Дополнительные сведения:
Information security strategy development and implementation. Integration information security principles into business and support processes. Process structuring and sustainability by the internal controls implementation. Project program management for technical and organizational solutions and controls.
Tactical and operational planning, budgeting, resource engagement, motivation, key performance indicators and tracking procedures. Information security management processes on the Group of companies level. The Board and stakeholders reporting. M&A (Merger and Acquisition) experience from the both sides.
Establishing the processes of information security and business continuity management: creating the processes from zero level or re-engineering of existing processes. Defining, initiation, implementation, management and control of process performance. Growing the process maturity to the levels GMM:defined or GMM:managed
Vulnerability management, cryptography, logical access rights management, privacy, monitoring and incident management, compliance requirements, security tools administration, business continuity management and disaster recovery, vendor relation management. ISO 2700x, PCI DSS, ISO 2230x, Russian FZ-152, FZ-161, STO BR+.
Creating the base for information security management and business continuity. Development and adaptation of frameworks, policies and procedures. Implementation, training, awareness. Defining the gaps, remediation plan development, key indicators and metrics defining. Performing, tracking and control.
Cooperation with Business, Operations, IT, Legal, HR and other key players. Priorities definition, team engagement and project management, conflicts resolving.