You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Kris VandermastKV

Kris Vandermast

Security/DevSecOps Architect

€890/day
Antwerpen, BE
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Kris

Kris holds a bachelor's degree in computer science.

Early in his career, Kris already showed a talent for versatile employability. On the one hand, he is a motivated and dynamic project leader, with a keen sense for classic project management with a touch of XP/Scrum. On the other hand, he maintained a strong affinity for Java and open-source technologies. Kris has taken on the role of project or team leader within various projects. Moreover, he is certified in ITIL, Prince2, and Scrum.

His versatile skills and ability to adapt quickly make him a valuable asset to any team.
In 2011, Kris focused on Android and iOS development: first as a coordinator and partner within the Cronos Group and later as an independent consultant for, among others, the European Commission and Telenet.

The past few years, his focus has been on secure, multidisciplinary development and architecture solutions, combined with (technical) change management towards more agile delivery models and platform engineering. Kris's main focus is on guiding development teams through this change and inspiring them for this new way of working.

Available for:
- Long-term projects, with a focus on Java/Kotlin (primarily back-end) and enterprise architecture.
- Coaching and management, including change management from legacy to modern architecture and infrastructure
  • Dutch

    Native or bilingual

  • English

    Fluent

  • French

    Fluent

  • German

    Basic

  • Spanish

    Basic

Can work on-site
Antwerpen (up to 20km)

Experience

  • European Commission
    Senior Architect
    PUBLIC SECTOR
    March 2025 - July 2025 (4 months)
    Brussel, Belgium
    A short feasibility study on:
    • The requirements analysis for the development of a sovereign FIDO2 certified authenticator and credential manager
    • The implementation analysis for the integration of Microsoft Entra ID, where the existing IAM solution would serve as External Authentication Method (2nd factor authentication) via the OIDC protocol
    • The analysis of a design sovereign wallet solution and propose improvements on anonymous credentials
    Java Kubernetes Enterprise Architecture Spring boot Spring Security
  • European Commission (SG)
    Security/DevSecOps Architect
    PUBLIC SECTOR
    November 2023 - July 2025 (1 year and 8 months)
    Brussel, Belgium
    • The introduction of SOLID and IDEALS best practices on Spring Boot application development
    • Introduction of DevSecOps in the full SDLC of the applications, including various quality gates such as SonarQube, Fortify and OWASP
    • Introduction of proper Git workflows and peer-review strategies
    • Standardization and modernization of development practices
    • Introduction of Spring Cloud Gateway, Spring Cloud Vault, ABAC
    • Auditing applications on security flaws and vulnerabilities
    • Introduction of zero-knowledge paradigms in the CI/CD flow
    • Designing an anti-malware and anti-virus solution
    • Re-designing different applications to be able to scale in K8S alike environments.
    • Restructuring the development teams to embrace new technologies and new development paradigms, focusing on delivering business value while choosing the most appropriate framework/vendor
    • Introduction of automated quality gates during the DevSecOps lifecycle for early CVE and code quality degradation detection.
    Spring boot Java Spring Security SOLID Kubernetes
  • FOD Volksgezondheid
    Senior Architect
    PUBLIC SECTOR
    October 2022 - November 2023 (1 year and 1 month)
    Brussel, Belgium
    with the FOD Public Health, I (co-)designed the following solutions:
    - A blueprint of the FIT FOD program, which aims to provide more agility in development and deployment processes, such as
    o Introduction of Git, Git Actions and accompanying best practices on development processes
    o Improvements and automation on CI/CD via Gitea, Git Actions, Jenkins etc
    o Introduction of additional QA gates such as SonarQube, OWASP and Renovate
    o Introduction of proper Secret Management via Hashicorp Vault
    o Migration from a classic JEE/PrimeFaces application stack to an Angular/Microservices stack using Spring Boot
    o Introduction of the new release philosophy using containers via K8S and Docker for deployment on private and public cloud solutions.
    - A blueprint of a new UAM solution using Keycloak as authentication workflow engine, using custom authenticators to enrich the authentication process with additional attributes and authorities. Next to a classic R(O)BAC approach, the flow would consider an ABAC based authentication using OPA.

    Next to designing larger changes into the FOD ecosystem, I was also involved in multiple reusable component and business projects where my prime objective was to improve the quality of code, stability and maintainability of the solution.
    Enterprise Architecture Java OPA Keycloak JPA/Hibernate

Recommendations

Be the first to recommend Kris

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • bachelor's degree
    bachelor's degree
  • Local Police Antwerp
    Local Police Antwerp

Skill set

Categories