IT Security Consultant
Überblick
Kurzer Überblick
Der Bewerber ist ein erfahrener IT-Sicherheitsmanager, der seit 1994 im Bereich der IT-Sicherheit tätig ist. Die Stellenbeschreibung reizte ihn vor allem wegen der Prozesse, die, wie er sagt, dauerhafter und anspruchsvoller sind als die technischen Aspekte. In seiner letzten Position arbeitete er am Aufbau eines Sicherheitsarbeitsplatzes, der alle Niederlassungen des Unternehmens weltweit bedienen wird. Außerdem arbeitete er am Aufbau eines Autobahnmautsystems, wo er für die Sicherheit bei der Verwendung von Zahlungs- und Flottenkarten sorgte. Die interessantesten Projekte sind für ihn die, an denen er noch nicht gearbeitet hat, da sie für ihn die beste Quelle für Erfahrung und Wissen sind. Er interessiert sich besonders für Sicherheitsprozesse und Audits. Er ist einer der wichtigsten Vertreter der Slowakischen Republik auf dem Gebiet der Entwicklung von ISO-Normen.
Berufliche Erfahrung
2006 to present: CEO, Security Consultant, Security Manager. Obtained CISA certification in December 2006, PRINCE2 Foundation certification in January 2010, and CRISC certification in May 2011. Currently preparing for the CEH exam in 2021.
2019 - 2021: Worked for 18 months as a full-time employee. Implemented an incident management process and security operation center for handling security incidents 24x7 for all subsidiaries and production plants worldwide. Updated existing process documentation and aligned it with ISO standards.
2016 - 2019: Worked on a project for 30 months as a full-time employee. Analyzed, described, and documented security processes to comply with ISO standards. Established IT risk management and internal audit processes for information security management system (ISMS).
2015: Worked on a project for 3 months as a part-time employee. Conducted risk analysis and provided recommendations for policy, procedures, and information security processes.
Worked on a security project for 6 months as a part-time employee. Updated existing security project, implemented new security policies and procedures, and integrated them with IT services based on ISO/IEC standards.
2012-2014: Worked on the Testa-NG project for 6 months as a full-time employee. Developed an encrypted network for the European Parliament. Responsible for defining, describing, and documenting the encryption process and security dependencies.
Implemented PKI for railroad tickets distribution for 3 months as a part-time employee. Developed policies, procedures, and work instructions based on ISO/IEC standards for the Railroad Company.
Conducted internal audits for information security management by ISO/IEC standards for 2 months as a part-time employee. Defined the scope of work and created a roadmap for certification process for ISO 27001.
Worked on capacity and availability management for 2 years as a full-time employee. Defined processes and operated them in the factory production environment.
Conducted internal audits for IT service management by ISO/IEC standards for 3 months as a part-time employee. Supported the certification process for ISO 20000 and built an integrated management system for ISO 9001, ISO 20000, and ISO 27001.
Provided consultation for process definition, implementation, and documentation for ISO 20000 certification process for an IT service provider. Developed a methodology for risk management and procedures for risk assessment.
Non-profit activities: Worked for SUTN (ISO national body) since 2008 as a part-time employee. Served as an ISO voting representative, managed sub-commissions, workgroups, and translated ISO standards into Slovak language.
| Angestellter | 3300 € / Pro Monat |
| Eben | EXPERT |