Information Security @ Staffbase · Security automation, AI tooling & GRC engineering · Chemnitz 🇩🇪
I own vulnerability management at Staffbase, a $1B+ employee communications company reaching about 16 million employees at roughly 2,000 organisations, and I automate the parts that repeat: vendor reviews, security questionnaires, the same scanner finding read four times over.
The automation has to show its work. An answer a security team cannot trace back is worth less to them than no answer at all.
I own vulnerability management end to end at that scale — then automate the rest of the security team's work so our hours go to judgement instead of copy-paste.
| 🎯 Vulnerability management | 230+ issues owned · 140+ pentest findings retested (26 High/Critical) · 46 bug-bounty reports triaged |
| ⚡ AI vendor reviews | ~4 hours → ~20 minutes, at ~$1.67 a run |
| 📋 GRC automation | 10+ security questionnaires in 3–4 days. Biggest was 900+ true/false questions — one wrong answer |
| 💰 ROI, not procurement | Accurate enough that we cancelled the commercial tool we were evaluating |
| 🏆 Recognition | CFO Innovation Award |
| 🔍 AI-augmented pentesting | Burp Suite Pro wired to Claude over MCP — testing driven in plain language |
The thread through all of it: get real ROI out of the AI you already pay for, instead of buying the next tool.
|
Your coding agent stopped asking permission. This keeps the receipt. Claude Code, Copilot CLI and Codex land in one live timeline on one machine — every command, file touch and network call. No tenant, no account, nothing uploaded.
|
🎯 VODP vodp.devFour scanners in. One honest list out. Burp Suite, ZAP, Nuclei and Dalfox normalised into one schema, deduplicated, and re-tested automatically when someone claims a fix.
|
||||||||
📋 Answerdeck answerdeck.appSecurity questionnaires gate enterprise deals. They shouldn't eat a week. Draws answers from a team's own evidence, cites the document behind each one, and routes every answer through human review before it leaves.
|
🏢 BrikSync PropOS briksync.comA live multi-tenant SaaS where the permission model is the product. Landlord, property manager, broker and tenant each sign in and see only their own part — enforced in the database, not hidden in the screen.
|
||||||||
🦊 aifoxx aifoxx.com"Is this tool SOC 2? Do they train on our data? Where does it live?" — the three questions every AI shortlist dies on. A catalogue where those fields are recorded once, comparably, with a link to the vendor page that proves each one.
|
|||||||||
I dispatch agents rather than typing the code myself — and I can tell you exactly how much, because I built the tool that measures it. Across my own projects:
From ClaudeSec, which instruments every tool call my agents make:
| 385,647 | tool-call spans logged, across 146 repositories and 3 agent harnesses |
| 4,843 | alerts raised on my own agents — 22 critical, 1,046 high |
From my session transcripts:
| 836 | subagents dispatched, over 1,358 sessions and 67 project directories |
| ~7 : 1 | agent/CLI actions per hand edit (43,790 Bash+MCP vs 6,382 Edit/Write) |
Every tool call routes through a pre-execution hook into ClaudeSec — so the agents that write my code are watched by the tool I built to watch agents.
Security & GRC
AI & agents
Build
Data & platform
Quality & observability
Design & workplace
Writing about AI-assisted pentesting, local inference for compliance, and shipping with agents → withkarann.com/blog
Working on something where AI meets security?
Book 30 minutes · [email protected]




