Sergey Belov

Sergey Belov Email and Phone Number

Head of Banking Systems Security Research Group @ Positive Technologies
Russia
Sergey Belov's Location
Moscow, Moscow City, Russia, Russian Federation
Sergey Belov's Contact Details

Sergey Belov work email

Sergey Belov personal email

n/a
About Sergey Belov

As a cybersecurity team lead with over a decade of experience outsmarting hackers, I've turned protecting financial and tech giants into my daily "capture the flag" game. My leadership style is hands-on because in cybersecurity, if you're hands-off, you're already breached. Building elite teams is my forte - we’re like the Ocean’s Eleven of cyber (with more keyboards and less George Clooney), pulling off penetration tests and vulnerability hunts with style and a wink. And when it comes to research? We don’t just stay ahead of the curve; we bend it, break it, and rewrite the book on it.

Sergey Belov's Current Company Details
Positive Technologies

Positive Technologies

View
Head of Banking Systems Security Research Group
Russia
Sergey Belov Work Experience Details
  • Positive Technologies
    Head Of Banking Systems Security Research Group
    Positive Technologies
    Russia
  • Positive Technologies
    Head Of Banking Systems Security Research Group
    Positive Technologies May 2023 - Present
    Moscow, Russia
  • Coinloan
    Security Expert
    Coinloan May 2022 - May 2023
    - Led drafting and implementation of various security features to enhance overall security posture of the company.- Maintained endpoint security management systems (Kolide and Jamf), resulting in improved endpoint security.- Implemented various custom checks for Kolide, which improved the accuracy and efficiency of security monitoring.- Maintained and managed the company's Web Application Firewall (WAF) using Cloudflare WAF.- Implemented a secure software development life cycle (SSDLC) in Gitlab (using various tools Bandit, Semgrep, Trivy, Kubesec, Gemnasium) and JFrog Artifactory, resulting in a marked improvement of the company products security.- Conducted regular security code review for company products (Python and Javascript), resulting in the identification and remediation of various critical security vulnerabilities.- Led penetration testing of company product by an external contractor.- Implemented Zero Trust architecture using Cloudflare ZTNA and Teleport.- Implemented security events aggregation to Slack using Cloudflare Workers, which improved the efficiency and effectiveness of security incident management.- Led various in-house security trainings, including code review from security perspective, common payment processing issues, and phishing awareness.
  • Huawei
    Vulnerability Assessment And Research Team Lead
    Huawei Aug 2020 - May 2022
    Москва, Россия
    - Led security assessments, penetration testing, tooling scans, and source code audits for an AI development platform, public deep learning framework infrastructure, hardware AI computing platform and various other products with a 10-person team.- Led security testing tools development.- Supervised security research projects.- Served as the SME for all application security, threat modeling, and vulnerability solutions.- Completed 20+ internal security testing projects for web applications, hardware platforms, end-user products, and IDE.- Discovered a 0-day vulnerability in the open-source product with a security risk of accessing user credentials.- Served as a mentor for junior engineers and gave an in-house lecture for staff on application security.- Received an Individual Award of the President of the Moscow Research Center.
  • Kpmg
    Cybersecurity Manager
    Kpmg Jul 2019 - Jul 2020
    Москва, Россия
    - Led a team of 5 security professionals to deliver 15 internal & external security projects and penetration testing initiatives.- Provided penetration testing for enterprise banking infrastructure, technical brand protection for a mobile operator, antifraud measures for an oil and gas company, and a security roadmap for a medical holding company.- Improved project report templates and client questionnaires to streamline project cost assessments and negotiations.- Participated in modernization of the access control system, improved the security of employee workstations, increased the frequency of hardware firmware update cycles, and updated the system for monitoring data leaks of company employees.- Built an internal information security knowledge base used by the Head of Cybersecurity and all staff, to streamline commercial offer quality, formation speed, reporting, and document preparation time in the field of information security.- Won 1st place in the internal information security competition out of 1,000+ KPMG participants across the globe.
  • Defence Group
    Senior Penetration Tester
    Defence Group 2017 - 2019
    Москва, Россия
    - Led 30+ Penetration testing projects for payment processing systems and ICO projects with a team of 3 testers.- Developed 5 vulnerability detection modules for Nessus Professional and discovered six 0-day vulnerabilities.
  • Defence Group
    Penetration Tester
    Defence Group 2016 - 2017
    - Conducted external and internal penetration testing of 25 web applications, including source code audits with PHP/Node.js, for 20 gambling, trading platforms, banking, and credit companies.- Reduced costs by 10% by developing data collection and node deployment/configuration tools to streamline penetration testing process.
  • Freelance
    Penetration Tester Contractor
    Freelance 2017 - 2019
    - www.group-ib.ru, Group-IB: Completed 7 penetration testing projects for financial sector clients. Conducted application security assessments using manual and automated penetration techniques with Burp Suite, Nessus, Acunetix, and OpenVAS. - deteact.com, DeteAct: Conducted application security assessments and penetration tests for 4 web & mobile applications. Manually tested and analyzed results and developed scripts & tools & automated application vulnerability scanning/testing. - 1gsecurity.com, 1Guard: Conducted penetration testing of external/internal network infrastructure and prepared reports.
  • Elvis-Plus
    Software Engineer
    Elvis-Plus 2011 - 2016
    - Built an OpenSSL-based cryptographic module for GOST algorithms (28147-89, 34.11-94, 34.10-2001) and a certificates management plugin according to Public-Key Cryptography Standard.- Implemented a Kernel-mode cryptographic module for GOST algorithms, a custom map module based on Qt Marble, firewall procedures for a network filtering kernel module, and a minor kernel module for maintenance.- Increased performance 10x by implementing a packet reordering mechanism with a lock-free queue and distribution of interrupt processing among processor cores.- Developed a cross-platform Win, Linux, and Solaris software licensing mechanism for license generation and validation and kernel-mode integrity checking module, eliminating a reliance on third-party software and decreasing operational costs.- Implemented necessary improvements to pass certification for compliance with FSTEC requirements.- Increased network data transmission speed by porting a Deflate compression algorithm for kernel-mode IPComp module.

Sergey Belov Skills

Perl C Masm Disassembly Reverse Engineering Ollydbg Winapi Windows Linux Php Penetration Testing Security

Sergey Belov Education Details

Frequently Asked Questions about Sergey Belov

What company does Sergey Belov work for?

Sergey Belov works for Positive Technologies

What is Sergey Belov's role at the current company?

Sergey Belov's current role is Head of Banking Systems Security Research Group.

What is Sergey Belov's email address?

Sergey Belov's email address is sb****@****kpmg.ru

What schools did Sergey Belov attend?

Sergey Belov attended National Research University Of Electronic Technology (Miet).

What skills is Sergey Belov known for?

Sergey Belov has skills like Perl, C, Masm, Disassembly, Reverse Engineering, Ollydbg, Winapi, Windows, Linux, Php, Penetration Testing, Security.

Not the Sergey Belov you were looking for?

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.