Tom Solowczuk
Principal Architect @ING
Signup · Get unlimited contacts
WORK HISTORY
Principal Architect @ING
Developing and implementing verious security standards within financial ecosystem.
EDUCATION
Adam Mickiewicz University
Bachelor's degree, Physics and Information Technology
ABOUT TOM SOLOWCZUK
I Successfully provide professional Security Infrastructure and architecture for over 10 years. Recently I have developed operating model for Security Architecture and nested within the portfolio delivery programme. I and can deliver wherever following experience is required- Information Security Policy development- Security Strategy and roadmaps- Secure design principles- Security architectural elements: framework, standards, guidelines, Non-Functional Security Requirements and more other document templates- Security functions integration with existing services- Non-functional security requirements- Network security - both trust and Zero-trust models. Network segmentation- Security Architecture experience with NIST, CIS, ISF SoGP, ISO27001 security controls and CobIT security standards- Application Security – OWASP TOP10 and ASVS 3 levels controls in SDLC. SANS25 (CWE), Developer security tools - Dependency check, Static and Static/Dynamic application security testing- Threat modelling techniques (STRIDE model)- Vulnerability, configuration management and response- PCI DSS v 3.2 requirements (particular PA-DSS part)- Cyber security tools for SOC compilation (SIEM & Sentinel integration)- Broad IT Systems experience within a large scale environment- Cloud IaaS/PaaS: AWS & Azure (security controls risk and mitigations)- Cloud SaaS: EDR, Blackberry, Citrix and VMware Unified Endpoint Management- Implementation of near Zero-day protection processes- Deep endpoint security experience - Data Loss Prevention, Anti Malware, Drive Encryption, EDR, IPS, WEB control, DXL fabric, Threat Intelligence Exchange and near zero day protection – sandboxing- Security compliance, audit and develop remediation methods (Splunk and distribution tools)- Prepare security controls RFP (request for proposal) to vendors to ensure they meet security needs- Document security infrastructure- Network security tools- Change release management in large organizations and Agile framework
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.