Profile – Jan-Peter von Hunnius (EN, Cybersecurity Expert)

# Profile: Jan-Peter von Hunnius — Cybersecurity Expert (EN)

> Source: `CYEQT - Jan von Hunnius - EN.pdf` (Aug 2025)
> Language: English · Variant: Cybersecurity Expert (hands-on technical)

## Role
**Cybersecurity Expert**

*Combines strategic consulting with hands-on implementation – from OEM negotiations down to the bit level.*

## Key Skills for the Project
ISO/SAE 21434, TARA, Item Definition, Cybersecurity Concept, Security Controls, Cybersecurity Engineering, CS Plan, CS Case, AutoSAR, Stack Configuration, Penetration Test, Key Lifecycle Management, UDS, SecOC, CAN, CAN-FD, LIN, SPI, I2C, HSM, Infineon Aurix, Infineon Traveo, NXP S32, ASPICE, Automotive SPICE, UN R155, ISO 24089, UN R156.

## Professional Summary
Experienced cybersecurity expert with deep technical and procedural expertise in the automotive domain. Specialized in secure software development, TARA, and cryptography, aligned with standards such as ISO/SAE 21434. As a lecturer, consultant, and manager, he delivers strategic, developmental, and training excellence — with a focus on practical, secure, and scalable system solutions.

## Professional Focus Topics
- **Cybersecurity Engineering** (2021–now / 5 years): Item Definition · TARA · Cybersecurity Concept · ISO/SAE 21434
- **Development Processes** (1999–now / 26 years): CMMi · Automotive SPICE · Agile Methods · SCRUM
- **Software Development** (1993–now / 32 years): C/C++ · Rust · Java · Scala · Modula-2 · Pascal · COBOL

## Education
- **Diploma Computer Science**, University Ulm (1996–1999) — Focus Programming Methodology; Diploma Thesis: Object-oriented Development of continuous Systems; Secondary Subject: Economics.
- **Intermediate Diploma Computer Science**, University Ulm (1993–1996) — Secondary Subject: Economics.

## Languages
- German — Native Language
- English — Professional Proficiency

## Customers & Industries
- **Automotive** (1999–now / 26 years): Daimler · AVL · U-Shin · Veoneer · Brose · Weber Hydraulik · Flux Mobility · Schaeffler Engineering · Magna Engineering
- **Semiconductors** (2010–now / 15 years): NXP · HID
- **Insurance** (2012–2016 / 4 years): Generali

## Selected Project Successes
- Saved several hundred thousand euros in development costs through TARA optimization and cybersecurity concept refinement.
- Successfully passed security assessments and reviews conducted by OEMs.
- Efficient CSMS rollout across different industry sectors.
- Identified strategic impact on the business case beyond the project scope and addressed it jointly with the OEM.
- Initiated and supported implementation of groundbreaking architecture decisions with system-wide implications.
- Successfully guided departments and projects through process assessments.

## Projects & Positions
- **FH Joanneum Graz** (2024–now): Lector „Automotive Cyber Security" (Master's Program Automotive Engineering).
- **EASELINK** (Q2 2025): Cybersecurity Consulting; architecture change simplifying separation of safety content & inter-MC communication. *Stack: ISO 15118, BLE, UWB, SecOC, UDS, PTC codeBeamer, Cymetris, Enterprise Architect.*
- **Weber Hydraulik** (Q2 2025): Cybersecurity Consulting & AI Strategy; CSMS ported to CRA-covered units; AI-driven processes introduced. *Stack: CRA, CSMS, LLM, Vector Store, Generative AI, AI-Pipeline.*
- **Joyson Safety** (Q2 2025): CSMS gap analysis vs ISO/SAE 21434.
- **Breachlabz / Aston Martin Lagonda** (Q1–Q2 2025): Coordination & Moderation Penetration Test.
- **NVIDIA** (Q1 2024–Q2 2025): Cybersecurity Assessments for middleware components. *Stack: NDAS, Middleware, JIRA, Confluence.*
- **CYEQT Knowledge Base** (2024): TARA tools study (CycurRISK, ThreatGuard, Medini, Cymetris).
- **Mobileye** (2024): Item Definition "out of context" for ADAS.
- **Pierer Innovation / KTM** (2024): Expedited TARA & threat model under time pressure; PKI infrastructure, UN R155.
- **Brose E-Bikes** (2023–2024): E-bike security concept (end-user component replacement).
- **Flux Mobility** (2023–2024): TARA/security concept for combustion→electric drive; SecOC, OEM discussions.
- **Schaeffler Engineering** (2023): TARA/security concept for EV clutch (Aurix TC3).
- **Magna Engineering** (2023): SecOC & intrusion detection concepts (vehicle level).
- **Bluewind** (2023): Stack configuration, OEM requirement alignment (Vector MicroSAR, DaVinci, Aurix TC3).
- **Weber Hydraulik** (2022–2025): TARA & security concept through OEM review; saved ~100k€. *Stack: Aurix TC2, Polarion, JIRA, Confluence.*
- **CYRES Consulting Austria** (2023–2024): CEO & Head of Cybersecurity Engineering; founded Graz subsidiary.
- **Veoneer Restraint Control** (2022–2024): TARA/security concept OEM review; Key Lifecycle Management OEM↔Supplier.
- **Veoneer – Data Storage** (2021–2022): TARA, Secure Boot, SecOC, Ethernet, X.509, MQTT, Fuzz Test, Yocto Linux, Aurix TC3, Intel Denverton.
- **U-Shin – Remote Unlock** (2020–2022): BLE localization (10 cm with 3 antennas); app for phones/wearables; reader ECU SW. *Stack: Android, Wear OS, iOS, Java, Swift, NFC, BLE, AutoSAR, NXP S12/S32.*
- **U-Shin – ESCL** (2015–2020): Tool/process migration to codeBeamer/Stages; Automotive SPICE, ISO 26262 ASIL D/B.
- **Bosch Rexroth** (2013–2015): Streamlined CMMI-compliant process.
- **Generali** (2011–2016): CMMI assessment as quality responsible.
- **NXP Semiconductors** (2010–2011): CMMI assessment; NFC, RFID, JCOP, Common Criteria.
- **AVL List** (2007–2010): Process setup & CMMI assessments.
- **Atronic Austria** (2004–2007): Processes & tool infrastructure; IBM Doors Factory.
- **Daimler / University Ulm** (1999–2003): PhD student SW process design; CMM, RUP, XP, GQM, Experience Factory.

## Private Projects (Selection)
- **AutoSAR Classic Stack** (2023–now): Secure open-source AutoSAR stack in Rust.
- **Vintage Computer Emulation** (2023–now): Rust, reuse, open source.
- **Poker-Bot Framework** (2010–now): Professional-level poker bot (Java/Scala/Rust, RL, Nash Equilibrium).

## Publications (Selection)
- *Insights into Vehicle Security Attack Vectors*, Scapy Con Automotive Regensburg 2024.
- *Cyber Security Beyond Cars: Compliance Challenges for OEMs and Their Supply Chain*, VDI Munich 2024.
- *Keynote & Workshop Automotive Cybersecurity*, QFD Group Budapest 2023.
- *Efficient & Effective TARA Development*, IQPC Automotive Cybersecurity Europe 2023.
- *Automotive Cybersecurity Nightmares*, CYRES Munich 2023.
- *Hacking Meets Automotive*, CYRES Munich 2022.
- *Effective Experience Repositories*, ICSE Portland 2003.
- *Experience in Implementing a Learning Software Organization*, IEEE Software 2002.
- *WESPI – Web Supported Process Improvement*, LSO Oulu 2000.


id: 3de39fddc5b24070a00ce69d211aad98
parent_id: d735e23d152b4489adaefd3dfe3e8bf8
created_time: 2026-07-19T15:11:03.389Z
updated_time: 2026-07-19T15:11:03.389Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author: 
source_url: 
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data: 
order: 1784473863389
user_created_time: 2026-07-19T15:11:03.389Z
user_updated_time: 2026-07-19T15:11:03.389Z
encryption_cipher_text: 
encryption_applied: 0
markup_language: 1
is_shared: 0
share_id: 
conflict_original_id: 
master_key_id: 
user_data: 
deleted_time: 0
is_locked: 0
extracted_resource_ids: 
type_: 1