- QualitestIT Cyber Security LeadDIGITAL & ITNovember 2021 - Today (3 years and 5 months)London, UK• Risk assessment and prioritisation• Threat modelling processes & frameworks• Attack surface management• Penetration testing management• Application security testing & automation• SCA (Software Composition Analysis), SAST (Static Application Security Testing), and DAST (Dynamic Application Security Testing) solutions as part of DevSecOps• Community of Practice (Cyber CoP) Lead
- Cyber LegionFounderDIGITAL & ITMarch 2021 - Today (4 years and 1 month)London, UKAs the founder of Cyber Legion, my role is to strategically lead the company in supporting businesses, individuals, and families to enhance their security posture and maturity across various aspects. Our focus lies in providing professional services and automation for identifying, fixing, and mitigating risks, ensuring security by design, and facilitating seamless, bug-free product operations.In addition to our core services, we offer next-level security consultancy for our clients.• Cyber Legion is dedicated to helping businesses, individuals, and families recognize and address cybersecurity threats and vulnerabilities. We aim to improve resilience against cyber attacks and safeguard the reputation and well-being of all parties involved.• Our mission is to create a business model that seamlessly integrates security, development, DevOps, and IT teams, enabling comprehensive asset risk management and valuation through a single platform – the Secure Client Portal.• Leveraging our expertise, we have devised an optimized process for identifying, assessing, analyzing, prioritizing, and reporting threats and vulnerabilities that impact organizations, individuals, and families globally.• At Cyber Legion, we provide an advanced cyber workflow management platform that bolsters security programs, making them more efficient, effective, and proactive in addressing cybersecurity needs.
- GfKSr. IT Security Analyst - Web Application SecurityDIGITAL & ITApril 2020 - November 2021 (1 year and 7 months)London, UK• Configure/maintain/support security testing tools• Managed the dynamic web application security testing (DAST) on more than 2K public websites/microservices with various web technologies, in authenticated/unauthenticated mode using tools such as Veracode/ NetSparker/Burp/• Hands on security testing and validation of findings to eliminate false positives.• Manage attacking surface management (ASM) and Risk assessment program RiskIQ/Cycognito• Responsible for ticketing based on application vulnerabilities identified during scans, and update tickets as technical remediation plans progress to completion Jira/ServiceNow• Manage & coordinate & perform third-party/internal penetration tests and security assessments on web app, API & network• Reporting KPI to the executive & management staff• Work with engineering squads (Developers, SREs & QAs) to ensure that projects are secure on delivery• Provide engineering teams with guidance in security web applications, APIs & Cloud Native Services• Explain risk and criticality of identified vulnerabilities to business owners/ technical teams and advise on remediation activities• Support engineering teams with security remediations, helping them meet agreed KPIs & SLAs• Integrate security tools & capabilities into product teams' CI / CD pipelines as part of SDLC• Contribute to defining & maintaining application security framework & associated standards• Use of dynamic & static security testing tools to assess product artefacts, such as source code, third-party libraries & containerised environments• Support SOC during security incidents involving Cloud environments and/or web services• Provide application security coaching & training of junior security peers and engineering colleagues
Ion Ion and 0 other people have recommended Ioan
- Baccalaureate Diploma, SCIENCESGCSE A-Level "BOGDAN VODA" Viseu de Sus, Romania2001Baccalaureate Diploma, SCIENCES
- Certified Ethical HackerEc Council2018
- Microsoft Network & SecurityMicrosoft2018
- Splunk SecuritySplunk Security2019
- Penetration Testing With Kali LinuxOffensive Security2020
- Application Security and Secure CodingCheckmarx2020
- Penetration Testing & Vulnerability ManagementQualys, Cybrary & Rapid 72019