Bucharest, Romania
Competent and enthusiastic Information Security Professional with extensive experience in Information Security and IT industries. Developed from skilled and focused IT professional into proficient information security consultant, trainer and manager, while remaining always eager and passionate about improving and growing. Dedicated practitioner and leader in the process of identifying and mitigating information security risks and guiding companies throughout their information security journey to process maturity, having strong documentation and presentation skills. Strong believer in personal development and streamlining processes. Knowledgeable in the areas of: Information security controls regulatory requirements and their definition, implementation and evaluation for compliance. Information security management, policies and procedures, Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP), Incident Management, Security Awareness, Security operations and monitoring, Network & systems security, Threat & Vulnerability Management, Identity & Access Management, Mobile Device Management (MDM)
Advising customers in improving their security posture and compliance with relevant regulatory and industry standards. Creating the strategy for delivering NIS assessment engagements and mapping the services delivered by Safetech to NIS compliance requirements. Acting as keynote speaker at different conferences and webinars to create awareness regarding cybersecurity, especially regarding compliance with European NIS Directive. Acting as SME and trainer for Risk Assessment, Audit and Compliance activities. Thought leadership regarding GRC activities. Managing presales activities for GRC services and security solutions. Assessing new potential technology partnerships from a technical point of view.
Allocating project work, reviewing to ensure quality and following through to delivery. Coordinating with Security Testing and Security Monitoring departments, PMO, Sales and customer teams during project work to ensure deadlines and expectations are met. Consulting on identifying and mitigating potential information security risks and reporting to management. Evaluating customers' information resources and IT support infrastructure implementation according to industry best practices and their compliance with: Industry security standards such as ISO 27001, European Regulations such as GDPR European Directives such as NIS Performing risk assessments, vulnerability assessments and information security audits of new technologies, workflows, business processes and applications before Go-Live. Advising customers in improving their technical landscape and compliance with relevant regulatory and industry standards. Participating in security conferences, meetings and presentations in area of activity Researching workflows, technologies and solutions to streamline operations within the department and further on. Supervising continuous improvement of personnel in the department. Developing and revising security policies, standards, guidelines and procedures Creating and delivering information security training sessions.
Administration, configuration and maintenance of company and customers' IT and Security infrastructures based on Microsoft and IBM software and hardware technologies. Proof of Concept (PoC) sessions delivery , implementation, configuration and support for the security solutions marketed by the company from vendors such as Fortinet, Barracuda, Vision Solutions (Double-Take), Veeam Software. Microsoft technologies: Windows 2003 & 2008 Servers, Active Directory, Exchange 2007 & 2010, SQL 2005 & 2008 Servers, Dynamics NAV & CRM. IBM technologies: Lotus Domino 8.5, IBM Blade Center, IBM xSeries servers, IBM System Storage VMWare vSphere HA Clusters, vCenter Server, Cisco switches and access points Backup plans for servers and databases Security awareness and instructing users on best practices regarding the information they create and manage, and how to protect their user accounts.
Installed, configured and secured the server and network infrastructure of the company consisting of Microsoft Windows Server 2003 and 2008 and SMB-level networking equipment. Configured secure internet access for the company by implementing Microsoft ISA Server. Implemented network segregation for different group of users. Implemented WSUS for managing updates and applying security patches for servers and workstations Created a backup plan for the Windows and Linux Servers and tested backup integrity. Raised security awareness and instructed users on best practices regarding the information they create and manage, and how to protect their user accounts.
Offering support to the sales force, production, financial and controlling department for the ERP software (Progress Software) and general IT requests. Coordinating with IT Infra Ops and Business Systems Support in the Netherlands