Tomáš Filip personal email
- Valid
Experienced security lead professional helping global industry leaders to build from scratch and optimize sustainable security operations. EXPERTISE:• IT Security Lead with 17 years of experience;• Successful creator of various unique regional & global security functions for global industry leaders in pharmaceutics, banking, insurance, and food and beverage industry; and• Security team management – structuring and staffing national, regional and global, multitier international security teams (up to 40 members). MAIN AREAS:• Risk analyses & mitigation;• Incident response;• Quality assurance;• Change management; • Team building & leadership; and• New functions designed and implemented from scratch.FOCUSE:• Security operations center;• Security governance;• Incident response;• Advance security analytics - APT detection, analyses and remediation; and• SIEM.EXPERIENCE:• Built and implemented the framework for monitoring IT risks & controls in banking sector – the Czech National Bank; • Implemented sustainable SOX control framework successfully attested ; • Designed and led the implementation of access rights management according to SOD principles in SAP;• Designed and implemented IT security strategy;• Built global Security Operations Center team including the 2nd largest SIEM deployment in Europe; and• Designed and built process for monitoring and early detection of business user malicious activities (data theft).
Curium Pharma
View- Website:
- curiumpharma.com
- Employees:
- 1830
-
Global Head Of Cyber SecurityCurium PharmaPrague, Czechia -
Senior Cyber Security ManagerCurium Pharma Nov 2021 - PresentPrague, Czechia -
Head Of SecurityO2 It Services S.R.O. Jun 2020 - Oct 2021Prague, Czechia -
Head Of Cyber Defense CenterAec A.S. Feb 2019 - Feb 2020Prague, The Capital, Czech Republic -
Head Of Information Security And BcmNakit - National Ict Agency Feb 2017 - Jan 2019Prague, The Capital, Czech Republic- Build the Security Operations Center (SOC) function for e-Government and Ministry of the Interior - Led a consulting team for cyber security matters serving the Ministry of the Interior - Build and providing internal security and business continuity management (BCM) functions for the company
-
Head Of Global Security Operations CenterNovartis Aug 2013 - Jan 2017Prague- Established the Global Security Operations Center function from scratch together with a project team- Led SOC in 24/7 model- Managed multinational team of specialists - Operated in the environment under SOX, GxP and HIPPA regulations- Determined strategy and road map based on risk assessment the in all above-mentioned areas - Determined and managed development and implementation of necessary policies, procedures and controls to ensure IT compliance with legislative and Company requirements (e.g. polices, operations guides, training, on-boarding and off-boarding manuals, work instructions for use cases, service descriptions with internal and external customers, data privacy risk assessment)- Established and monitored routine procedures to ensure effective working of processes in operations;- Facilitated audits and penetration tests focused on SOC, evaluation and control on implementation of fixes;- Communicated with peers and management on performance, strategy and plans of SOC- Managed vendors (SIEM, service providers)- Communicated with system/log source owners on SOC services, onboarding process, phases and service conditions- Implemented incident ticketing and handling tool, detection & investigation supporting tools and external security threat feeds -
It Security & Governance DirectorCeska Pojistovna Jan 2012 - Jul 2013- Over 15 000 users and 400 IT specialists;- Determined the strategy and scope of IT Security based on the risks assessment;- Determined and managing of the development and implementation of necessary policies, procedures and controls to ensure IT compliance legislative and Company requirements e.g. End User Policy, IT Risks management, Incident management, Secure Application Development, Security Configuration Standards for all OS, Desktops, AV; - Established and managing a team for security event logging and on-line monitoring over critical IT infrastructure (OS, DB and APP level, hundreds of servers);- Established and managing a team for IT forensic investigation;- Established a data leakage protection team using unique scoring system- Assessed changes to IT infrastructure and applications and determining security requirements to fulfill security standards and cover risks;- Developed and managing security of mobile devices;- Established and monitoring of routine procedures to ensure effective working of the controls (also related to FARG – Italian equivalent of SOX using ITGC);- Carried out checks to determine that controls are run as specified (sustainability, ensuring compliance with FARG);- Ensured the conduct of the necessary internal assessment tests defined in the procedures and implementation of fixes required;- Facilitated and managing audits and penetration tests, evaluation and control on implementation of fixes;- Developed and managing of awareness trainings;- Implemented and managing the user authorization process for privileged and also business users; - Maintained internal certification authority;- Deviations management; - Provided periodic Security reporting to the executive board;- Managed teams for change management and release management.
-
Global Security Team LeaderGenerali Sep 2010 - Jul 2013- Defined focus and scope;- Led cross boarder activities;- Ensured consistent common approach across Europe;- Led development of global guidelines; - Developed shared knowledge bases for various areas e.g. incidents, policies, projects, security technologies; -
It Security DirectorČeská Pojišťovna Jun 2008 - Dec 2011
-
It Controls And Security ManagerPlzeňský Prazdroj Jul 2005 - Jun 2008- Over 3500 users in 5 countries and 100 IT Specialists- Determined and managed the development and implementation of necessary policy, procedures and controls to ensure IT compliance legislative and Company requirements;- Established and monitored routine procedures to ensure effective working of the controls; - Carried out checks to determine that controls are run as specified;- Facilitated and managed audits and penetration tests, evaluation and implementation of fixes;- Developed and managed awareness trainings;- Implemented and managed the user authorization process; - Acted as Information Security Officer for Central n Europe; o FW, VPN, Logical security, Physical Access, AV, Application security, Network security, Change Management, Incident and Problem Management, End User Environment, Security on projects etc.- Shared knowledge among SABMiller Information Security Officers members in SABMiller´s Global Security Board. Project Leadership IT General Controls Manager (SOX)- Implementation and maintenance of Sarbanes-Oxley requirements in IT as project manager;- Determination and management of the development and implementation of necessary policy, procedures and controls to ensure IT compliance legislative and Company requirements;- Establishment and monitoring of routine procedures to ensure effective working of the controls; Segregation of Duties and privileged rights management in SAP (CZ,SK, HUN)Emergency access for IT employees to SAP -
Information Security OfficerSabmiller Jul 2005 - Jun 2008 -
It SupervisorThe Czech National Bank Apr 1999 - Jun 2005Initially focused on internal control systems in banks and their internal audit functions. In 2002, moved to a new team for audit/control of managing risks in IS/IT in commercial banks, including on-site inspections of IS/IT management by said banks.During on-site inspections, acted as IT security leader (2-4 people) or took over as team leader (6-7 people), which involves checking and assessing the following:- Development of IS/IT strategies,- Organization of IS/IT and separation of divergent functions,- Quality of all written materials having to do with IS/IT,- Security policies for IS/IT,- Classification and protection of information assets,- Evaluation of IT risks and risks analyses,- Security lapses in IS/IT area,- Outsourcing IT,- Personal security in IS/IT,- Physical plant security in IS/IT,- Monitoring use of and access to systems,- DRPOther responsibilities:- Contributed to internal methodology for IT security- Analyzed, judged and ultimately (dis)approved IT-related clauses for banking license applications or requests for changes in existing licenses;- Assessed the outsourcing and insourcing of IS/IT by banks,- Contributed to new legislation concerning IS/IT,- Contributed to new models for rating banks (using the risk based approach).
Tomáš Filip Skills
Tomáš Filip Education Details
-
Economics, Law, Informatics -
Economics Of Tertiary Sector
Frequently Asked Questions about Tomáš Filip
What company does Tomáš Filip work for?
Tomáš Filip works for Curium Pharma
What is Tomáš Filip's role at the current company?
Tomáš Filip's current role is Global Head of Cyber Security.
What is Tomáš Filip's email address?
Tomáš Filip's email address is fi****@****ail.com
What schools did Tomáš Filip attend?
Tomáš Filip attended Czech University Of Life Sciences Prague, University Of West Bohemia, Pilsen.
What skills is Tomáš Filip known for?
Tomáš Filip has skills like Information Security, It Audit, Security, Information Technology, Information Security Management, Risk Management, Itil, It Management, Iso 27001, It Service Management, Sarbanes Oxley Act, Auditing.
Who are Tomáš Filip's colleagues?
Tomáš Filip's colleagues are Martin Ducros, Sandrine Vergison, Philippe Delbos, Derek Mcclure, Thomas Delacour, Antoine Caperaa, René Blaauw.
Not the Tomáš Filip you were looking for?
-
Tomáš Filip
Rychvald -
1umusic.com
-
Tomáš Filip
Brno -
2skoda-auto.cz, man.eu
2 +498915XXXXXX
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial