CYBER KILL CHAIN :: CAREER TIMELINE

Fabrice Ryba is an IT-Security Engineer at ausecus GmbH in Berlin, Germany, where he works on product development for KRITIS Defender — building WebUI, CI/CD, data-processing and threat intelligence features in Python. His career spans the full defensive lifecycle: SOC build-out and SIEM/SOAR engineering, threat hunting, vulnerability management, security consulting and compliance auditing. He holds an M.Sc. in Computer Science from Freie Universität Berlin. Outside of work, he keeps his offensive-security skills sharp on TryHackMe and HackTheBox.

Reconnaissance

2003 – 2017

Education — Freie Universität Berlin — Berlin

Foundations — gathering the intel and groundwork before the operation begins.

  • > Abitur, Marie-Curie-Oberschule, Berlin (08/2003 – 07/2010)
  • > Zivildienst (civilian service), Sankt Gertrauden-Krankenhaus, Berlin (10/2010 – 03/2011)
  • > B.Sc. Computer Science, Freie Universität Berlin (04/2011 – 09/2014), grade 2.6
  • > Bachelor's thesis: "Implementing and Analysing sFlow measurements at an IXP"
  • > M.Sc. Computer Science, Freie Universität Berlin (10/2014 – 07/2017), grade 2.2
  • > Cyber Security Summer School (C3S), Tallinn
  • > 24th USENIX Security Symposium, Washington — co-authored DDoS research
  • > Internet Engineering Task Force 96, Berlin
  • > Master's thesis: "Is there only trash in the bin? Analyzing privacy conflicts in Pastebin"
ResearchNetworkingPrivacy

Weaponization

Sep 2017 – Sep 2018

Cyber Security Consultant — Mazars GmbH — Berlin

Building the capability — assembling the tooling and compliance groundwork.

  • > Design, implementation, and operation of a penetration-testing system landscape
  • > Consulting and auditing for compliance requirements (§8a BSIG, ISO 27001, GDPR)
  • > Software testing based on functional & non-functional requirements (ISTQB Certified Tester)
ISO 27001§8a BSIGISTQB

Delivery

Oct 2018 – Aug 2020

Berater Informationssicherheit — iABG mbH — Berlin

Delivering the payload — running live cyber-range simulations and security assessments.

  • > Trainer for the iABG Advanced Cyber Range (cyber-attack simulations)
  • > Vulnerability management and remediation coordination
  • > SIEM use cases & rules implementation with alert analysis & escalation
  • > BSI IT-Grundschutz conform operations and Audit support
Cyber RangeSIEMIT-Grundschutz

Exploitation

Sep 2020 – Mar 2022

IT-Security Analyst — Netzbetreiber — Berlin

Finding and acting on the weak points — incident and vulnerability analysis.

  • > SIEM engineering — use cases, rule implementation, testing
  • > SIEM analysis — alert analysis & escalation
  • > IT security incidents — analysis, assessment, remediation coordination
  • > Vulnerability management — assessment & remediation coordination
  • > SOC build-out — architecture, technical support
  • > ISMS based on IT-Grundschutz — concepts, security assessment
SIEMVulnerability ManagementISMS

Installation

Mar 2022 – Mar 2024

IT-Security Operation Engineer — Netzbetreiber — Berlin

Embedding lasting capability — SOC architecture and automation at scale.

  • > SIEM Implementing/updating and testing rules
  • > SOAR playbook & API connection implementations
  • > Threat hunting via threat-intelligence analysis; deriving and testing attack scenarios
  • > Extending existing use cases in response to new or changed TTPs
  • > Log-source onboarding & guides
  • > Developing and automating processes within the SOC and CSIRT
SIEMSOARThreat HuntingCSIRT

Command & Control

Apr 2024 – Present

IT-Security Engineer — ausecus GmbH — Berlin

Building and commanding the platform — product engineering for critical infrastructure defense.

  • > Product development (of KRITIS Defender)
  • > Python programming for product features (e.g. WebUI, CI/CD, data processing)
  • > Security analyses for clients (assessments, findings, and remediation guidance)
  • > Threat intelligence research and analysis supporting ausecus' products and clients
PythonElastic Stack (ELK)DebianThreat IntelligenceClaude Code

Actions on Objectives

Ongoing

Current arsenal

The mission: defending critical infrastructure — and the toolkit built up along the way.

$ grep -r "Security Operations & Defense" ./arsenal/

SIEMSOARSecurity Operations CenterCyber DefenseThreat HuntingVulnerability ManagementMitigation Strategies

$ grep -r "Governance, Risk & Compliance" ./arsenal/

ISO 27001 / IT-Grundschutz§8a BSIGCVSS 2/3MITRE ATT&CK Matrix

$ grep -r "Certifications" ./arsenal/

ISTQB Certified TesterIT-Grundschutz-PraktikerIPMA Basiszertifikat (GPM)

$ grep -r "Security Tools" ./arsenal/

ArcSightQRadarStormshieldPrimekeyNessusOpenVASOpenCTIMISP

$ grep -r "Engineering & Platforms" ./arsenal/

PythonBashJavaScriptC#VBAC++JavaCErlangHaskellPrologx86 AssemblerElastic Stack (ELK)DebianClaude Code

$ grep -r "Languages" ./arsenal/

German (native)English (business fluent)French (basic)