مصطفى  كمال, Lead information security engineer

مصطفى كمال

Lead information security engineer

Loyalty service llc

البلد
روسيا
التعليم
ماجستير, Cyber Security
الخبرات
6 years, 0 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :6 years, 0 أشهر

Lead information security engineer في Loyalty service llc
  • روسيا - Moscow
  • أشغل هذه الوظيفة منذ أغسطس 2023

• Internal and external audit of IT infrastructure.
• Penetration testing, Incident analysis and response
• Installation, configuration of SIEM system, IDS/IPS etc.
• Develop, design and implement DevSecOps strategy and architecture
• Developing threat model using MITRE_ATT&CK framework
• Security awareness training for employees including social engineering
• Development, defining, implementation of regulatory documents in accordance with Federal Laws and ISO 27001, 27002, PCI DSS, MITRE, SANS, NIST, OWASP.
• Collaboration, signing agreements with vendors and clients

Leading IT Engineer في Evraz Vanadi
  • روسيا - Moscow
  • مايو 2022 إلى فبراير 2023

• Installation, configuration, troubleshooting and management of networking devices, servers, services, subsystems, Exchange servers, DHCP, AD, ACL etc.
• Installation, configuration, troubleshooting and management of Zabbix for enterprise IT infrastructure monitoring.
• Troubleshooting, maintaining and management of IoT devices.
• Implemented automation for information security processes.
• Participated in IT infrastructure development planning.
• Provided information security for remote offices through VPN.
• Conducted network troubleshooting and security analysis.
• Utilized PowerShell and Python for system administration tasks.

System Administrator في Haval motors manufacturing Rus LLC
  • روسيا - Tula
  • سبتمبر 2021 إلى مايو 2022

• Ensured smooth operation of local networks, servers, & network devices.
• Managed 300 workstations including MES workstations.
• Registered and managed user accounts and passwords.
• Implemented data copying, archiving, and backup processes.
• Provided technical and software support to users.
• Managed Active directory
• Identified and resolved network and program errors.
• Implemented measures for ensuring technological security.

System security administrator في Central Hospital
  • روسيا - Moscow
  • مارس 2021 إلى سبتمبر 2021

• Performed all tasks and duties of system administrator such as managing 190 workstations including special medical equipment’s, troubleshooting network, servers, AD, ACL, DNS, DHCP, and network devices.
• Administered and secured hospital website.
• IT audit of the hospital
• Participated in information security system implementation projects.
• Assisted in infrastructure and network IT projects.
• Utilized and implemented virtualization using VMware.
• Maintained office equipment, prepared documentations and inventory.
• Worked with specials medical software and devices.

Junior Penetration tester في Vendorie
  • روسيا - Moscow
  • يناير 2017 إلى فبراير 2020

Vulnerability assessment, Penetration testing utilizing all open-source tools included in Kali Linux such as OpenVAS, Nmap, Nikto, Burpsuit, Nessus, SQLMap, Theharvester, sublist3r, Netcat, Google Dorks, Dirb, enum4linux, DNSRecon, Dig, Metasploit, John the Ripper, Wireshark, Ettercap, Hping3, Mimikatz etc.

الخلفية التعليمية

ماجستير, Cyber Security
  • في Tula State University
  • ديسمبر 2023

Project: Use of machine learning technology in penetration testing: Focus on IDS evasion Project: Opensource software threats Practical project: Critical infrastructure security threats and solutions Paper: Secure DevOps practices scientific research on ML based IDS evasions using saliencyMapattack with cleverhans framework. creating/writing and training ML based python program to evade IDS and proposing defence mechanism.

بكالوريوس, Secure Systems and Networks
  • في Siberian State University of Telecommunications and Informatics
  • يناير 2020

Bachelor: Infocommunication Technologies and Communication Systems Specialization: Secure Systems and Networks University: Siberian State University of Telecommunications and Informatics, Novosibirsk

Specialties & Skills

System Administration
Linux server administration
Firewall Administration
Penetration Testing
Network security analysis
web security
telecommunications
problem analysis
microsoft servers
servers
linux server
Penetration testing
Server engineer
Bash scripting
Pfsense configuration and installation
Fortigate firewall installation and configuration
server troubleshooting
PowerShell scripting
Server deployment automation via PowerShell
Linux server administration
windows Server administration
CISCO switch configuration
Firewall configuration
Incidence response
SIEM setup and configuration
IP table configuration
Server Monitoring
Zabbix configuration and troubleshooting
VMware ESXi administration
Splunk installation and configuration
windows server
systems management
network engineering
computer hardware troubleshooting
windows network administration
network operations
networking software
system administration
system maintenance
firewalls
security management
risk management
vulnerability management
vulnerability assessment
cyber security
information systems development
endpoint security
web application security
security information
security
routing
access control
Google cloud
Docker, Docker-Compose
Ansible
GitLab, GitHub
Firewall configuration, IPS IDS setup SOC analyst
Jenkins
Terraform
Cloud Computing (Yandex Cloud, Google Cloud, Azure, Selectel)
Active Directory

اللغات

الانجليزية
متمرّس
الروسية
متمرّس
الأوردو
اللغة الأم

التدريب و الشهادات

Certified Ethical hacker CEH (تدريب)
معهد التدريب:
Eccounsil
تاريخ الدورة:
January 2023
Cyber security analyst (الشهادة)
تاريخ الدورة:
April 2020
SSCP (تدريب)
معهد التدريب:
ISC²
تاريخ الدورة:
July 2020
المدة:
100 ساعة
Development of a Secure online store "Vendorie" and penetration testing (تدريب)
معهد التدريب:
Sibsutis
تاريخ الدورة:
September 2020
المدة:
40 ساعة

الهوايات

  • Gym, Learning about trending IT topics, Volleyball