>_ Dion Avé
>_ Professional Summary
HBO-ICT graduate specializing in Information Security Management through the Governance, Risk and Compliance track, combining security governance and risk analysis with hands-on Zero Trust IAM and AI-agent authorization research.
Built and evaluated a Proxmox-native SPIFFE/SPIRE research lab and translated experimental evidence into practical control-design conclusions.
* UPAE = Unauthorized Privileged Action Execution.
>_ Selected Technical Projects
Proxmox-native SPIRE + mTLS + Prompt-Injection Research
dion@resume:~/projects$ ./thesis_lab.sh --info
built:
- Configured SPIFFE/SPIRE workload identities, trust domains, mTLS service communication, and Envoy RBAC
- Designed an indirect prompt-injection experiment spanning a public chatbot, intake queue, and privileged internal agent
- Tested vulnerable, neutral, and hardened agent conditions using 22 payload variants across 11 categories
- Analysed outcomes using Wilson intervals, Fisher tests, and Cochran-Mantel-Haenszel analysis
result:
- C0/C1 UPAE: 23.56%/24.29%; statistically indistinguishable (Fisher p = 0.797)
- C2: 0/664 observed UPAE, while data exfiltration remained possible in 24.59% of trials
- 0/1,993 direct mTLS or RBAC boundary bypasses
conclusion:
- Identity and RBAC controlled access correctly; the agent's decision, not its identity, was compromised
Control Station — Governed Homelab & AI-Agent Operations
dion@resume:~/projects$ ./control_station.sh --info
platform:
- Built a Git-backed source of truth for deployed services, operational state, architecture decisions, and change evidence
- Operate self-hosted Gitea, OpenBao, service monitoring, backups, and a Python/SQLite agent capability registry
security:
- Separated non-root agent identities, sandboxed runtimes, fixed worktrees, protected PRs, and human-gated elevation
- Added SOPS/age secret handling, task-scoped credentials, audit telemetry, and drift detection
governance:
- Use schema-validated architecture records, change classifications, review evidence, and recovery procedures
- Document unresolved risks explicitly rather than presenting the environment as fully hardened
>_ Experience
Graduation Intern, Zero Trust IAM Research
- Owned delivery of an AI-agent security research project in a professional IAM advisory environment.
- Connected workload identity, backend authorization, intake-channel trust, and prompt injection in an applied Zero Trust model.
- Documented how authenticated tool calls can still violate authorization when agents treat untrusted content as instructions.
Pre-launch Security Readiness Assessment
- Conducting a pre-launch assessment covering assets, data flows, IAM, Fabric/Power BI, and AI-related risks.
- Reconstructing the current security state through interviews, evidence gathering, source notes, and decision logs.
- Building a risk register, minimum launch baseline, and go/no-go readiness report.
Cybersecurity / Strategy & Risk Intern
- Researched Continuous Monitoring in a Strategy & Risk context, connecting monitoring to governance and assurance.
- Observed client-facing work and a security maturity assessment in an advisory environment.
- Explored ServiceNow and translated research into a structured presentation for business stakeholders.
Owner / IT Support Consultant
- Operated a small IT advisory business covering support, web hosting, networking, IoT, and malware removal.
- Diagnosed devices, home networks, websites, and IoT environments for non-technical customers.
- Explained security risks while independently managing planning, administration, and delivery.
Motorcycle Technician / Lead Builder
- Rebuilt a Yamaha XVS 1100 wiring harness around a motogadget mo.unit blue.
- Validated circuits in controlled stages and documented the system for maintainability.
Earlier Experience
Information Security Intern · Merlin Software · 2020–2021
- Supported ISO 27001 re-certification and conducted a practical risk assessment.
Social Media Crisis Trainer · Parcival Crisis · 2020–2021
- Prepared 1,000+ injects across three crisis simulations and supported ISMS work.
IT Support Consultant · uwComputerstudent · 2017–2023
- Supported and educated home users across devices, networks, IoT, and malware removal.
>_ Education
>_ Education
B.Sc. HBO-ICT — Information Security Management
Track: Governance, Risk and Compliance
Thesis: Zero Trust IAM for non-human identities and AI agents @ SonicBee
Result: 8.5/10
Security Operations · Information Security Governance · Business Continuity · Human Factors
>_ Core Capabilities
Governance, risk & compliance
- GRC specialization track
- ISO 27001 / ISMS support
- Risk analysis and registers
- Security baseline development
Identity & AI security
- Zero Trust IAM and non-human identities
- SPIFFE/SPIRE workload identity
- mTLS and Envoy RBAC
- AI-agent authorization testing
Technical foundation
- Python, JavaScript, and SQL
- Linux, Windows, and Kali Linux
- Proxmox and OPNsense
- Networking and segmentation
Research & validation
- Controlled experiment design
- Authorization-boundary testing
- Evidence and log analysis
- Statistical interpretation