Security mentoring for individuals and teams
Security is a product of good engineering with a bit of hacker culture on top.
I mentor software development, product, and security people through pairing, feedback sessions, practical coaching, and focused lectures. My goal is to build a capability within you or your team that stays long after I'm gone. That capability is discernment under uncertainty: validating what works in reality and capping risk instead of trusting prompted answers or debating opinions.
Working with Michal on a greenfield logging and monitoring platform fundamentally changed how I think about secure system design. He doesn't just talk from 10,000 feet: he pair programs, dives into details, and gives feedback that actually improves your code. The biggest shift was learning to look at problems from different angles and practicing real agility, not just ceremonies.
For teams and companies
If you ship software products, you're probably familiar with this pattern:
- Quality and security are seen as expensive luxuries, so they compete with delivery speed, and often get cut
- Risks are vague and fragmented, and they throw unpredictable blockers into delivery plans
- “Compliance” is used as a magic chant to over-compensate or excuse pointless work
The goal of my work is to make quality and security default, not an expensive exception. I do this by:
- Putting everyone on the same side by framing risks explicitly and connecting them to product goals and business impact
- Turning generic “guardrails and checklists” into prioritized controls that are reusable and proportional to your needs
- Designing a development life cycle rooted in discernment: converting uncertainty into hypotheses, testing early and capping risk with explicit decisions
Do you prefer a structured entry instead of open-ended mentoring? The 10-hour Starter takes one feature and builds a risk-focused approach your team can repeat:
- Kickoff (2 hours): scope 1–2 pilot features + rapid risk assessment (quick mirror of your top risks)
- Thinking in systems and threats (2 hours): product-neutral intro to the way of thinking, with interactive examples
- Facilitated work on your product (6 hours): defining a simple process for your team on a pilot feature, identifying gaps, and capturing verification checks to answer “what would convince us it's safe enough?”
Under the hood, this is building a lightweight SSDLC rooted in threat modeling and explicit risk decisions. You finish with:
- At least one real threat model (covering quality and security risks)
- A prioritized risk list
- A named QC/Security Champion who knows how to carry it forward
Book a session or email me / DM on LinkedIn
For individuals and self-funded practitioners
Are you moving into engineering, from engineering to security, or closer to product? Or just curious how resilient systems are built? I offer 1:1 sessions and focused lectures to individuals who are between roles or want to step up their skills.
For many “future practitioners”, their first steps aren't in adopting more security tools, but in building stronger foundations:
- Computer science, operating systems and Linux basics
- Data analysis, automation and maintenance
- Critical thinking: debugging, testing, weighing risk and validating opinions
We can combine these with engineering and security topics like test-driven development, threat modeling, and offensive/defensive techniques so you don't just know what to do, but also have the actual skills and experience to do it.
And if you're from the opposite camp—deep in technical knowledge but need to brush up product thinking, public speaking and presentation—we can work on that too. These skills are an integral part of my curriculum.
Topics we can work on
- Engineering quality and threat modeling
- System architecture and systems thinking
- SOC operations and security monitoring
- Secure development and compliance (a practical delivery perspective)
- Product development and product thinking
- Presentation and public speaking
- Engineering practices and engineering foundations
Book a session or email me / DM on LinkedIn
What you get: skill transfer, not dependency
For teams and companies, this means:
- Discernment habit: converting uncertain risks or “security requirements” into testable hypotheses, then capping risk with an explicit decision
- Creating a simple development life cycle with a handful of reusable patterns instead of one-off fixes
- Training an internal Security Champion so the capability stays when I'm gone
And for individuals:
- A stronger “QC muscle”: you'll learn to validate rather than trust—in a world where you can get all the answers through one prompt
- Impartial guide through role change (engineering, security, product work)
- Practices and homework relevant to where you need the most help
Pricing
- Intro call: free, 30-minute call to clarify goals and fit
- Individual session: 3000 CZK / €125 per hour (billed in 15-minute increments)
- 10-hour Starter: 25000 CZK / €1050 (for teams)
- If you're self-funded (especially between jobs): reduced rates are available
Conditions
- I am not subject to VAT payments
- The intro call is free. No contract required. Please avoid sensitive data
- Follow-up sessions are governed by a formal mentoring contract
- Timezone: Europe/Prague
- Rates are reviewed periodically. The prices shown here are current
Contacts and booking
- Booking page
- LinkedIn profile
- Email: michal at [this site's domain name]
- More options: see Stay in touch page