Больше информации по резюме будет доступно после регистрации

Зарегистрироваться
Was today at 14:58

Male

Moscow, not willing to relocate, prepared for business trips

Information security officer / Information security auditor

Specializations:
  • Information security specialist

Employment type: full time, project work/one-time assignment

Work experience 17 years 8 months

January 2024July 2025
1 year 7 months

Russia, www.rostelecom.ru

IT, System Integration, Internet... Show more

Information security architect
*Development of security architecture solutions for various information systems. * Architectural control of implemented and enhanced IS from the information security point of view.
December 2021January 2024
2 years 2 months

Moscow, rabota.sber.ru/

Financial Sector... Show more

Chief Engineer
As an expert in information security, my tasks include the following: - ensuring the safety of software development for stock trading, working in agile teams - setting up security controls around software development processes and integrations with external information systems and cloud services - developing and monitoring security requirements during architectural design of solutions - participating in the design of information flows, determining a secure infrastructure for projects - coordinating information security issues with the risk assessment committee - improving the safety of software assembly and deployment procedures - static testing of security products, conducting acceptance tests from the perspective of information security - coordinating role models in existing information systems
March 2018December 2021
3 years 10 months
Sibintek

IT, System Integration, Internet... Show more

Information security manager
Development of a new area — information security audit for Rosneft company: * development of methodology (procedures, questionnaires, etc.) for the new activity area — information security audit; * selection, training and management of the working group of 4 specialists; * conducting information security audits at the facilities of Rosneft and its subsidiaries. Development of architecture and practical deployment of software verification service for compliance with information security requirements: * training of 3 specialists in conducting software testing for compliance with information security requirements; * practical testing of the service using a controlled software environment (sandboxing); * methodological support for the service operation. Participation in organizational and methodological support of information security incident response center (SOC) deployment. Results: * developed IT audit area, created process audit methodology, formed and trained a team; * created and implemented software verification service for compliance with information security requirements (sandboxing), trained specialists, which increased the level of security when implementing software for Rosneft.
December 2015March 2018
2 years 4 months
GIVC ROSKULTURY - MINISTRY OF CULTURE RF
Senior Information Security specialist
• Maintain IS infrastructure • Detect and investigate security incidents • Design and implement security policies • Perform continuous vulnerability management process • Operate FW, IPS, VPN
December 2013June 2015
1 year 7 months
RostBank
Senior Security Engineer
• Implement DLP system in the Bank • Perform continuous vulnerability scanning • Perform security procedures design and implementation
November 2012October 2013
1 year

www.at-consulting.ru

IT, System Integration, Internet... Show more

Senior Security Specialist
•Perform SIEM administration •Perform continuous vulnerability scanning •Detect and investigate security incidents •Perform Assets management in SIEM
June 2007October 2012
5 years 5 months

www.raiffeisen.ru

Financial Sector... Show more

Security Analyst
Participated in the security audit of the information systems of the Bank branches. Provides control to eliminate violations. Conducted a technical audit of information systems. provides training recommendations for elimination of violations identified during the audit. Provides design, commissioning and operation of the various subsystems of the information security infrastructure (~10 000 ws) Participated in the development of regulatory documents Participated in the Incident Response Team

Skills

Skill proficiency levels
Advanced level
Information Security
Cisco
Cuckoo sandbox
Medium level
Network security
SIEM
DLP
MaxPatrol
НСД Dallas Lock
Kaspersky Labs
IPS
L3 VPN
УЦ VipNet
Sandboxing
Cloud data security
information security Incident Management
Basic level
Infowatch
Forensic
Level not specified
SEIM (HP ArcSight ESM)
Vulnerability management
DeviceLock
vGate
Vulnerabilitu scan
Cloud security
Cloud infrastructure security
information security ISC2
BPML

Driving experience

Own car

Driver's license category B

Higher education

1995
Higher education

Languages

Russian — Native

English — C1 — Advanced

Professional development, courses

2025
Software Architect
Skillbox, Software Architect
2022
ISC2
ISC2, Assessing Application Security
2022
ISC2
ISC2, Introduction to Artificial Intelligence (AI)
2022
ISC2
ISC2, Exploring Cybersecurity in Industrial Control Systems
2022
ISC2
ISC2, Building a Strong Culture of Security
2022
ISC2
ISC2, Securing Containers at the Speed of DevOps
2022
Sberbank corporate university
Sberbank corporate university, Monitoring & alerting
2022
Sberbank corporate university
Sberbank corporate university, containers in enterprise
2022
Sberbank corporate university
Sberbank corporate university, introduction to Kubernetes
2022
Sberbank corporate university
Sberbank corporate university, process mining
2022
Sberbank corporate university
Sberbank corporate university, Introduction to process modeling language BPML 2.0
2022
Sberbank corporate university
Sberbank corporate university, Introduction to Istio service mesh
2022
Sberbank corporate university
Sberbank corporate university, Cloud platform architecture & security
2021
ISC2
ISC2, Preparing for a Zero Trust Initiative
2021
ISC2
ISC2, Conducting Practical Risk Analysis
2020
ISC2
ISC2, Incident Management: Preparation and Response
2020
ISC2
ISC2, Introduction to the NIST Cybersecurity Framework
2020
ISC2
ISC2, Responding to a Breach
2020
ISC2
ISC2, Leveraging the Intelligence Cycle
2020
Purple Team Playbook
ISC2, Running a cybersecurity team
2020
autopsy.com
autopsy.com, Autopsy Basics and Hands On
2020
ISC2
ISC2, Practical Intrusion Analysis Using the Diamond Model
2020
ISC2
ISC2, Security Analysis with SPARTA
2020
Project Management Institute
«Specialist» Computer Training Center, Project management using MS Project Professional (UPR-J-2018)
2018
Micro Focus ArcSight (ESM/Express)
Axsoft, Analyst
2017
Certified Information Systems Security Professional (CISSP)
(ISC)², Certified Information Systems Security Professional (CISSP)
2016
VIPNet Win&Lin 3.2 administration
Infotecs, VIPNet Win&Lin 3.2 administrator
2015
Information security (professional retraining, 642 learning hours)
Moscow Bauman State Technical University, Moscow, Information security specialist
2014
Advanced Persistent Threat protection
dialog nauka, Advanced Persistent Threat protection
2014
Infowatch Traffic Monitor 4 administration
Infowatch, Infowatch Traffic Monitor 4 administratior
2013
Check Point Security Administrator R75
Diona master lab, Check Point Security Administrator R75
2013
Сheck Point Security Expert R75
Diona master lab
2008
Cisco NW Device Security
Global Knowledge Network GmbH (Vienna)
2007
Wireless Hacking Hands-On
Network Training Center UNI
2007
Hands-On Hacking Webapplications
Network Training Center UNI
2007
Hands-On Hacking Unlimited
Network Training Center UNI
2006
Сheck Point Security administration NGX 1-1
Network Training Center UNI
2006
Сheck Point Security administration NGX 1-2
Network Training Center UNI
2004
Securing Cisco IOS Networks (SECUR)
Ciscotrain
2004
Cisco Secure PIX Firewall Advanced (CSPFA).
Ciscotrain

Tests, examinations

2021
SkillFront
SkillFront, ISO/IEC 27001 Information Security Associate
2020
ISC2
ISC2, Incident Management: Preparation and Response
2020
ISC2
ISC2, Purple Team Playbook
2020
(ISC)²
(ISC)², Introduction to the NIST Cybersecurity Framework
2020
(ISC)²
(ISC)², Responding to a Breach
2019
(ISC)²
(ISC)², Certified Cloud Security Professional (CCSP)
2019
AXELOS
Peoplecert International Ltd., ITIL Foundation
2017
(ISC)²
(ISC)², Certified Information Systems Security Professional (CISSP®)

Citizenship, travel time to work

Citizenship: Russia

Permission to work: Russia

Desired travel time to work: Doesn't matter