Yavuz Sönmez

I work on cloud and application security. Today that means owning security for a multi-account AWS environment — posture and vulnerability management, identity, resilience, and the application code itself.

I came to security through engineering rather than through audit. Before moving into security full time, I spent two years building the backend of the same platform I now secure.

Topics I am enthusiastic about

  • Cloud and application security — Zero trust architecture, defense in depth, and secure-by-default patterns from the pipeline through to production.
  • AI in cybersecurity — What it genuinely gives defenders, and the attack surface it opens up on the way in.
  • Red teaming — Everything found by attacking a system makes the defensive work sharper.
  • Threat intelligence — Developing the skill to read adversarial tactics, techniques and procedures through MITRE ATT&CK, and to answer them with the defensive patterns of MITRE D3FEND. Learning how attackers actually operate is what makes a defense worth building.
  • Security of critical infrastructure — The part of the field where the point is protecting people and the businesses they depend on. It is also some of the hardest engineering there is: systems that cannot be taken offline to be fixed, and failures nobody can afford.

Background

I studied software engineering at the Heilbronn campus of the 42 school network. I am currently based in southern Germany, near the Swiss city of Basel. I speak English, French, and Turkish, and I am learning German.

Feedback

If something here is wrong, or you would like to get in touch — contact@yavuzsonmez.com.