John Buehrer
Kernkompetenzen
With a background of close to 25 years in DevOps and more than 15 years of in-depth experience in DevOps security, mostly in the financial and the public sector, John is extremely well positioned to frame IT security in strongly regulated environments. Recently, this exposure increasingly included AI-related security and governance topics, providing him we the necessary insights into the specifics of a fluid and non-deterministic environment.
His recent approach to AI was to deliberately move to extensive experimental AI work, which has given him an exhaustive understanding of the specifics of an AI environment and its particular challenges.
That work trains a particular reflex: assume the system is wrong until it proves otherwise, and don't confuse a demo with something that survives production.
He started turning that reflex on AI with small software projects and good results — commercially ready and source-available. His code is gated on SAST and DAST security reviews before publication, with documented triage decisions.
John's emerging AI work covers security and operational integrity within AI systems, including key and secret handling, supply chain, deployment hardening, and what evidence survives for future audits.
He advocates an "arbitrage master" role for entry-level junior engineers using multiple AI models to add value and gain work experience, rather than being "replaced" by AI in the first place.
John often uses "AI through humor" to explain topics, keeping the human element in view.
John obtained a BsC in Computer Science & Engineering at the University of Michigan and has extensive certified knowledge in the areas relevant to secure DevOps environments.
Downloads
Referenzprojekte
CertGrep Suite — AI-assisted development under governance
Post-quantum-aware X.509 analysis toolkit, built with AI pair-programming and AI-driven SAST/DAST security scans. EU AI Act compliant.
mehr...Curiosity Lab — making LLM behavior visible
Desktop client for Claude and other popular LLM frontier models, with a simple system prompt and predefined "curiosity riders" for demos.
mehr...Web-Print — a tool packaged as a Claude agent skill
A page-capture utility as a Claude Code skill and plugin, to fix poorly printing web pages due to HTML/CSS gaps.
mehr...Keyfactor EJBCA — AI-assisted code contributions, merged by the vendor
Code developed with AI assistance for the open-source EJBCA K8S cert-manager issuer, submitted to the vendor and accepted.
mehr...This is a post-quantum-aware X.509 analysis toolkit, built with AI pair-programming and used as
the working laboratory for a governance regime around AI-written code: per-release SAST
and DAST with a written reason for anything left unfixed, an EU AI Act scoping
assessment of the product, and a documented risk review of the AI vendor it depends on.
https://gitlab.com/umi-ch/cert-grep
https://gitlab.com/umi-ch/cert-grep/-/tree/main/insights
- AI Transformation
- Automatisierung
- Infrastructure Management
- Mensch-Maschine-Interaktion
This is a desktop client for Claude and other popular LLM frontier models. It provides a simple system prompt but also predefined (and customizable) per-turn "curiosity riders" (injection) as separate controls, alongside a running cost meter. Built so a client can watch what prompt design actually changes — in the answer, and on the bill — instead of being told.
https://github.com/John-D-B/Curiosity-Lab-for-Claude
- KI-Strategie
- Kundeninteraktion
- Mensch-Maschine-Interaktion
A page-capture utility distributed both as a command-line tool and as a Claude Code skill and plugin, with strict invocation rules so that an agent knows when not to run it. Shipped with a published security assessment and disclosed residual risk.
https://github.com/John-D-B/web-print
- AI Transformation
- Governance
- Infrastructure Management
- Mensch-Maschine-Interaktion
Code developed with AI assistance, submitted to Keyfactor's open-source EJBCA cert-manager issuer and merged by its own maintainers in March 2026. An external check on whether AI-assisted work survives review by people with no stake in the method. AI pair-programming saved substantial amounts of time and know-how onboarding in order to fix this relatively simple problem.
https://github.com/John-D-B/ejbca-cert-manager-issuer
https://github.com/John-D-B/ejbca-ce