Working in the IT / Information Security field for more than 20 years, specifically in the fields of Internal Auditing, Risk Consulting and Information Security, holding a BSc in Physics from the National and Kapodistrian University of Athens, Greece. Professional certifications: Cisco Certified Network Security Professional (CCNP), Certified in Risk and Information Systems Control (CRISK), Certified Information Security Manager (CISM), ISO27001 Lead Auditor and Cisco Intrusion Prevention System Specialist (CIPSS).Experience:- Security Standards (e.g. ISO 27000 Series, COBIT, ISF, NIST, PCI-DSS, etc.) - Network Security (e.g. IDS/IPS, Firewalls, Routers, Switches, etc.)- ISO/IEC 27001:2013 Implementation (based on ISO/IEC 27003:2017), Training, Audit and Awareness- Risk Analysis & Management (e.g. ISO/IEC 27005:2018, NIST SP-800-30, CRAMM, COBIT Risk IT, etc.) - Risk Methodologies & Training- IT Risk Assessments & Controls Audits using NIST Cybersecurity Framework (CSF)- Information Security Management & GRC Tools / Platforms- Extensive experience and knowledge of Laws & Legislation with regard to Information Security, Data Protection & Privacy- Extensive experience and knowledge of GDPR (Gap Analysis, Business Process & Data Mapping, PIA, Risk Assessment)- Privacy Information Management System (PIMS) (based on ISO/IEC 27701:2019 an extension to ISO/IEC 27001:2013 and ISO/IEC 27002:2013 for privacy management)- Business Continuity & Disaster Recovery Plans (based on ISO 22301 & ISO 27031)- Information Security Incident Management (based on ISO/IEC 27035-1 & ISO/IEC 27035-2)- Records Management (based on ISO 15489-1:2016 & ISO/TR 15489-2:2001), Data Retention & Disposal- International Standard on Assurance Engagements (ISAE) 3402 (SOC2 Type I & II reports)- Quality Standards (e.g. ISO 9001:2015, ISO 9004:2018)- National Industrial Security Certificate (EKBA)
Listed skills include Information Security Management, Information Security, Network Security, Iso 27001, and 30 others.