IT Security Consultant
Overview
Short Summary
The candidate is a Senior IT Security Consultant. He has worked on the development, implementation and documentation of processes or audits according to ISO/IEC 27001 and ISO/IEC 9001. In addition to GDPR, he has been responsible for government systems or the Health Care Act, for example. He has also worked as Head of IT where he managed over 10 employees. He is fluent in English.
Work Experience
10/2021 - Present
Information Security Consultant
Technology sector
- Information security implementation in development projects,
- Implementation v controls according to cyber law
- Development of business continuity and disaster recovery plans,
- Performing risk analysis and risk management activities,
- Other IT security related consulting services.
05/2015 - 09/2021
Senior Security Consultant & Technical Lead
Security sector
- Implementation of cyber security requirements according to Cybersecurity Law 69/2018 for three companies,
- Identification of legal and contractual compliance requirements and leading their implementation in company (GDPR, Cyber security Law, Government information systems Law, Health Care Law, etc),
- Recommendation of technical and procedural controls to increase resilience against cybersecurity threats,
- Setting up processes of cybersecurity incident handling in compliance with Slovak cybersecurity law,
- Risk analysis and risk management activities – design of risk management processes with all involved parties, realization of risk analysis, communication of results to management, including recommendation of controls to address risks identified,
- Business continuity activities – BIA, strategy, business continuity and disaster recovery planning for several clients (manufacturing company, government companies, power distributor company, commercial companies),
- Configuration of RSA Archer tool (BIA, DRP, vulnerability management, risk management, etc),
- Development and implementation of documentation, processes and audits according to ISO/IEC 27001 standard requirements
- Preparation of companies for ISO/IEC 27001 and ISO 9001 certification.
- Internal audits at the company and clients according to ISO27001.
- Other IT security related consulting services.
02/2019 - 02/2020
Senior Security Consultant
Consultancy sector
- Risk analysis and risk management activities,
- Business continuity activities – BIA, strategy, business continuity and disaster recovery planning and testing,
- Development and implementation of documentation according to ISO/IEC 27001 standard requirements
- Preparation of companies for ISO/IEC 27001 and ISO/IEC 9001 certification.
- Other IT security related consulting services.
07/2012 - 06/2014
Senior Information Security Consultant
Technology sector
- Risk analysis and risk management activities,
- Proposition of controls to mitigate risks,
- Proposition of policies and procedures related to information security,
- Information security audits,
- Other IT security related consulting services.
02/2010 - 02/2012
Senior Information Security Consultant
Technology sector
- Information security specialist for development projects (over 16,5 mil. €),
- Business continuity and disaster recovery plans,
- Performing risk analysis and risk management activities,
- User access policies for information systems (definition of user processes and user rights according to business needs),
- Preparing company to achieve ISO/IEC 27001 certification of information security management,
- Other IT security related consulting services.
02/2007 - 07/2009
Senior Information Security Consultant
Technology sector
- Design of information security management system in complex environments (clients with 4000+ employees and 600+ applications),
- Design and realization of security risk analysis in complex environment,
- Implementation of information asset classification program,
- Development and implementation of isms in compliance with ISO/IEC 27001 standard,
- Other IT security related consulting services.
10/2005 - 09/2006
Head of IT Security Department
Banking sector
- Management of 15 employees,
- Implementation of identity and access management project – role-based access,
- Security operations of certification authority for internet banking and home banking clients,
- Development and implementation of security policies and procedures,
- Definition of security requirements for new projects,
- Internal/external security incident management and investigation,
- Other security related activities.
10/2004 - 09/2005
Manager for Security Related Products
Technology sector
- Network security projects – DMZ, firewalls, IPS, IDS, authorization servers, VPN, …
- Security projects for protection of classified information,
- Development and implementation of policies,
- Projects for protection of personal information,
- Hardening of applications and operation systems,
- Information security risk analysis,
- Other security related activities.
08/1997 - 8/2004
Head of IT Security Department
Banking sector
- Development of IT security policy,
- Development of IT security framework,
- Business continuity plans,
- Security inspections at branches,
- Development of user procedures,
- Risk analysis – CRAMM,
- Other security related activities.
- Head of the Year 2000 project,
- Member of teams implementing new products - responsibility for information security.
EDUCATION
1992 – 1997
Comenius University Bratislava
Specialization Theoretical informatics
Thesis on information security (Cryptanalyses of shift registers with nonlinear feedback function)
CERTIFICATIONS
- CISA - Certified Information Systems Auditor
- CISM - Certified Information Security Manager
- CISSP - Certified Information Systems Security Professional
- ISSMP - Information Security Management Professional
- CBCP (DRII) – Certified Business Continuity Professional
- ITILv3 Foundations – IT Infrastructure library Foundations certificate
- RSA Archer® Certified Professional
- Internal auditor ISMS according to ISO/IEC 27001:2013 and ISO 19011:2011
- Manager of ISMS according to ISO/IEC 27001:2013
- Internal auditor for management systems according to STN/IEC 20000-1:2014
| Employee | 3500 € / Per month |
| Level | EXPERT |