Kai Ullrich

About

Cybersecurity Expert, SAP Security Specialist, Consultant, Security Researcher, Trainer

28 years of professional experience specializing in SAP security.

  • Degree: Diplom-Mathematiker
  • Certifications: OSCP, OSCE, CISSP

Cybersecurity expert with 28 years of professional experience specializing in SAP security. Combines in-depth knowledge of offensive security—including red teaming and attack simulations—with comprehensive expertise in defensive security, SIEM, and security monitoring. As a well-rounded security professional, he helps companies identify, assess, and mitigate risks in complex IT and SAP environments. His experience as a trainer and instructor also enables him to convey technical knowledge in an accessible way and to build lasting safety skills.

Skills

Security Generalist

  • Holistic assessment of security risks, threats, and protective measures
  • Advisory services on security strategies and security architectures
  • Analysis and assessment of security risks in complex enterprise environments
  • Delivery of security knowledge through training courses, workshops, and seminars
  • Effective communication between technical experts, management, and business stakeholders

Offensive Security

  • Execution of Red Team exercises and attack simulations in large-scale SAP environments
  • Extensive Red Team experience in both SAP and non-SAP environments
  • Identification and assessment of vulnerabilities in business processes and IT systems
  • Support in prioritizing and remediating identified vulnerabilities
  • Author of numerous zero-day vulnerabilities and technical publications on security vulnerabilities

Defensive Security

  • Design and optimization of security monitoring and detection strategies
  • Implementation and optimization of SAP Enterprise Threat Detection (ETD)
  • Conducting security assessments and security maturity assessments
  • Support for incident response and detection processes
  • Design and delivery of security awareness programs
  • Training employees and business units on cybersecurity and SAP security topics
  • Promoting a sustainable security culture to reduce human-related risk factors

More Skills

  • Practical software development experience spanning multiple generations of technologies
  • In-depth understanding of applications, interfaces, and system architectures gained through decades of hands-on software development
  • Effective use of artificial intelligence for tool development, forensic analysis, and security-related automation
  • Experience working with local large language models (LLMs)

Resume

Education

Diplom-Mathematiker

1998

Universität Dortmund, Germany

Certifications

  • OSCP – Offensive Security Certified Professional
  • OSCE – Offensive Security Certified Expert
  • CISSP – Certified Information Systems Security Professional

Languages

  • German: Mother Tongue
  • English: Fluent
  • French: Fluent

Career History / Work Experience

Monitoring of Large-Scale SAP Landscapes with SAP Enterprise Threat Detection (ETD)

Jul 2023 - Dec 2026
  • Development and fine-tuning of detection and monitoring patterns
  • Triage, analysis, and handling of security alerts
  • Support for the strategic enhancement of monitoring capabilities
  • Support for AI-driven automation of security monitoring

Red Team Exercises and Attack Simulations

2023 - 2024
  • Conducted realistic attack simulations against SAP environments for customers of various sizes
  • Performed Purple Team exercises in collaboration with customer Blue Teams to enhance detection and response capabilities

Security Consultant and Acting IT Coordinator

Sep 2022 - Apr 2023

Mid-sized provider of outpatient healthcare services

Red Team Engineer

2017 - Aug 2022

Code White GmbH, Ulm

  • Conducted numerous realistic attack simulations for large German mid-sized enterprises and DAX 30 companies
  • Performed black-box penetration tests against web applications, Windows Active Directory environments, cloud infrastructures, and other enterprise systems
  • Planned and executed sophisticated phishing campaigns to assess organizational resilience
  • Conducted Java source code reviews to identify security vulnerabilities and implementation flaws
  • Performed security research leading to the discovery of approximately six zero-day vulnerabilities

Self-employed IT Consultant specializing in SAP Identity Management

2012 - 2017
  • Successfully delivered dozens of identity and access management (IAM) implementation projects for organizations of various sizes and industries
  • Analyzed customer requirements and translated them into tailored technical solutions
  • Developed custom integration interfaces for third-party systems, including IBM AS/400 and IBM Lotus Notes

Senior Consultant

2005 - 2012

SAP Deutschland GmbH & Co. KG

  • Delivering implementation projects across the DACH region and the Nordic countries in the areas of security, authentication, and Identity & Access Management (IAM)

Software Developer

1998 - 2005

SAP AG, Walldorf

  • Development of various security features in the SAP R/3 core, including secure storage mechanisms and the SAP logon ticket
  • Contribution to foundational security capabilities such as PKI integration, cryptographic operations, and digital signatures
  • Since 2001, serving as development architect with responsibility for security in the development of the SAP Enterprise Portal

Lectures & Teaching

  • 2017 - 2019: Lecturer at the University of Applied Sciences Mannheim, “Introduction into Penetration Testing”
  • October 2022: The log4shell disaster at the it-sa Nuremberg, the largest trade fair for IT security in the DACH region
  • Jan - April 2023: What every Java developer should know about Offensive Security at Java User Group meetings in Nuremberg, Zurich, Mannheim, Darmstadt

Contact

Phone:

+49 1577 2068876