Rebecca Falke

Web Application Security Engineer and Fullstack Developer

Living in Munich  
Your current time
Rebecca's current time

Hi, my name is Rebecca!

While having studied computer science at Munich University of Applied Sciences , I developed a passion for IT-security. Accordingly my master thesis deals with emulation techniques of web application honeypots.

Currently I am working at weframe AG as a Security Engineer. I am constantly enhancing the security of the Weframe One web application, such as input validation, hardening authorization or building a Content-Security-Policy. I also improved the quality, for example by introducing migrations that are easily rolled back on our test systems.

Before, I worked at jameda GmbH which is Germany’s leading platform for physician search and consultation ratings. I developed a new modern PHP7 authorization service, maintained jameda’s backend applications and worked with React on the search and profile pages.

When I came to New Zealand for a working holiday in 2017 I got the great opportunity to get to know the startup culture at Cove Insurance . I enjoyed working as a security developer on a modern Facebook Chatbot together with an agile team. Having been a backend developer before, I extended my knowledge and became a fullstack developer at Cove working with the technologies NodeJS and React. My application security skills allowed me to improve Cove's product. For example, with hardening the user management (authentication and authorization) or redesigning the payment process I achieved to offer a much safer experience both to customers and to the business.

Before, during my job as a professional Java developer at secunet Security Networks AG in Munich I was part of a scrum team developing software for the German tax return system with 5 million end-users. My tasks were extending and maintaining backend SOAP services providing security-related functionality (e.g. certificate handling, authorization, authentication, encryption) and the frontend JavaFX application ElsterAuthenticator for user certificate handling. Furthermore, I performed third level support, deployments and secure code reviews frequently there.

My internships abroad at PanthaCorp in Manly and Siemens Corporate Research in Princeton did not only teach me technical skills, but also contributed to my personal development and English skills.

I love traveling, photography, bouldering, swimming, outdoor activities, board games with friends and good & reasonable priced food.

Please feel free to contact me if you have any questions or proposals!

Open Source Projects

Glastopf Project Image

GlastopfInjectable

Masterarbeit
Web Application Honeypot

View more
Travelblog Project Image

Travelblog

Uni Project
Ruby on Rails Blog for Travellers

View more

Work Experience

Security Engineer - weframe AG - Munich, Germany (Jan 2020 - current, 10 months maternity leave in between)

Fullstack developer - Jameda GmbH - Munich, Germany (Oct 2018 - Dez 2019)

Security developer - Cove Insurance Ltd. - Auckland, New Zealand (Nov 2017 - Jun 2018)

  • Developed as a fullstack developer on a Facebook Chatbot that offers customers to buy and to handle insurance
  • Implemented and maintained features and services
  • Designed and implemented application security solutions e.g. user management
  • Conducted secure code reviews to detect and report vulnerabilities
  • Hardened or redesigned the Chatbot's applications to countermeasure found issues
  • Improved the API's test coverage
  • Maintained or extended the AWS infrastructure
  • Learned NodeJS, React, Microsoft Bot Framework and AWS

Consultant and Java developer - secunet Security Networks AG - Munich, Germany (Jun 2015 - Aug 2017)

  • Worked on different projects of the German tax return system "Elster"
  • Developed and maintained SOAP services that handle registration, authentication, authorisation, encryption for users and taxing authorities
  • Further development of the ElsterAuthenticator for certificate handling
  • Hardened applications (e.g. XML parser hardening) and secure code reviews
  • Wrote integration-, component- and unittests
  • Continuous integration
  • Deployments
  • Third level support

Intern - Pantha Corporation Pty. Ltd. - Manly, Australia (Oct 2012 - Feb 2013)

  • Worked on a not-for-profit fundraising web application, based on Magento eCommerce
  • Design modifications with CSS and HTML
  • Continuous integration

Intern - Siemens Corporate Research - Princeton (NJ), USA (Sept 2011 - March 2012)

  • Worked on a web application that presents geothermal data
  • Learned Spring MVC, PostgreSQL and ExtJS

Working student - Saxonia Systems AG - Munich, Germany (March 2011 - Aug 2011)

  • First insight into web applications using Adobe Flex, Action Script, MXML and Hibernate