Больше информации по резюме будет доступно после регистрации
ЗарегистрироватьсяOnline
Male, 52 years, born on 27 March 1974
Moscow, willing to relocate (Other regions), prepared for business trips
IT Security manager
Specializations:
- Information security specialist
Employment type: full time
Work experience 28 years 4 months
December 2018 — currently
7 years 5 months
Sberbank
Head of corporate business protection
- Lead the team;
- Drive IT Security architecture designs and implementation of security solutions;
- Drive engineering and reporting quality improvements;
- Ensure compliance with internal standards and regulatory requirements;
- Contribute to the management of the technology direction and roadmap of security tools, investigate technologies;
- Leads the Project Management groups, provide consultancy to other teams.
June 2017 — December 2018
1 year 7 months
VTB Capital
Moscow, www.vtbcapital.com
Financial Sector... Show more
Lead of Security engineering and architecture
- Lead the team;
- Drive IT Security architecture designs and implementation of security solutions;
- Drive engineering and reporting quality improvements;
- Ensure compliance with internal standards and regulatory requirements;
- Manage security incidents in interaction with other support functions, internal audit and IT Security;
- Developing procedures for managing business continuity and disaster recovery in relation to security tools;
- Contribute to the management of the technology direction and roadmap of security tools, investigate technologies, run proof of concepts and preparation of success criteria;
- IT security audit of a subsidiary, preparation of risk list and remediation plans;
- Be a part of a global support in order to support and maintain the bank’s security tools;
- Manage the on boarding of new security tools to monitoring system;
- Preparation of department budget, control and reporting to management;
- Leads the Project Management groups, provide consultancy to other teams.
Experience in the design, implementation and maintenance of security tools and technology: End-point protection, Imperva DAM, Splunk, Symantec Control Compliance suite, Privilege access management; APT, NBA, Cisco ACS, Quest Change auditor, ObserveIT, Jam boxes, Password vaults.
Most of the negotiations and all correspondence in the company are in English.
Now in preparation for the CISM exam.
October 2003 — June 2017
13 years 9 months
Croc Incorporated.
Moscow, www.croc.ru/eng/
IT, System Integration, Internet... Show more
IT Security Technical Manager
- Own and maintain overall methodology, process and documentation for projects
- Leads the Project Management group
- Providing the full range of Information Security Consulting Services to Clients.
- Conducting information security Audits, Risk Assessments.
- Developing the Architecture and Concept documents on Information Security Systems.
- Conducting the full range work on Information Security Systems design (Technical Scope, Draft Project, Technical Project with key technology choices, Security Policies, Procedures and Standards, Working Documentation) in accordance with Russian and international standards.
- Presale work, preparing technical and commercial offers. Holding negotiations with Clients and Partners. Making reports at the seminars and conferences.
- Communicates with IT leadership and Business leadership to communicate IT Processes, strategy, direction, and changes
- Scheduling and conducting periodic review sessions with department team leads to assess individual team progress and propose tactics in implementation
- Identify and advise of scheduling contingencies and mitigation
- Monitor project cost control
Experience in the pre-sale, design, implementation of security tools and technology: Network security (NGFW/IPS, VPN, Anti DDoS, NAC, Secure WiFi, SSO, DAM), AntiFraud, Infratructure security(Antivirus, Device/APP control, Antispam, MDM, Personal cloud security, DataDiode), Data security (DLP, Printing control, PKI, HSM, Data encryption), Security governance (SIEM, UEBA, Vulnerability scanners, UAM), IT Security audit and certification readiness, compliance management, PII).
The major training courses: IBM project management, ISO27001 standard auditor, project risk management, different security product courses (Check Point, RSA Security,..).
Methodologies & standards: MSF, ISO 27001
January 1998 — October 2003
5 years 10 months
SVET Computers
Moscow
IT, System Integration, Internet... Show more
System engineer
Participation in architectural design of infrastructure system;
Participation in delivery of project results like architectural design and implementation of infrastructure system;
Delivery of operational guides;
Consultancy in network and system applications;
Assessment of current state of customers's systems;
Support and maintenance for corporate firewalls and proxy servers, operating FreeBSD ipfw, SQUID and MS ISA;
Developed and periodical actualization of firewalls & data access security polices;
Took part in company public web & database servers system & application security assessment & periodical stability/security testing;
Provided end-user support on PC hardware and Microsoft products (Windows/Office) for primer corporate customers, including service calls and hardware/software installations at client’s site.
Skills
Skill proficiency levels
About me
Significant experience in organizing large-scale project works and leading a team of specialists; deep knowledge in information security; knowledge of legal and technical aspects of information security; experience in implementing a family of infrastructure products and information security systems in heterogeneous environments; experience in designing and deploying large IT infrastructures; experience in the development of design and technical documentation in accordance with the requirements of GOST 34XX; knowledge in the field of methodologies and standards for the creation of information systems (MSF, GOST 34XX). Experience in auditing for compliance with requirements and bringing in compliance with the standards of the IS of Russia and international (27001, PCI DSS, 152-FZ, STO BR). Experience of large-scale IS projects with geographically distributed structure (whole RF). Experience working with the largest Russian companies (energy, manufacturing, financial organizations, government agencies, commodity companies). The experience of creating large architectural solutions of IS "from scratch."
Deep knowledge of II Security technologies and products of leading companies in the field of information security: Symantec, Imperva, ObserveIT, Splunk, RSA Security dev, Symantec, Microsoft, IBM, Websense, Check Point, StoneSoft, Aladdin, Trend Micro, Cisco, SafeNet, including Russian IZ, Elvis +, Infotex. Certificates of these companies.
Higher education
1997
Higher education
Bauman Moscow State Technical University (BMSTU)
Information technology, Engineer
Languages
Professional development, courses
2011
Комплексная защита персональных данных в информационных системах персональных данных
АИС
2010
Project management Fundamental
IBM
2010
Risk management
IBM
2010
Внедрение системы управления информационной безопасностью для соответствия требованиям м/н стандарта ISO/IEC 27001
АИС
2009
курсы по ведению переговоров и презентаций
УЦ
2008
MSF управление проектами
MS
2007
Комплексная защита информации в организации
Маском
2007
Теория и практика применения PKI
ИЗ
2007
курсы по проектированию и внедрению систем информационной безопасности с использование продуктов Microsoft
MS
Tests, examinations
2008
Теория и практика применения PKI
ИЗ
2006
Trend Micro Certified Security Master
TM
2005
Check Point Certified Security Expert
ChkP
2005
RSA Certified Security Professional
RSA
2004
Microsoft Certified Systems Engineer : Security
MS
Citizenship, travel time to work
Citizenship: Russia
Permission to work: Russia
Desired travel time to work: Doesn't matter
