Nicolas Tran

Nicolas Tran

M. S. Cybersecurity · BSI Hall of Fame (2025) · Full-Stack Developer

End-to-end development of security solutions and secure infrastructure. Based in Germany.

Scroll

What I Do

Security-first engineering from concept to production.

End-To-End Development

I own features from UI to database. Frontend, backend, data layer, and everything in between.

Security & Identity

Every system I build is designed with security in mind, from architecture decisions to the code that ships.

Containerized Deployment

I ship on self-hosted infrastructure. Containerized, reproducible, and built to last.

Timeline

A decade of learning, building, and securing.

2014 — 2017

IT Systems Apprenticeship

PSC - Portable System Center · Saarbrücken

Vocational training as Management Assistant for IT Systems. Customer consulting, website development and migration, employee training, and technical support.

2017

Cisco CCNA Certified

Vocational Training Center Halberg · Saarbrücken

Routing and Switching: Introduction to Networks. Protocols, addressing, and subnetting.

2017 — 2021

B.S. Cybersecurity

Saarland University · Saarbrücken

Thesis on automated in-browser generation, analysis, and countermeasure selection for User Account Access Graphs. Focus: Web Security, Mobile Security, Physical-Layer Security, Hacking.

2018 — 2021

Research & Teaching Assistant

CISPA Helmholtz Center for Information Security · Saarbrücken

Taught Foundations of Cybersecurity. Ported C++ to JavaScript + WebAssembly for ICAPS 2020. Built graph-based Internet models with Cypher and Python.

2021 — Present

Full-Stack Developer

Step3IT (formerly TUXGUARD) · Neumünster

Building secure web apps with Django, FastAPI, and Node.js. Containerized architectures with Docker, Keycloak, and Postgres. Automated deployments cutting costs by 50%+.

2022 — 2026

M.S. Cybersecurity

Saarland University · Saarbrücken

Thesis on dynamic instrumentation of OpenSSL's Libcrypto for runtime monitoring. Advanced topics: Side Channel Attacks, IT Forensics, Security Testing, Machine Learning.

2025

BSI Hall of Fame

Federal Office for Information Security

Recognized by the German Federal Office for Information Security for contributions to national cybersecurity.

Your Organzation? Contact me now!

Specializations

Domains I work in daily and go deep.

Security Engineering

Web application security, access control and identity management, and threat modeling. From secure coding practices and vulnerability research to hardening production systems.

KeycloakOAuthOIDCLDAPSSOTLSOpenSSLDNS

Backend & Infrastructure

Building RESTful APIs and backend services across Python and Node.js, deployed on self-hosted Linux infrastructure with containerized architectures.

PythonJavaScriptFastAPIDockerNginxLinuxBash

Mail Systems & Groupware

Protocol-level knowledge of SMTP, mail delivery flows, and spam filtering. Building and maintaining self-hosted mail and groupware infrastructure with high deliverability.

HarakaPostfixRspamdSPFDKIMDMARCS/MIME

Familiar With

Additional technologies and tools in my toolkit.

Languages
Web & Frameworks
Security
Infrastructure & Databases
Tools & Workflows

Languages

CC++GoJavaC#PythonJavaScriptBashPDDL

Web & Frameworks

DjangoFastAPINode.jsExpressJinja2HTMLCSSBootstrapTailwind CSS

Security

Cryptographyx.509DANEPGPS/MIMEOpenSSLSide-Channel AttacksFuzzingReverse EngineeringForensicsNetwork SecurityPhysical-Layer Security

Infrastructure & Databases

LinuxDockerApacheNginxgRPCKopanoNextcloudDovecotCiphermailSQLPostgresMariaDBSQLiteNeo4JCypherElasticsearchRedis

Tools & Workflows

GitVimtmuxmakesshWiresharktcpdumpnmapFridaSwaksMkDocsLaTeXTypstMarkdown

German (Native) · English (C2) · French (B2)

Get in Touch

Interested in working together or just want to say hello?

Saarlouis, Germany