About Paul
German
Native or bilingual
English
Fluent
Russian
Conversational
Experience
- Hessische Zentrale für DatenverarbeitungSecurity Incident Manager (CSIRT)PUBLIC SECTORAugust 2023 - Today (2 years and 10 months)Wiesbaden, Germany• Research, analysis, and evaluation of IT vulnerabilities and IT threat landscapes• Target group-specific information preparation and provision of recommendations for action regarding IT vulnerabilities and IT threat landscapes• Initiation, consultation on mitigation, and follow-up of security incidents• Vulnerability scans and management (Nessus, Greenbone, Nuclei)• Processing and follow-up of security incidents (Remedy)• Optimization of existing CSIRT processes• Organizational support for IT crisis situations
- DekaBank Deutsche GirozentraleIT Security SpecialistBANKING AND INSURANCEDecember 2020 - June 2023 (2 years and 7 months)Frankfurt, GermanyPenetration Test Manager | DekaBankFrankfurt am Main | December 2020 – June 2023Project Work
- Identification of potential for internal process improvements
- Project initiation and development of a blueprint for process automation
- Analysis of internal and external process-supporting tools
- Project plan management (Jira)
- Management of Red Team activities in an agile style
- Determination of test scope, milestones, and target systems within the framework of a simulated cyber attack
- Coordination and moderation of daily meetings
- Quality assurance of test results, as well as assignment of derived measures to existing projects & lines
Day-to-day business- Responsibility for the field of penetration testing with an annual budget > EUR 1 million
- Coordination of over 150 penetration tests annually
- Moderation of kick-off and daily meetings
- Onboarding and offboarding of external penetration testers including authorization management (Omada IAM)
- Quality control of penetration test results
- Vulnerability and incident management (BMC Remedy ITSM, RADAR Cyber Security)
- Provider management
- Commissioning and management of external service providers
- Recording of KPIs & requirements for service providers
- Effort / budget controlling (MS Office, SAP)
- Collaboration with information security management
- Participation in phishing campaigns
- Close coordination on risk acceptances from penetration tests
- Consultation on the creation of security concepts
- Collaboration with the Security Operation Center
- Creation and expansion of SIEM use cases from penetration tests
- Purple team coordination to improve detection mechanisms
- DekaBank Deutsche GirozentraleBusiness Service & Regulatory ControlBANKING AND INSURANCENovember 2018 - November 2020 (2 years)Business Service & Regulatory Control | DekaBankFrankfurt am Main | November 2018 – November 2020Project WorkSub-project management for identifying digitalization potential of existing processesCoordination and moderation of status meetingsRecording and tracking of project results and milestones (MS Excel, PowerPoint)Day-to-day businessCoordination of money transactions between the securities system and the central order platform (SAP)
Recommendations
Be the first to recommend Paul
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Bachelor of ArtsTechnische Hochschule Mittelhessen2017Bachelor of Arts (B.A.), Business Administration - Financial Services
Certifications
- Certified Ethical Hacker (CEH)EC-Council2023
- Certified ScrumMaster®Scrum Alliance2021