Experienced Information Security Consultant with a demonstrated history of working in the information technology and services industry. Strong information technology professional with a Specialist focused in Mathematics and Mechanics/Computer Security from Ural State University named after A.M.Gorky.
-
Ml Cloud Senior Application Security SpecialistNone Dec 2024 - PresentMoscow, Moscow City, Russia -
DeveloperWl May 2023 - Dec 2024- Design of a system for distributed network/application scanning based on containerization, postgres, clickhouse, kafka;- Development of core service with Go (gin, gorm, k8s): a scanner containers orchestration service with REST API;- Development of a Java transformer micro-service (WAF virtual patching) to convert the scanner findings to ModSecurity rules;- (in progress) Development of integration tests based on karate+OpenAPI specification
-
Head Of Design And Development Of Security Systems/Head Of Cloud Solutions SecurityVk Sep 2022 - Dec 2024Realized projects:- designing, deployment, support of centralized and managed system of access to prod/dev environment via ssh (forked Teleport)- designing, deployment, support of centralized and managed system of access to privileged web resources via mTLS (forked Pomerium)- designing, deployment, support of centralized and managed system of access to logsRoles and responsibilities:- leading of team of Cloud platform (4 engineers)- leading of team of infrastructure security team (4-7 engineers)- designing secure enterprise systems- development of secure tools -
Head Of Application SecurityDelivery Club Dec 2021 - Sep 2022Moscow, Moscow City, RussiaRealized projects:- securing external partners web services integration with IAM system (Ory stack, OpenResty custom Lua scripts) for SSO- managing the automation and implementation of business unit Secure SDLC (GitLab, DefectDojo) to reduce application risksRoles and responsibilities:- leading of team of Secure SDLC automation- designing secure integration of external clients- incident-based security planning and mitigation planning with CISO- interviewing candidates for business unit security positions- improving web security -
Senior Security EngineerDelivery Club Nov 2020 - Nov 2021Realized projects:- IT forensics analysis of data leak incident for malefactor identification- hardening authentication/authorization of software architecture in conjunction with a development team- development of a distributed system based on AWS ES2 nodes (terraform/python AWS API) with TCP-packets exit-node randomization to performing less detectable scans and brute forces: auto deployment from scratchRoles and responsibilities:- reviewing and fixing the security of systems in conjunction with a development team- incident-based security planning and mitigation planning with CISO of two business units- interviewing candidates for business unit security positions- improving infrastructure and web security -
Information Security ConsultantИнфосистемы Джет Oct 2016 - Nov 2020Russian FederationRealized projects:- over 30 penetration tests for compliance with PCI/DSS and Central Bank requirements- IT forensics analysis to mitigate malefactor intrusion effects- deploying ElastiFlow in external client's infrastructure for malicious network activity investigating- hardening anti-fraud system (Intellinx) for compliance with PCI/DSS- external clients' applications code review and SAST (android/iOS applications, web applications)Roles and responsibilities:- perform penetration tests to identify security issues and risks, and consulting mitigation plans- evaluate and recommend new and emerging security products and technologies- performing pilot projects of WAF (Imperva, PTAF) -
Leading Specialist, Information Security System ImplementationСкб Контур Jun 2012 - Oct 2016Realized projects:- two ISO 27000 compliance audits (risk assessments)- about 5 penetration tests for external clients- over 20 projects of security audit for compliance with "Federal Law on the protection of personal data" (GDPR-like) based on threat modeling; designing and implementing an appropriate security system (FW appliance, VPN appliance, PKI systems with tokens, AV); develop and interpret security policies and procedures- implementing Symantec Backup solution to backup financial information in remote VDS with local "one-touch" self-destruction system in case of alert- designing and implementing a system of digital rights protection based on MS RMS to secure intellectual property of the external client- development of threats scoring system for automated generation of documents (threat model, security controls for actual threats) based on target system actors and IT assets (PHP, MySQL, JS)Roles and responsibilities:- designing and implementation of security systems for external clients -
Head Of Department Of Infotelecommunication System ProtectionFsue Zaschitainfotrans Feb 2010 - Jun 2012Realized projects:- over 10 projects of security audits for compliance with "Federal Law on the protection of personal data" (GDPR-like) based on threat modeling; designing and implementing an appropriate security system- about 5 projects of security audits for compliance with "Federal Law on the protection of confidential data"Roles and responsibilities:- designing and implementation of security systems for external clients
-
Head Of Pharmacy Applications Support SubdivisionГуп Со Фармация Mar 2008 - Feb 2010Realized projects:- development of an automated self-update mechanism for the rich client using any type of connection (Ethernet, dial-up) to minimize the participation of pharmacies employee (Visual FoxPro, Perl)- developing embedded editor of scanned drug licenses for warehouse employees to increasing speed of processing of incoming drugs- implementing developed pharmacy soft in the whole region (over 100 drug stores) including network deploymentRoles and responsibilities:- development of pharmacy applications (Visual FoxPro/SQL, C++ WinApi, Perl)- development of analytics interfaces for managers- managing group of 3 developers to implement client-side in pharmacies
-
Information Security SpecialistЗао Сберинвестбанк Nov 2006 - Oct 2007
-
TechnicianUral State University Named After A.M.Gorky Jul 2005 - Jul 2006Roles and responsibilities:- troubleshooting network issues of users- montage of networks
Arthur Skok Skills
Arthur Skok Education Details
-
Mathematics And Mechanics/Computer Security -
Cisco Fundamentals Of Java Programming -
Ccna (Cisco Certified Network Associate)
Frequently Asked Questions about Arthur Skok
What company does Arthur Skok work for?
Arthur Skok works for None
What is Arthur Skok's role at the current company?
Arthur Skok's current role is ML Cloud Senior Application Security Specialist.
What schools did Arthur Skok attend?
Arthur Skok attended Ural State University Named After A.m.gorky, Ural State University Named After A.m.gorky, Ural State University Named After A.m.gorky.
What skills is Arthur Skok known for?
Arthur Skok has skills like Information Security, Information Security Management, Security Management, Security Audits, Software Development, Security, Threat Modeling, Penetration Testing, Cloud Computing, Enterprise Software, Javascript, Html.
Not the Arthur Skok you were looking for?
-
1mella.ai
-
1gmail.com
-
Arthur Skok
New York City Metropolitan Area
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial