>_ Dion Avé

Email[redacted]
Phone[redacted]
LocationHoogwoud, NL
LinkedInlinkedin.com/in/dion-ave
GitHubgithub.com/dionoss
Webdionave.dev

>_ Professional Summary

HBO-ICT graduate specializing in Information Security Management through the Governance, Risk and Compliance track, combining security governance and risk analysis with hands-on Zero Trust IAM and AI-agent authorization research.

Built and evaluated a Proxmox-native SPIFFE/SPIRE research lab and translated experimental evidence into practical control-design conclusions.

1,993 experiment trials 24.29% neutral-agent UPAE* 0/664 hardened-agent UPAE*

* UPAE = Unauthorized Privileged Action Execution.


>_ Selected Technical Projects

Control Station — Governed Homelab & AI-Agent Operations

Docker · Gitea · OpenBao · Python · SQLite · SOPS/age · systemd
dion@resume:~/projects$ ./control_station.sh --info

platform:
  - Built a Git-backed source of truth for deployed services, operational state, architecture decisions, and change evidence
  - Operate self-hosted Gitea, OpenBao, service monitoring, backups, and a Python/SQLite agent capability registry

security:
  - Separated non-root agent identities, sandboxed runtimes, fixed worktrees, protected PRs, and human-gated elevation
  - Added SOPS/age secret handling, task-scoped credentials, audit telemetry, and drift detection

governance:
  - Use schema-validated architecture records, change classifications, review evidence, and recovery procedures
  - Document unresolved risks explicitly rather than presenting the environment as fully hardened

>_ Experience

2025–2026

Graduation Intern, Zero Trust IAM Research

SonicBee
  • Owned delivery of an AI-agent security research project in a professional IAM advisory environment.
  • Connected workload identity, backend authorization, intake-channel trust, and prompt injection in an applied Zero Trust model.
  • Documented how authenticated tool calls can still violate authorization when agents treat untrusted content as instructions.
1,993 trials · Thesis grade 8.5/10
May 2026–Present

Pre-launch Security Readiness Assessment

GoNudge
  • Conducting a pre-launch assessment covering assets, data flows, IAM, Fabric/Power BI, and AI-related risks.
  • Reconstructing the current security state through interviews, evidence gathering, source notes, and decision logs.
  • Building a risk register, minimum launch baseline, and go/no-go readiness report.
Launch baseline · Risk register · Go/no-go evidence
2023–2024

Cybersecurity / Strategy & Risk Intern

KPMG
  • Researched Continuous Monitoring in a Strategy & Risk context, connecting monitoring to governance and assurance.
  • Observed client-facing work and a security maturity assessment in an advisory environment.
  • Explored ServiceNow and translated research into a structured presentation for business stakeholders.
2023–2024

Owner / IT Support Consultant

Avé IT Advies
  • Operated a small IT advisory business covering support, web hosting, networking, IoT, and malware removal.
  • Diagnosed devices, home networks, websites, and IoT environments for non-technical customers.
  • Explained security risks while independently managing planning, administration, and delivery.
2026–Present

Motorcycle Technician / Lead Builder

GoNudge
  • Rebuilt a Yamaha XVS 1100 wiring harness around a motogadget mo.unit blue.
  • Validated circuits in controlled stages and documented the system for maintainability.

Earlier Experience

Information Security Intern · Merlin Software · 2020–2021

  • Supported ISO 27001 re-certification and conducted a practical risk assessment.

Social Media Crisis Trainer · Parcival Crisis · 2020–2021

  • Prepared 1,000+ injects across three crisis simulations and supported ISMS work.

IT Support Consultant · uwComputerstudent · 2017–2023

  • Supported and educated home users across devices, networks, IoT, and malware removal.

>_ Education

>_ Education

Graduated 2026

B.Sc. HBO-ICT — Information Security Management

The Hague University of Applied Sciences

Track: Governance, Risk and Compliance
Thesis: Zero Trust IAM for non-human identities and AI agents @ SonicBee
Result: 8.5/10

Security Operations · Information Security Governance · Business Continuity · Human Factors


>_ Core Capabilities

Identity & AI security

  • Zero Trust IAM and non-human identities
  • SPIFFE/SPIRE workload identity
  • mTLS and Envoy RBAC
  • AI-agent authorization testing

Technical foundation

  • Python, JavaScript, and SQL
  • Linux, Windows, and Kali Linux
  • Proxmox and OPNsense
  • Networking and segmentation

Research & validation

  • Controlled experiment design
  • Authorization-boundary testing
  • Evidence and log analysis
  • Statistical interpretation

>_ Interests

Motorcycle buildingElectrical troubleshooting · Controlled validation
Citroën 2CV restorationLong-term planning · Technical documentation
SkydivingChecklist discipline · Risk awareness
dion@resume:~$