TODO – Profile & Project-Agent Pivot (Product Security + Secure AI)

# TODO – Profile & Project-Agent Pivot

> Goal: broaden from "Automotive Cybersecurity" to **Product & Embedded Security (cross-sector + CRA)** and **Secure AI Systems**, and fix the misfiring freelancermap Project-Agent search.
> Created 2026-07-23. Convergence niche: *Secure AI-enabled Product Security — TARA/CRA compliance + adversarial-ML hardening + bit-level implementation.*

---

## P0 — Project-Agent re-tuning (today, zero cost)
- [ ] Audit current search config at `freelancermap.at/edit/projektagent/99267` — list active keywords, rate, remote filter.
- [ ] **Add positive keywords:** Cyber Resilience Act, CRA, Produktsicherheit, product security, IEC 62443, IoT security, embedded security, TARA, CSMS, SBOM, "AI security", secure AI, secure ML.
- [ ] **Add exclusions / negative keywords:** Cloud, DevOps, OpenShift, Kubernetes, SIEM, SOC, Purview, DLP, ServiceNow, M365, Netzwerk, Linux Admin, Windows Endpoint, IAM-Plattform.
- [ ] Set **rate floor ≥ 85 €/h** (target ≥ 100 €/h); verify remote ≥ 50 % filter is active.
- [ ] Monitor next 2 agent emails → measure discard rate → iterate keywords.

## P1 — Profile broadening (this week)
- [ ] Update **DE + EN profiles**: reword headline from "Automotive Cybersecurity" → "Product & Embedded Security (Automotive · IoT · Industrial · CRA)".
- [ ] Foreground existing CRA / cross-sector CSMS / 62443 work (Weber Hydraulik CRA port, EASELINK, Flux Mobility) above the pure-auto history.
- [ ] Add **"Secure AI Systems" section** to profiles: AI Act, NIST AI RMF, OWASP LLM Top 10, applied ML (Weber Hydraulik AI-Strategie; poker-bot imitation→RL pipeline).
- [ ] Create **new profile variant** focused on the convergence niche: "Secure AI-enabled Product Security" — for targeted applications to AI-adjacent product-security roles.
- [ ] **Keep** the 21434-specific DE variant (41b88f10…) for pure-auto roles.

## P2 — AI model artifact as proof (the poker bot)
> This is the demonstrable proof for the AI track. See separate TODO in super-marvin notebook.
- [ ] Sanitize repo for publication (strip Torn/live harness; keep sim testbed + 3 models + training CLI).
- [ ] Public repo skeleton + README (Gen1→4.8→NN journey, 3-NN architecture diagram).
- [ ] Package eval harness as one-command benchmark vs 10 opponent types.
- [ ] RangeNet ablation (range-aware vs range-blind) → results table.
- [ ] Writeup (1500–2500 words) — the portfolio artifact.

## P3 — One adjacent framework (pick one)
- [ ] **IEC 62443** (industrial/OT) — lowest-effort extension of existing auto work; OR
- [ ] **AI Act / NIST AI RMF** — for the AI track. Add to profile once comfortable.

## P4 — Channels
- [ ] Re-evaluate whether freelancermap alone is enough, or add 1 channel (LinkedIn "open to work" with broadened headline; Hays/Robert Half for product-security).
- [ ] Decide on one public artifact link in profile (poker-bot repo once P2 done).

---

## Notes
- Hard filters stay: remote ≥ 50 %, rate ≥ 85 €/h. Non-negotiable.
- Classic IT-security (SOC/SIEM/network/IAM-admin/M365) remains excluded even if re-tuned search surfaces it.
- The poker-bot artifact only goes public AFTER sanitization (legal/ToS gate).

id: 875e42ca124042b0a5c988b33f3ca02a
parent_id: d735e23d152b4489adaefd3dfe3e8bf8
created_time: 2026-07-23T09:37:25.568Z
updated_time: 2026-07-23T09:37:25.568Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author: 
source_url: 
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data: 
order: 1784799445568
user_created_time: 2026-07-23T09:37:25.568Z
user_updated_time: 2026-07-23T09:37:25.568Z
encryption_cipher_text: 
encryption_applied: 0
markup_language: 1
is_shared: 0
share_id: 
conflict_original_id: 
master_key_id: 
user_data: 
deleted_time: 0
is_locked: 0
extracted_resource_ids: 
type_: 1