Больше информации по резюме будет доступно после регистрации

Зарегистрироваться
Was online yesterday at 21:36

Candidate

Male, 41 year, born on 12 June 1983

Considers offers

Armenia, not willing to relocate, prepared for business trips

The approximate area of the job search is specified

Senior Director of Security or equivalent leadership roles (e.g., CEO, CIO, or CISO)

Specializations:
  • Chief executive officer (CEO)
  • Chief information officer (CIO)
  • Information security specialist

Employment: full time, part time, project work

Work schedule: full day, flexible schedule, remote working

Work experience 18 years 5 months

January 2023currently
2 years 3 months
Krisp Technologies Inc.

Armenia, www.krisp.ai

IT, System Integration, Internet... Show more

Senior Director Of Security
Led the creation and execution of comprehensive security policies, ensuring the safeguarding of products, data, and organizational assets. Performed regular risk assessments to proactively identify and address security vulnerabilities. Designed and directed a robust incident response framework, ensuring efficient coordination and resolution during security incidents. Maintained adherence to industry regulations, including GDPR and CCPA, ensuring organizational compliance and data protection. Successfully obtained SOC 2 Type II and PCI-DSS certifications and oversaw the organization's annual recertification process. Partnered with product development teams to embed security measures at the earliest stages of product design and development. Effectively managed third-party vendor relationships to mitigate associated security risks.
July 2020currently
4 years 9 months
Krisp Technologies Inc.

Armenia, www.krisp.ai

IT, System Integration, Internet... Show more

Director of Security
Successfully led the SOC 2 Type II certification process, ensuring continuous compliance through annual recertifications (2021–2024). Embedded security into the software development life cycle (SDLC) by leveraging Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools. Strengthened the organization's security posture by deploying Cloud Directory and Endpoint Detection and Response (EDR) solutions. Conducted regular penetration tests and engaged third-party auditors to identify and address potential security vulnerabilities.
August 2019July 2020
1 year
SCHNEIDER GROUP

Moscow, schneider-group.com/ru/

Financial Sector... Show more

Corporate Security Manager
Deployed advanced DLP solutions to safeguard sensitive information and prevent unauthorized disclosure. Oversaw the implementation and management of Identity Management (IDM) systems to enhance user authentication and enforce access control policies. Ensured compliance with international and regional data protection regulations, including GDPR and Russia's Federal Law on Personal Data (FZ-152). Conducted thorough vulnerability scans to identify, prioritize, and remediate potential security weaknesses. Designed and implemented role-based access control (RBAC) frameworks to limit data access to authorized personnel only. Developed and conducted regular security awareness programs to educate employees on data protection best practices and emerging threats. Provided expert security consulting services to customers, helping them identify risks, implement robust security measures, and achieve compliance with industry standards.
November 2017December 2018
1 year 2 months
ForexTime

Cyprus, www.forextime.com/

Financial Sector... Show more

Head of Internal Security
Directed the development and execution of a comprehensive security strategy, encompassing both IT and physical security to protect organizational assets. Led a team of cybersecurity professionals, fostering a culture of excellence, collaboration, and continuous improvement. Conducted in-depth risk assessments, identifying vulnerabilities and implementing effective mitigation strategies to reduce potential threats. Designed and deployed advanced DLP solutions to ensure the protection and confidentiality of sensitive information. Established and maintained an incident response plan, enabling swift and coordinated actions during security incidents. Ensured adherence to global and regional data protection standards, such as GDPR and CCPA, to maintain compliance and safeguard sensitive data. Implemented identity and access management (IAM) solutions to enforce secure authentication protocols and limit unauthorized access. Oversaw continuous threat monitoring and analysis, leveraging cutting-edge tools to detect and respond to potential security risks in real time. Authored and enforced comprehensive security policies and procedures to align with industry best practices and organizational goals. Managed security risks associated with third-party vendors, conducting regular assessments and ensuring compliance with security requirements.
November 2016November 2017
1 year 1 month
InecoBank

Armenia, www.inecobank.am/en

Financial Sector... Show more

Head of Administration & Supervision Department
Successfully led the ISO 27001:2005 certification project, overseeing the subsequent upgrade to the 2013 standard to enhance the organization's information security framework. Founded the Information Security Division, strategically recruiting and building a high-performing team from the ground up. Directed the comprehensive security operations for the headquarters and 14 branch offices, including the deployment and management of CCTV systems, alarm systems, and security personnel. Oversaw the security of the corporate fleet, implementing GPS tracking systems to enhance vehicle monitoring and ensure operational safety. Actively collaborated with internal software development teams as a security business partner, integrating OWASP SDLC best practices into projects to ensure secure software design and implementation.
May 2008November 2016
8 years 7 months
InecoBank

Armenia, www.inecobank.am/en

Financial Sector... Show more

Head Of Information Security Management Division
Designed and implemented comprehensive strategies to safeguard banking products and prevent fraud, ensuring the integrity and trustworthiness of financial operations. Conducted regular penetration testing and vulnerability assessments to identify and address potential security weaknesses proactively. Ensured strict adherence to key security standards and frameworks, including PCI-DSS, ISO 17799, and ISO 27001, to maintain compliance and mitigate risks. Ensured full compliance with the requirements of banking sector regulators, aligning security policies and practices with industry regulations and expectations. Implemented regular access reviews to ensure appropriate user permissions and minimize the risk of unauthorized access to sensitive systems and data. Conducted proactive threat modeling exercises to identify potential risks and design strategic security controls to mitigate emerging threats. Performed comprehensive risk assessments to evaluate potential security threats and vulnerabilities, providing a quantitative analysis of risk exposure. Developed and implemented strategic mitigation plans to address identified risks, ensuring timely and effective risk reduction strategies.
April 2006May 2008
2 years 2 months
HSBC Bank Armenia

Armenia, www.hsbc.am/en-am/

Financial Sector... Show more

IT Security Supervisor
Designed and implemented comprehensive security policies to safeguard IT infrastructure and systems, aligning with industry standards and organizational objectives. Led the management of security incidents, ensuring prompt investigation, effective response, and timely resolution to minimize impact. Administered and maintained network equipment and antivirus solutions to ensure the integrity, reliability, and security of the IT environment. Managed and maintained critical banking systems, including AS/400 and Lotus Domino servers, ensuring their optimal performance, security, and availability. Provided strategic security support to executive management, offering guidance on risk mitigation, incident response, and security policy alignment to ensure informed decision-making.

Skills

Skill proficiency levels
IPS
IDS
DLP
ISO 27001
GDPR
PCI-DSS
BurpSuite Pro
JumpCloud
OKTA
SOC 2 Type II
Rapid7
Logz.io
Coverity
SDLC
SAST
DAST
HIPAA
Security Risk Management
Vulnerability Management
Physical Security
SSDLC
Аудит безопасности
Внутренний контроль
Руководство коллективом
Управление командой
Технические средства информационной защиты
Анализ рисков
SIEM

Driving experience

Own car

Driver's license category B, C

About me

With over 18 years of expertise in cybersecurity and leadership, I excel in developing and executing strategic security frameworks that align with organizational goals. My comprehensive experience spans SOC 2 Type II certifications, PCI-DSS compliance, DevSecOps, regulatory adherence, and advanced incident response mechanisms. I am passionate about leveraging technical proficiency and managerial skills to foster innovation, secure critical assets, and promote a culture of resilience. My goal is to contribute as a strategic leader ensuring robust security and operational success.

Higher education

2008
National Polytechnic University of Armenia
Computer Systems, Complexes and Networks, Engineer

Languages

ArmenianNative


EnglishC2 — Proficiency


RussianC2 — Proficiency


Citizenship, travel time to work

Citizenship: Armenia

Permission to work: Armenia, Russia

Desired travel time to work: Doesn't matter