Zpět na profesionály

IT Security Consultant

Přehled


Krátké shrnutí

Kandidát je senior konzultantem v oblasti bezpečnosti IT. Pracoval na vývoji, implementaci a dokumentaci procesů nebo auditů podle norem ISO/IEC 27001 a ISO/IEC 9001. Kromě GDPR měl na starosti například systémy státní správy nebo zákon o zdravotní péči. Pracoval také jako vedoucí oddělení IT, kde řídil více než 10 zaměstnanců. Hovoří plynně anglicky.

Pracovní zkušenosti

10/2021 - Present

Information Security Consultant

Technology sector

  • Information security implementation in development projects,
  • Implementation v controls according to cyber law
  • Development of business continuity and disaster recovery plans,
  • Performing risk analysis and risk management activities,
  • Other IT security related consulting services.

05/2015 - 09/2021

Senior Security Consultant & Technical Lead

Security sector

  • Implementation of cyber security requirements according to Cybersecurity Law 69/2018 for three companies,
  • Identification of legal and contractual compliance requirements and leading their implementation in company (GDPR, Cyber security Law, Government information systems Law, Health Care Law, etc),
  • Recommendation of technical and procedural controls to increase resilience against cybersecurity threats,
  • Setting up processes of cybersecurity incident handling in compliance with Slovak cybersecurity law,
  • Risk analysis and risk management activities – design of risk management processes with all involved parties, realization of risk analysis, communication of results to management, including recommendation of controls to address risks identified,
  • Business continuity activities – BIA, strategy, business continuity and disaster recovery planning for several clients (manufacturing company, government companies, power distributor company, commercial companies),
  • Configuration of RSA Archer tool (BIA, DRP, vulnerability management, risk management, etc),
  • Development and implementation of documentation, processes and audits according to ISO/IEC 27001 standard requirements
  • Preparation of companies for ISO/IEC 27001 and ISO 9001 certification.
  • Internal audits at the company and clients according to ISO27001.
  • Other IT security related consulting services.

02/2019 - 02/2020

Senior Security Consultant

Consultancy sector

  • Risk analysis and risk management activities,
  • Business continuity activities – BIA, strategy, business continuity and disaster recovery planning and testing,
  • Development and implementation of documentation according to ISO/IEC 27001 standard requirements
  • Preparation of companies for ISO/IEC 27001 and ISO/IEC 9001 certification.
  • Other IT security related consulting services.

07/2012 - 06/2014

Senior Information Security Consultant

Technology sector

  • Risk analysis and risk management activities,
  • Proposition of controls to mitigate risks,
  • Proposition of policies and procedures related to information security,
  • Information security audits,
  • Other IT security related consulting services.

02/2010 - 02/2012

Senior Information Security Consultant

Technology sector

  • Information security specialist for development projects (over 16,5 mil. €),
  • Business continuity and disaster recovery plans,
  • Performing risk analysis and risk management activities,
  • User access policies for information systems (definition of user processes and user rights according to business needs),
  • Preparing company to achieve ISO/IEC 27001 certification of information security management,
  • Other IT security related consulting services.

02/2007 - 07/2009

Senior Information Security Consultant

Technology sector

  • Design of information security management system in complex environments (clients with 4000+ employees and 600+ applications),
  • Design and realization of security risk analysis in complex environment,
  • Implementation of information asset classification program,
  • Development and implementation of isms in compliance with ISO/IEC 27001 standard,
  • Other IT security related consulting services.

10/2005 - 09/2006

Head of IT Security Department

Banking sector

  • Management of 15 employees,
  • Implementation of identity and access management project – role-based access,
  • Security operations of certification authority for internet banking and home banking clients,
  • Development and implementation of security policies and procedures,
  • Definition of security requirements for new projects,
  • Internal/external security incident management and investigation,
  • Other security related activities.

10/2004 - 09/2005

Manager for Security Related Products

Technology sector

  • Network security projects – DMZ, firewalls, IPS, IDS, authorization servers, VPN, …
  • Security projects for protection of classified information,
  • Development and implementation of policies,
  • Projects for protection of personal information,
  • Hardening of applications and operation systems,
  • Information security risk analysis,
  • Other security related activities.

08/1997 - 8/2004

Head of IT Security Department

Banking sector

  • Development of IT security policy,
  • Development of IT security framework,
  • Business continuity plans,
  • Security inspections at branches,
  • Development of user procedures,
  • Risk analysis – CRAMM,
  • Other security related activities.
  • Head of the Year 2000 project,
  • Member of teams implementing new products - responsibility for information security.

EDUCATION

1992 – 1997

Comenius University Bratislava

Specialization Theoretical informatics

Thesis on information security (Cryptanalyses of shift registers with nonlinear feedback function)

CERTIFICATIONS

  • CISA - Certified Information Systems Auditor
  • CISM - Certified Information Security Manager
  • CISSP - Certified Information Systems Security Professional
  • ISSMP - Information Security Management Professional
  • CBCP (DRII) – Certified Business Continuity Professional
  • ITILv3 Foundations – IT Infrastructure library Foundations certificate
  • RSA Archer® Certified Professional
  • Internal auditor ISMS according to ISO/IEC 27001:2013 and ISO 19011:2011
  • Manager of ISMS according to ISO/IEC 27001:2013
  • Internal auditor for management systems according to STN/IEC 20000-1:2014
Author
IT Security Consultant
60c23cdde342f3000bacc6a7
Zaměstnanec85190  / Měsíčně
ÚroveňEXPERT
Role
IT Security Consultant
Jazyky
English
Dovednosti
Application ServerCertificationsIT Security ConsultantMicrosoft serversOperation SystemsProject Manager
Lokality
PezinokBratislavaRemote