Moritz Wilhelm

Security Engineer III - Automated Vulnerability Management

Munich, Bavaria, Germany
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

👤
Senior
🎓
Top School
Moritz Wilhelm is a security engineer with eight years of experience, currently driving automated vulnerability management at Google from Munich. He holds a BSc in Cybersecurity and an MSc in Computer Science, and his work spans research-grade web security to production-grade scanner development. At Google he designed and implemented a generic path traversal detector as an open-source Tsunami plugin and contributed backend fuzzing and HTTP utilities to the widely used Tsunami security scanner. His research background at CISPA includes reproducible web crawling, teaching infrastructure for web security, and modeling Internet routing for defensive AI planning—demonstrating a blend of practical engineering and academic rigor. Known for turning vulnerability taxonomies into deployable detection logic, he combines deep protocol-level knowledge with hands-on Java and Python implementation experience.
code8 years of coding experience
job5 years of employment as a software developer
bookMaster of Science - MS Computer Science, Master of Science - MS Computer Science at Universität des Saarlandes
languagesEnglish, German, French, Japanese
github-logo-circle

Github Skills (10)

testing10
it-security10
javas10
http10
fuzzing10
network-security10
url-encoding10
java10
http-request10
security10

Programming languages (2)

JavaRust

Github contributions (5)

github-logo-circle
This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Role in this project:
userBack-end Developer
Contributions:31 commits in 15 days
Contributions summary:Moritz primarily focused on developing a generic Path Traversal detector plugin for the Tsunami Security Scanner. Their contributions include the creation of core classes like `PotentialExploit`, `InjectionPoint`, and `ExploitGenerator` to facilitate vulnerability detection. They implemented `PathParameterInjection` and `GetParameterInjection` to identify potential vulnerabilities. Furthermore, they enhanced the detector by adding configurable payloads and response checks to verify exploitability.
security-scanner
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
Role in this project:
userBack-end Developer
Contributions:5 commits in 9 days
Contributions summary:Moritz primarily contributed to the back-end functionality of the Tsunami security scanner. They added utility methods for URL encoding and implemented a `toBuilder()` function for HTTP requests, suggesting work related to network communication and data handling. Furthermore, the user developed a FuzzingUtils class with related testing, indicating a focus on vulnerability scanning techniques and input validation. The user also modified existing classes for better design and usability.
network-securityvulnerabilities
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial