Cyber Security Engineer @ NewCold · Breda, Netherlands 🇳🇱
I moved from securing systems to governing them. Cybersecurity protects your data; AI governance protects your decisions. I work in the overlap — AI security, AI risk assessment and EU AI Act readiness — and I build the tooling that turns frameworks into things engineering teams can actually implement.
JKasteele/ai-act-companion — a local-first, explainable EU AI Act risk classifier that cites the exact Article and Annex behind every verdict, and generates what comes after the classification.
- Deterministic rule engine, not an LLM guessing — prohibited / high-risk / limited / minimal tiers, every verdict cited
- 21 governance & assurance reports — DPIA, FRIA, Annex IV technical documentation, conformity tracking, post-market monitoring plan, control catalogues, red-team plans
- AI security built in — architecture-aware severity mapped to OWASP LLM Top 10 (2025) and MITRE ATLAS, with an offence↔defence loop linking each red-team test to the control that verifies it
- Runs where you work — CLI, Python API, MCP server / Claude Code plugin, GitHub Action, or the live demo
- 270 automated tests · 95% coverage · MIT ·
pip install ai-act-companion
Owner of five security competencies at NewCold: AI Security, Security Operations, Email Security, Endpoint Security and Security Awareness. On the AI side, that looks like:
- EU AI Act readiness — risk classification, Article 15 gap analysis, Annex III / IV scoping, and the templates that make it repeatable
- End-to-end AI risk assessments — STRIDE threat models, likelihood × impact risk registers, DPIAs, control catalogues, prioritised remediation
- Adversarial testing — prompt injection, jailbreaking and data extraction, mapped to the OWASP Top 10 for LLM Apps and MITRE ATLAS
- Frameworks → controls — NIST AI RMF, ISO/IEC 27001:2022 and NIST CSF 2.0, translated into things engineering teams can implement
- Earlier: delivered a full EU AI Act high-risk assessment for an AI-powered HR app — risk assessment · DPIA · bias audit
Reading the EU AI Act is the easy part. The work is producing the artefacts that survive contact with a real system, then sitting down with the engineers who have to act on them.
- CompTIA SecAI+ (CY0-001) — securing AI systems, adversarial testing, AI governance
- Associate of ISC2 — CISSP exam passed
- AI Security Foundation (S-AISF) — SECO-Institute
- BSc Cyber Security & Cloud — Hogeschool Utrecht
Python · PowerShell · Docker · LLM red-teaming (Garak / PyRIT) · agentic AI & MCP · Microsoft Defender XDR / SIEM · Microsoft Intune
Dutch and English · EU citizen · based in the Netherlands, working across CET.
Always glad to talk with people working on AI assurance, AI security or EU AI Act implementation. It's a small field and it's moving quickly.



