IT Security Consultant
Přehled
Krátké shrnutí
Kandidát je senior konzultantem v oblasti bezpečnosti IT. Pracoval na vývoji, implementaci a dokumentaci procesů nebo auditů podle norem ISO/IEC 27001 a ISO/IEC 9001. Kromě GDPR měl na starosti například systémy státní správy nebo zákon o zdravotní péči. Pracoval také jako vedoucí oddělení IT, kde řídil více než 10 zaměstnanců. Hovoří plynně anglicky.
Pracovní zkušenosti
10/2021 - Present
Information Security Consultant
Technology sector
- Information security implementation in development projects,
- Implementation v controls according to cyber law
- Development of business continuity and disaster recovery plans,
- Performing risk analysis and risk management activities,
- Other IT security related consulting services.
05/2015 - 09/2021
Senior Security Consultant & Technical Lead
Security sector
- Implementation of cyber security requirements according to Cybersecurity Law 69/2018 for three companies,
- Identification of legal and contractual compliance requirements and leading their implementation in company (GDPR, Cyber security Law, Government information systems Law, Health Care Law, etc),
- Recommendation of technical and procedural controls to increase resilience against cybersecurity threats,
- Setting up processes of cybersecurity incident handling in compliance with Slovak cybersecurity law,
- Risk analysis and risk management activities – design of risk management processes with all involved parties, realization of risk analysis, communication of results to management, including recommendation of controls to address risks identified,
- Business continuity activities – BIA, strategy, business continuity and disaster recovery planning for several clients (manufacturing company, government companies, power distributor company, commercial companies),
- Configuration of RSA Archer tool (BIA, DRP, vulnerability management, risk management, etc),
- Development and implementation of documentation, processes and audits according to ISO/IEC 27001 standard requirements
- Preparation of companies for ISO/IEC 27001 and ISO 9001 certification.
- Internal audits at the company and clients according to ISO27001.
- Other IT security related consulting services.
02/2019 - 02/2020
Senior Security Consultant
Consultancy sector
- Risk analysis and risk management activities,
- Business continuity activities – BIA, strategy, business continuity and disaster recovery planning and testing,
- Development and implementation of documentation according to ISO/IEC 27001 standard requirements
- Preparation of companies for ISO/IEC 27001 and ISO/IEC 9001 certification.
- Other IT security related consulting services.
07/2012 - 06/2014
Senior Information Security Consultant
Technology sector
- Risk analysis and risk management activities,
- Proposition of controls to mitigate risks,
- Proposition of policies and procedures related to information security,
- Information security audits,
- Other IT security related consulting services.
02/2010 - 02/2012
Senior Information Security Consultant
Technology sector
- Information security specialist for development projects (over 16,5 mil. €),
- Business continuity and disaster recovery plans,
- Performing risk analysis and risk management activities,
- User access policies for information systems (definition of user processes and user rights according to business needs),
- Preparing company to achieve ISO/IEC 27001 certification of information security management,
- Other IT security related consulting services.
02/2007 - 07/2009
Senior Information Security Consultant
Technology sector
- Design of information security management system in complex environments (clients with 4000+ employees and 600+ applications),
- Design and realization of security risk analysis in complex environment,
- Implementation of information asset classification program,
- Development and implementation of isms in compliance with ISO/IEC 27001 standard,
- Other IT security related consulting services.
10/2005 - 09/2006
Head of IT Security Department
Banking sector
- Management of 15 employees,
- Implementation of identity and access management project – role-based access,
- Security operations of certification authority for internet banking and home banking clients,
- Development and implementation of security policies and procedures,
- Definition of security requirements for new projects,
- Internal/external security incident management and investigation,
- Other security related activities.
10/2004 - 09/2005
Manager for Security Related Products
Technology sector
- Network security projects – DMZ, firewalls, IPS, IDS, authorization servers, VPN, …
- Security projects for protection of classified information,
- Development and implementation of policies,
- Projects for protection of personal information,
- Hardening of applications and operation systems,
- Information security risk analysis,
- Other security related activities.
08/1997 - 8/2004
Head of IT Security Department
Banking sector
- Development of IT security policy,
- Development of IT security framework,
- Business continuity plans,
- Security inspections at branches,
- Development of user procedures,
- Risk analysis – CRAMM,
- Other security related activities.
- Head of the Year 2000 project,
- Member of teams implementing new products - responsibility for information security.
EDUCATION
1992 – 1997
Comenius University Bratislava
Specialization Theoretical informatics
Thesis on information security (Cryptanalyses of shift registers with nonlinear feedback function)
CERTIFICATIONS
- CISA - Certified Information Systems Auditor
- CISM - Certified Information Security Manager
- CISSP - Certified Information Systems Security Professional
- ISSMP - Information Security Management Professional
- CBCP (DRII) – Certified Business Continuity Professional
- ITILv3 Foundations – IT Infrastructure library Foundations certificate
- RSA Archer® Certified Professional
- Internal auditor ISMS according to ISO/IEC 27001:2013 and ISO 19011:2011
- Manager of ISMS according to ISO/IEC 27001:2013
- Internal auditor for management systems according to STN/IEC 20000-1:2014
| Zaměstnanec | 85190 Kč / Měsíčně |
| Úroveň | EXPERT |