Berend-Jan Wever EN | NL

Download resume.pdf
berendj@nwever.nl (PGP)
LinkedIn
GitHub
Website

Introduction

Berend-Jan Wever is an offensive information security researcher whose work has evolved from low-level discovery and exploit development to large-scale adversarial validation in AI-enabled systems. He specializes in offensive research, fuzzing, automation, vulnerability analysis, and the design of scalable security validation methods. Over the course of his career, he has reported hundreds of security issues across operating systems, web infrastructure, cloud platforms, and complex distributed systems, impacting billions of users.
His research combines systems-level understanding with adversarial thinking: he identifies how small flaws compose into broader attack paths, traces root causes back to architectural and procedural weaknesses, and builds the automated workflows needed to validate defenses at scale. This naturally extends into AI-focused security research, where he evaluates adversarial techniques, prompt-injection risks, model abuse, and detection gaps in AI-assisted environments.
Berend-Jan has spent decades working with security teams at some of the largest companies in the industry, helping them move from isolated bug-finding to repeatable, scalable security programs. He develops automation, suggests process changes, creates training, and designs validation frameworks that help teams find and remove entire classes of weaknesses before they reappear. His work has consistently focused on long-term impact: building methods that scale with product growth and remain effective as systems evolve.
He creates actionable reports for engineers and high-level risk assessments for management, advises on remediation and mitigation strategies, and helps junior researchers grow by sharing techniques, tools, and research methods. He enjoys presenting his work, discussing emerging threats, and pushing security research forward into new domains such as AI-driven systems, adversary emulation, and automated security review at scale.

Technology

Berend-Jan has worked across a broad range of platforms, languages, and security domains. The most relevant areas are summarized below.

Operating Systems and Cloud

Microsoft Windows, Linux, Amazon Web Services (AWS).

Languages

Java, Python, JavaScript/TypeScript, C, C++, C#, PowerShell, Bash, SQL, assembly.

Security Disciplines

Fuzzing, reverse engineering, exploit development, adversarial emulation, threat modeling, security automation, detection engineering, vulnerability analysis.

Platform Experience

Browsers, operating systems, cloud services, drivers, firmware, web infrastructure, and distributed systems.

Recent Work History

Principal Security Researcher within Microsoft Azure Security Engineering

Location: Work from home in the Netherlands
Period: 2025-Present
Activities: adversary emulation, security research, security validation, automation, AI security research

This role reflects the natural progression of Berend-Jan's work from offensive research and automation to AI-focused adversarial security validation, where the emphasis is on understanding emerging risks in AI systems, validating defensive controls at scale, and translating adversary behavior into measurable, repeatable security testing.

Senior Security Engineer within Amazon Web Services (AWS) Holistic Testing Team

Location: Work from home in the Netherlands
Period: 2021-2024
Activities: team leadership, security reviews, threat modeling, automation, security training

Senior Security Researcher and head of Fuzzing Community at Intel

Location: Work from home in the Netherlands
Period: 2019-2021
Activities: technical leadership, fuzzing, automation, training, cross-team strategy

Owner of SkyLined Security

Location: Work from home in the Netherlands
Period: 2011-2019
Activities: security research, fuzzing, automation, consulting, research publications

Senior Software Security Engineer in Chrome Security Team at Google

Location: Work from home in the Netherlands
Period: 2008-2011
Activities: security engineering, fuzzing, automation, patch validation, security process

Security Researcher in Security Windows Initiative Attack Team at Microsoft

Location: Work from home in the United Kingdom
Period: 2005-2008
Activities: offensive security, fuzzing, design & implement automation, vulnerability analysis, research

Skills and Experience

Key skills

Historically Notable Publications

A small selection of contributions to the information security community:

Spoken languages

Dutch - native
English - Fluent
German - Proficient
French - Basic