Jonatan Männchen

CEO

Winterthur, Zurich, Switzerland10 yrs 9 mos experience
Highly Stable

Key Highlights

  • CISO leading security initiatives for the Erlang ecosystem.
  • Expert in Elixir and Erlang with extensive open-source contributions.
  • Proven track record in developing secure, scalable solutions.
Stackforce AI infers this person is a Fintech and SaaS expert with a strong focus on security and architecture.

Contact

Skills

Core Skills

Information SecurityTeachingCloud ComputingSystem ArchitectureElixirOpenid ConnectSolution Architecture

Other Skills

Information Security ManagementSQLMicrosoft AzureKubernetesphoenixErlangAshGPU-accelerated calculationsGraphQLPHPSymfonyRESTPostgreSQLForklift OperationjQuery

About

I am a software engineer and ecosystem security leader with a deep focus on the Erlang, Elixir, and Gleam communities. Today I serve as the Chief Information Security Officer of the Erlang Ecosystem Foundation, where I lead several large-scale initiatives that strengthen the supply chain security and long-term resilience of the BEAM ecosystem. My work includes establishing the Ægis Initiative, operating the EEF CNA (our CVE authority for Erlang/OTP, Elixir, Gleam, and Hex packages), and driving key improvements across our toolchain: signed and verifiable release pipelines, Hex.pm vulnerability handling, OpenVEX support, SCITT/attestation integrations, and ecosystem-wide compliance efforts across standards such as OpenChain, SLSA, SSDF, and SBOM formats. As an open-source maintainer, I build and maintain tools that make BEAM systems more observable, secure, and introspectable — including Clarity, Atlas, Crux, purl, and several Ash ecosystem tooling projects. I regularly collaborate with language maintainers and commercial partners to modernize and harden the BEAM supply chain end-to-end. Before focusing on ecosystem security full-time, I spent over a decade as a lead engineer and architect, designing distributed systems, developer tooling, and data-heavy backend services for companies across industries. I speak at conferences such as Code BEAM on security, identity, and large-scale open-source coordination, and I’m passionate about advancing security and reliability practices across open-source ecosystems in a way that preserves their flexibility, transparency, and collaborative strengths.

Experience

Erlang ecosystem foundation

Chief Information Security Officer

Jan 2025Present · 1 yr 2 mos · California, United States · Remote

  • As the Chief Information Security Officer at the Erlang Ecosystem Foundation (EEF), I drive security initiatives across Erlang, Elixir, Gleam, and the broader community. My role involves analyzing and implementing data protection, compliance, and secure development practices—particularly focusing on requirements like EU CRA/CISA and supply chain integrity. I maintain the EEF’s CNA (CVE Numbering Authority), ensuring vulnerability disclosures are managed effectively. I also collaborate closely with volunteer working groups, design software solutions for security challenges, and actively engage in fundraising activities.
Information Security ManagementInformation Security

Ict berufsbildungscenter ag

Course Instructor

Dec 2023Present · 2 yrs 3 mos · St Gallen, Switzerland · On-site

  • ÜK Kursleiter für Informatiker/in EFZ Applikationsentwicklung
  • Modul 210 Public Cloud für Anwendungen nutzen
  • Modul 106 Datenbanken abfragen, bearbeiten und warten
  • As a course instructor at ICT Berufsbildungscenter AG, I am responsible for guiding and mentoring apprentices in the field of software engineering during their multi-week courses as part of their EFZ apprenticeship in Switzerland. My role involves delivering comprehensive instruction on specialized topics, including the use of public cloud for applications (Modul 210) and querying, editing, and maintaining databases (Modul 106). I introduce new concepts through detailed presentations, support apprentices in their self-learning endeavors by providing additional explanations, troubleshooting assistance, and deepening their understanding of complex topics. Furthermore, I am responsible for conducting examinations and grading to assess their knowledge and skills development. My focus is on fostering a learning environment that equips apprentices with the technical expertise and problem-solving abilities necessary for their professional growth.
Information SecurityTeachingSQLCloud ComputingMicrosoft Azure

Erlang ecosystem foundation

Open Source Developer

Sep 2023Sep 2023 · 0 mo · Remote

  • As an open source developer contracted by the Erlang Ecosystem Foundation, I was responsible for designing and implementing a robust OpenID Connect solution for the Elixir/Erlang ecosystem. My work included developing a certified OpenID Connect implementation, verified by the OpenID Foundation, and creating multiple companion libraries for the Erlang web server, Cowboy, as well as for the Elixir web framework, Phoenix/Plug. I also developed a generator to streamline the setup process for Phoenix projects, enabling faster and more efficient project initialization. Beyond the initial release, I maintained the project, ensuring its ongoing stability and performance, and provided support for integrating the implementation into other projects. Additionally, I contributed to the implementation of the Financial-grade API (FAPI) 2.0 standards, enhancing security and functionality within the ecosystem. To showcase this project, I delivered a talk at Code BEAM America, highlighting its features, development process, and impact on the community.
Information SecurityphoenixOpenID ConnectElixirErlang

Sustema ag

Technology Lead

Jun 2020Dec 2024 · 4 yrs 6 mos · Zurich, Switzerland

  • As Lead Engineer at Sustema AG, I played a key role in shaping both the technical architecture and business strategy of the company, which focuses on using ESG and behavioral analytics to enhance the underwriting processes for insurers globally. My responsibilities included leading the architecture and planning for all of Sustema's applications, ensuring they were scalable, efficient, and aligned with our business goals.
  • In addition to my architectural work, I contributed to defining Sustema's business offerings and strategy, collaborating closely with the leadership team to align our technical capabilities with market demands. I was also responsible for the development and implementation of a powerful calculation engine, built using Elixir, which incorporated GPU-accelerated calculations to enhance the scoring system used by insurers for real-time analytics.
  • Another significant aspect of my role was the development of an entity resolution service, which merged data from more than 10 different entity data sources into a single, coherent set of information. This service provided insurers with comprehensive and accurate data, enabling better underwriting decisions.
  • Furthermore, I led the technical implementation of pilot projects with multiple insurers, focusing on demonstrating the capabilities and effectiveness of Sustema's solutions in real-world environments. This work played a key role in driving adoption and validating our technology within the industry. My contributions at Sustema AG have been instrumental in launching innovative solutions that have the potential to transform the insurance industry’s approach to risk assessment and sustainable business practices.
Information SecurityKubernetesphoenixSystem ArchitectureOpenID ConnectElixir+3

Joshmartin gmbh

Partner / Technology

Sep 2016Aug 2023 · 6 yrs 11 mos · Switzerland

  • As a Partner and Lead Technology at JOSHMARTIN GmbH, a Swiss software consultancy, I played a key role in guiding the company's strategic direction and overseeing its operations. My responsibilities included co-leading the company, which involved shaping strategy, making employment decisions, and managing overall business operations. I directly led a team of four engineers, defining project scopes with customers, planning and estimating implementations, and managing the successful execution of projects. My technical contributions were primarily focused on backend development, with extensive work using Elixir/Phoenix, but I also contributed to frontend development with VueJS. Additionally, I coordinated the setup and maintenance of hosting environments using Kubernetes, ensuring reliable and scalable deployments for our clients.
  • Among the notable projects I led were the development of an asset management consultation tool for acrevis Bank AG and a COVID-19 contact tracing application for the cantons of Appenzell Ausserrhoden, Appenzell Innerrhoden, and St. Gallen. The latter project was instrumental in helping local health departments manage the pandemic, and I had the opportunity to present this work at Code BEAM V Europe.
Information SecurityGraphQLKubernetesphoenixSystem ArchitectureOpenID Connect+3

Pwc

Senior Software Engineer

Sep 2015Aug 2016 · 11 mos · Zürich Area, Switzerland

  • As a Senior Software Engineer at PwC Experience Center, I played a crucial role in delivering several high-impact projects and driving internal improvements. My responsibilities primarily focused on backend development, where I was involved in the implementation of various significant projects, including the Bexio Banking Integration, a video learning platform for orthopedic surgeons, and a car auction platform. Additionally, I conducted an internal review of a large software project at PwC Switzerland, ensuring alignment with best practices and company standards.
  • Beyond technical development, I was instrumental in establishing team structures for effective project management and implementing processes aimed at improving code quality across the board. I also managed internal networking efforts to foster collaboration and knowledge sharing within the organization, contributing to a more cohesive and efficient development environment. My work not only delivered critical solutions to clients but also enhanced the overall technical capabilities and processes within the PwC Experience Center.
Information SecurityPHPSymfonyOpenID ConnectRESTSolution Architecture

Mediahead ag

Software Engineer

Jan 2015Aug 2015 · 7 mos · Zürich Area, Switzerland

  • As a Software Engineer at Mediahead AG, I was responsible for maintaining and refining the Mediahead Tools, primarily developed on Symfony 2, as well as working on other smaller projects using Flask (Python) and Express.js. I held full-stack responsibilities, managing everything from the user interface and frontend development to business logic, backend integration, and database management. I played a key role in planning the architecture for the next version of the Mediahead Tools, ensuring scalability and efficiency. Additionally, I led the migration from root servers to Platform as a Service (PaaS), enhancing the deployment and management of our applications.
Information SecurityPHPSymfonySolution Architecture

Swiss air force

private 1st class - aircraft mechanic

Mar 2014Dec 2014 · 9 mos · Locarno

  • During my mandatory military service with the Swiss Air Force, I served as a Private 1st Class Aircraft Mechanic. Throughout my service, I was responsible for performing essential maintenance tasks on aircraft, conducting thorough checks to ensure operational readiness, and troubleshooting any mechanical issues that arose. My role also included carrying out small repairs to maintain aircraft functionality and safety. Additionally, I maintained clear and effective communication with pilots to address their concerns and ensure that all aircraft were in optimal condition for their missions. My service was focused on maintaining the high standards required for military aviation, contributing to the overall success of the Swiss Air Force operations.

Amiado group / axel springer

2 roles

Web Developer / Instructor

Aug 2012Mar 2014 · 1 yr 7 mos · Zürich Area, Switzerland

  • As a Software Engineer and Instructor, I returned to the company where I completed my apprenticeship, transitioning from a learner to an educator while continuing to develop my technical expertise. In this role, I took on the responsibility of training and mentoring new apprentices, guiding them through the complexities of software development and helping them build a strong foundation in the field.
  • In addition to my instructional duties, I played a key role in the relaunch of partyguide.ch, where I worked on transitioning the platform to a new technology stack. This project involved modernizing the site, improving its performance, and ensuring it met contemporary web standards. My contributions spanned across various stages of development, from planning and architecture to implementation and deployment, further solidifying my experience in both software engineering and technical education.

Apprentice "Informatiker Applikationsentwickler EZF"

Aug 2008Aug 2012 · 4 yrs · Zürich Area, Switzerland

  • As an Apprentice "Informatiker Applikationsentwickler EFZ," I gained hands-on experience working on large-scale web platforms, including students.ch, partyguide.ch, and usgang.ch. These platforms, primarily built in PHP, provided me with a solid foundation in application development. During my apprenticeship, I was involved in various aspects of the development process, from coding and debugging to implementing new features and maintaining existing ones. This experience allowed me to develop a strong understanding of web development, particularly in PHP, and equipped me with the skills necessary to build and manage robust online platforms.
Information SecuritySolution Architecture

Education

Berufsbildungsschule Winterthur

EFZ — Informatiker Applikationsentwickler

Jan 2008Jan 2013

Schulhaus Oberseen

Schulabschluss Sekundarschule — Sekundarschule Profil A

Jan 1999Jan 2008

Stackforce found 100+ more professionals with Information Security & Teaching

Explore similar profiles based on matching skills and experience