, ISO 42001 or the EU AI Act.
Product Owner für Regulatory & Security Compliance und KI. Ich baue die KI-Agenten, Dashboards und Traceability-Systeme, die Compliance-Arbeit von Monaten an Papierkram auf Minuten prüfbarer Ergebnisse verkürzen — ohne Kompromisse bei ISO 21434, UN R155, China GB 44495, ISO 27001, ISO 42001 oder dem EU AI Act.
Evidence lived in shared drives. Audit readiness meant a 6-week scramble before every review, pulling screenshots into Word.
I built real-time Splunk & trace systems turning SLAs, incidents and controls into live signals — not quarterly deliverables.
CSMS Coach proved an LLM can guide engineers through ISO 21434 work products, generating first-pass artefacts a reviewer can refine in minutes.
Agents that watch incidents, draft regulator reports, tailor CVs, score evidence — human-in-the-loop at every gate. Fast, accurate, auditable.
Nachweise lagen auf Netzlaufwerken. Auditbereitschaft hieß 6 Wochen Panik vor jedem Review — Screenshots in Word kopieren.
Ich habe Splunk-Dashboards und Trace-Systeme gebaut, die SLAs, Vorfälle und Kontrollen in Live-Signale verwandeln — statt in Quartalsberichte.
CSMS Coach zeigt: ein LLM kann Ingenieure durch ISO-21434-Work-Products führen und Erstentwürfe liefern, die in Minuten freigegeben werden.
Agenten, die Vorfälle beobachten, Meldungen entwerfen, Lebensläufe anpassen, Evidenzen bewerten — Mensch an jedem Gate. Schnell, genau, auditierbar.
A 10-clause demo of an on-premises ISO 27001:2022 ISMS document generator. Runs entirely on local LLMs via Ollama + ChromaDB RAG — no cloud, no API keys, your data never leaves the machine.
A guided AI assistant that walks trainees through generating cybersecurity work products for automotive components — step-by-step, aligned to the CSMS process. Built for MS Copilot; portable to any LLM. Actively extending it to cover the type-approval regulations that make CSMS mandatory: UN R155 and China GB 44495.
Security Compliance Engineer on VW's D³ project, a secure cloud-to-edge pipeline distributing encrypted diagnostic assets and firmware to independent automotive networks. Ran TARA risk analyses, tracked applicable regulations, and managed IT-security vendor transitions to stay aligned with UNECE R155/R156.
Supported a Volkswagen ADMT ISO 9001 quality-management audit by scripting an AI-assisted review of 400+ internal policies, mapping each to audit requirements for fast gap analysis.
Evaluated China GB/T automotive cybersecurity regulation across Volkswagen platforms with CARIAD — built end-to-end traceability, ran stakeholder communication, and coordinated homologation testing for regulatory alignment.
A Streamlit tool for AI-governance document work: ingests policy/compliance documents, builds a RAG index, cross-references requirements, and summarizes findings — keeps ISO 42001 and EU AI Act documentation reviewable.
Local desktop tool: scrape → AI-score → review → tailor CV → apply. Gemini rates each listing against your CV, outputs ATS-clean DOCX. 100% local, human-in-the-loop — no auto-submit.
A side-by-side breakdown of UN R155 and China's GB 44495-2024 — CSMS requirements, implementation timelines, and where the two regulations' technical test methods diverge, mapped against ISO/SAE 21434.
A practitioner-oriented walkthrough of the global regulations and standards shaping automotive cybersecurity — written for engineers moving from policy into day-to-day delivery.
Eine 10-Klausel-Demo eines On-Premises-ISMS-Dokumentgenerators für ISO 27001:2022. Läuft vollständig auf lokalen LLMs via Ollama + ChromaDB RAG — keine Cloud, keine API-Keys, Daten verlassen nie das Gerät.
Ein geführter KI-Assistent, der Anwender Schritt für Schritt durch die Erstellung von Cybersecurity-Work-Products für Automotive-Komponenten leitet. Gebaut für MS Copilot; auf jede LLM-Plattform übertragbar. Wird aktuell um die Typgenehmigungsvorschriften erweitert, die CSMS verpflichtend machen: UN R155 und China GB 44495.
Security Compliance Engineer im VW-D³-Projekt, einer sicheren Cloud-to-Edge-Pipeline für die Verteilung verschlüsselter Diagnose-Assets und Firmware an unabhängige Automotive-Netzwerke. Führte TARA-Risikoanalysen durch, verfolgtes geltende Vorschriften und koordinierte IT-Sicherheits-Vendor-Übergänge für die Einhaltung von UNECE R155/R156.
Unterstützte ein Volkswagen-ADMT-Audit zur ISO 9001 Qualitätsmanagementsystem durch die Automatisierung einer KI-gestützten Überprüfung von 400+ internen Richtlinien, mit Zuordnung zu Audit-Anforderungen für schnelle Lücken-Analyse.
Evaluierte die chinesische GB/T-Automotive-Cybersecurity-Regulierung auf Volkswagen-Plattformen mit CARIAD — baute durchgehende Traceability, führte Stakeholder-Kommunikation durch und koordinierte Homologations-Tests für regulatorische Angleichung.
Ein Streamlit-Tool für KI-Governance-Dokumente: erfasst Richtlinien- und Compliance-Dokumente, baut einen RAG-Index, referenziert Anforderungen dokumentübergreifend — hält ISO-42001- und EU-AI-Act-Dokumentation prüfbar.
Lokales Desktop-Tool: Scraping → KI-Bewertung → Review → CV-Anpassung → Bewerbung. Gemini bewertet jede Stelle gegen deinen Lebenslauf, liefert ATS-saubere DOCX. 100 % lokal, Mensch an jedem Gate.
Ein direkter Vergleich von UN R155 und Chinas GB 44495-2024 — CSMS-Anforderungen, Umsetzungsfristen und wo sich die technischen Testmethoden beider Regulierungen unterscheiden, abgeglichen mit ISO/SAE 21434.
Praxisorientierter Überblick zu den globalen Regulierungen und Standards der Automotive Cybersecurity — geschrieben für Ingenieure, die von Policy in den täglichen Delivery-Alltag wechseln.
NIST, ISO 21434, ISO 27001, UN R155, China GB 44495. Traceability spines and real-time dashboards that make continuous audit readiness a default, not a scramble.
AI-driven compliance tooling that streamlines complex work products and stays aligned with ISO 42001 and the EU AI Act — documentation that writes itself, reviewed by humans.
Release planning, change management, and multi-level backlog alignment for global platforms. Governance ships alongside the feature, not six sprints later.
ASPICE-grade backlog management for mission-critical automotive systems. Stakeholders and engineers work from the same linked, auditable record.
NIST, ISO 21434, ISO 27001, UN R155, China GB 44495. Traceability-Rückgrat und Echtzeit-Dashboards, die kontinuierliche Auditbereitschaft zum Standard machen — nicht zum Stressfall.
KI-getriebenes Compliance-Tooling, das komplexe Work Products schlank macht und sich an ISO 42001 und dem EU AI Act ausrichtet — Dokumentation, die sich selbst schreibt, von Menschen geprüft.
Release-Planung, Change Management und mehrschichtige Backlog-Abstimmung für globale Plattformen. Governance geht gemeinsam mit dem Feature in Produktion — nicht sechs Sprints später.
ASPICE-Backlog-Management für sicherheitskritische Automotive-Systeme. Stakeholder und Entwickler arbeiten auf demselben verlinkten, auditierbaren Datenbestand.
Statistical periodicals & regional economic reports for Bursa and Eskişehir, 2009–2015.
Regression analysis, estimation, and applied case studies.
Earlier academic work and essays.
Statistische Periodika und regionale Wirtschaftsberichte für Bursa und Eskişehir, 2009–2015.
Regressionsanalyse, Schätzung und angewandte Fallstudien.
Frühere akademische Arbeiten und Essays.
Got a compliance program that should ship like a product? Let's build it.
Ein Compliance-Programm, das wie ein Produkt ausgeliefert werden soll? Lass uns bauen.