Speaking & Events
Sharing insights on container security at conferences, workshops, and meetups worldwide.
Upcoming Events
Defense Against the Dark Arts: NPM Attack
enterJS 2026
Dockerize Securely
WeAreDevelopers World Congress 2026
Beyond SBOMs: The Future of Container Supply Chain Security
WeAreDevelopers World Congress 2026
When a single phished NPM maintainer led to 18 compromised libraries—including Chalk and Debug, downloaded billions of times weekly—it proved one thing: SBOMs alone aren’t enough. In this talk, I explore how modern supply-chain attacks unfold and how the next generation of tools—attestations, provenance, and signing—can prevent a repeat of the September 2025 NPM breach.
Past Events
Beyond SBOMs: The Future of Container Supply Chain Security
DevOpsDays Zurich 2026
When a single phished NPM maintainer led to 18 compromised libraries—including Chalk and Debug, downloaded billions of times weekly—it proved one thing: SBOMs alone aren’t enough. In this talk, I explore how modern supply-chain attacks unfold and how the next generation of tools—attestations, provenance, and signing—can prevent a repeat of the September 2025 NPM breach.
Writing a Tech Book: Docker and Kubernetes Security
JobRad Podcast: Increase Cycle Time
Interview on JobRad's tech podcast 'Increase Cycle Time' about the process of writing a technical book.
Java Supply Chain Security with Docker
JCON Europe 2026
Interview with Baruch Sadogursky at JCON Europe
JAVAPRO / Tessl
Docker Commandos v1.5
Rabobank
Docker Commandos v1.5 at Rabobank, part of their Docker Champions program. Full supply-chain security pipeline from Docker Init to cryptographic signing and zero-day runtime defense.
Dockerize Securely
Jfokus 2026
#cTENcf Birthday Bash Freiburg
Docker Freiburg and Black Forest Meetup
10 Docker Commandos
JobRad GmbH
The first private Docker Commandos workshop — v1.0 format delivered to the JobRad engineering team in Freiburg. Small group, fully hands-on.
Docker Captain, DevSecOps, and Developer Advocacy
TACOS Podcast
Docker Deep Dive with a Docker Captain
WeAreDevelopers World Congress
Speaking Topics
A deep dive into the September 2025 NPM supply chain attack—one of the largest in history—and how to defend your enterprise JavaScript applications.
View TopicWhen a single phished NPM maintainer led to 18 compromised libraries—including Chalk and Debug, downloaded billions of times weekly—it proved one thing: SBOMs alone aren’t enough. In this talk, I explore how modern supply-chain attacks unfold and how the next generation of tools—attestations, provenance, and signing—can prevent a repeat of the September 2025 NPM breach.
View TopicA Jfokus talk on building secure container images using SBOMs, OCI 1.1 attestations, and Docker Bake, told through the narrative of the Docker Commandos in Asgard.
View TopicCelebrating the 10th anniversary of the CNCF, Hacktoberfest, and publication of Docker and Kubernetes Security.
View TopicA PlatformCon talk on 10 lesser-known Docker commands for improving development workflows, vulnerability scanning, supply chain security, and local AI workflows.
View TopicInvite Me to Speak
Available for conferences, workshops, corporate training, and meetups. I can present remotely or travel to your event.
Talk Formats:
- • 20-45 minute talks
- • Half-day workshops
- • Full-day training
- • Panel discussions
Requirements:
- • Travel and accommodation covered
- • Recording permission preferred
- • Slide sharing encouraged
- • 4-6 weeks advance notice
