IT Security Consultant
Overview
Short Summary
The candidate is an experienced IT security manager who has been working in IT security since 1994. The job description attracted him mainly because of the processes, which as he says are more durable and demanding than the technical stuff. In his last position, he worked on building a security workplace that will serve all the company's branches globally. He also worked on building a highway toll system where he provided security for the use of payment and fleet cards. The most interesting projects for him are the ones he has not worked on before, as they are the best source of experience and knowledge for him. He is particularly interested in security processes and auditing. He is one of the main representatives of the Slovak Republic in the field of ISO standards development.
Work Experience
2006 to present: CEO, Security Consultant, Security Manager. Obtained CISA certification in December 2006, PRINCE2 Foundation certification in January 2010, and CRISC certification in May 2011. Currently preparing for the CEH exam in 2021.
2019 - 2021: Worked for 18 months as a full-time employee. Implemented an incident management process and security operation center for handling security incidents 24x7 for all subsidiaries and production plants worldwide. Updated existing process documentation and aligned it with ISO standards.
2016 - 2019: Worked on a project for 30 months as a full-time employee. Analyzed, described, and documented security processes to comply with ISO standards. Established IT risk management and internal audit processes for information security management system (ISMS).
2015: Worked on a project for 3 months as a part-time employee. Conducted risk analysis and provided recommendations for policy, procedures, and information security processes.
Worked on a security project for 6 months as a part-time employee. Updated existing security project, implemented new security policies and procedures, and integrated them with IT services based on ISO/IEC standards.
2012-2014: Worked on the Testa-NG project for 6 months as a full-time employee. Developed an encrypted network for the European Parliament. Responsible for defining, describing, and documenting the encryption process and security dependencies.
Implemented PKI for railroad tickets distribution for 3 months as a part-time employee. Developed policies, procedures, and work instructions based on ISO/IEC standards for the Railroad Company.
Conducted internal audits for information security management by ISO/IEC standards for 2 months as a part-time employee. Defined the scope of work and created a roadmap for certification process for ISO 27001.
Worked on capacity and availability management for 2 years as a full-time employee. Defined processes and operated them in the factory production environment.
Conducted internal audits for IT service management by ISO/IEC standards for 3 months as a part-time employee. Supported the certification process for ISO 20000 and built an integrated management system for ISO 9001, ISO 20000, and ISO 27001.
Provided consultation for process definition, implementation, and documentation for ISO 20000 certification process for an IT service provider. Developed a methodology for risk management and procedures for risk assessment.
Non-profit activities: Worked for SUTN (ISO national body) since 2008 as a part-time employee. Served as an ISO voting representative, managed sub-commissions, workgroups, and translated ISO standards into Slovak language.
| Employee | 3300 € / Per month |
| Level | EXPERT |