I've joined Celtra in June 2020 as Senior Information Security Manager. Working fully remote and reporting directly to CTO who was based in New York, the begining was very challenging and the onboarding super fast. Especially due to this being my first role focused entirely on Information Security. I've quickly grown into the role and (despite the different title) become some sort of unofficial CISO at Celtra.
Celtra gig was a true rollercoaster, where I a had a privilege to work with some of most talented and amazing people I've met in my carrer.
June 2020 - December 2024
Senior Information Security Manager
Core responsibilities:
Keep Celtra and Celtra clients’ data secure.
Be able to demonstrate the above to Celtra existing and prospective clients.
Empowering employees and the team to effectively navigate and respond to contemporary cybersecurity risks and threats.
Duties and achievements:
Spearheading Celtra's information security efforts:
· Managing department’s roadmap and its timely execution.
· Leading InfoSec and IT work team, setting goals and performance expectations.
· Ensuring the organisation's ongoing compliance with SOC2 controls.
· Ensuring alignment of the production environment with the CIA triad model.
· Reporting identified risks and needed improvements to management.
· Ensuring prompt responding to client Information Security assessments
Process optimisation and bottleneck elimination:
· i.e. SSO where possible, Risk assessment added to SDLC, clearer data governance, automated on/off-boarding tasks, decluttering Jira, etc.).
· Rolling-out and managing Vulnerability Disclosure Program, resulting in significant noise reduction, faster report validation and triage.
Empowering employees and the team:
· Decreasing unauthorized sharing, transfer, or use of sensitive data with Auto document classification using DLP rules,
· Implemented password management solution, reducing weak and reused passwords usage by 80%.
· Establising security baselines for endpoints, monitoring for compliance.
· Phishing Awareness Automation, resulting in less than 6% phish-prone.
· Conducting knowledge shares, employee trainings (OWASP).
Managing primary IdP and Company SaaS stack