Saltanat Mashirova, Advanced Cyber Security Architect/Engineer

Saltanat Mashirova

Advanced Cyber Security Architect/Engineer

Honeywell

البلد
كازاخستان - Nur-Sultan
التعليم
ماجستير, Networked Systems
الخبرات
10 years, 9 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :10 years, 9 أشهر

Advanced Cyber Security Architect/Engineer في Honeywell
  • كازاخستان - Nur-Sultan
  • أشغل هذه الوظيفة منذ يناير 2021

Provide network security consultancy to various green and brown field projects to ensure effective operational deployment, ensuring solutions are designed for the Industrial Control System's technical policies and standards. Develop, deploy and maintain network security standards for the Industrial Control System network based on policy requirements, some of the day to day and long-term activities are: Future Growth Project at Tengiz (Chevron)

• Risk management and assessment
• FTE (fault-tolerant Ethernet) architectural design
• Network and systems Hardening
• Network and Cyber Security Assessments
• Network Vulnerability Assessment
• Endpoints and network hardening
• Virtualization, DMZ, Cyber security, Commissioning and Brownfield integration - (Chevron, Tengiz)
• Future Growth Project Integrated Operation Control Center, Start-up & Commissioning - (Chevron, Tengiz)
• Future Growth Project Gathering Wellpads Commissioning & Integration - (Chevron, Tengiz)

Information Security Officer في Astana International Exchange
  • كازاخستان - Nur-Sultan
  • سبتمبر 2018 إلى يناير 2021

• Managing large-scale transformation projects within the Kazakhstan Stock Exchange market, got recognition from the AIFC governor and AIX management.
• Implementation of ISO27002/27032 (Certification dated August, 2019), and meet on-going ISO27002/27032 requirements.
• AWS, Azure Cloud Security
• SWIFT Information Security Officer
• Formulating the Cyber Security Policy according to AIX's risk management process.
• Outlining and implementing a cyber security work plan based on the Cyber Security Policy with relevant company officers.
• Formulating and approving AIX's cyber security procedures.
• Raising employee awareness of cyber security issues.
• Involvement in projects and purchasing of products and services, whose acquisition has cyber security implications for AIX, with responsibility for assimilating and implementing cyber security mechanisms.
• Involvement in reception tests, as well as the deployment and assimilation stage of new ICT systems.
• Manage response and recovery process (determine containment ability while examining procedures and methods for addressing damage scenarios).
• Implement, support and maintenance of Cloud Access Security Broker (Mvision Cloud from McAfee).
• Implement, support and maintenance endpoint security controls (McAfee).
• Implement, support and maintenance Data Leakage Protection Systems (McAfee).
• Act as a BCP manager.
• Maintain infrastructure security (AWS).

Senior Specialist في BI Group
  • كازاخستان - Nur-Sultan
  • يونيو 2018 إلى سبتمبر 2018

• Interpreted clients' needs and introduced services to fit specific requirements.
• Risk Assessment of Technical Task for new development.
• Handling in-house and third-party security testing projects.
• SDLC.
• Evaluated diverse organizational systems to identify workflow, communication and resource utilization issues.
• Led e-learning, big data (BI) projects, including coordinating schedules, organizing resources and delegating work to meet deliverable and timeline requirements.

IT Security Manager في JSC Real Estate Fund Samruk – Kazyna
  • كازاخستان - Nur-Sultan
  • نوفمبر 2016 إلى يونيو 2018

JSC “Real Estate Fund “Samruk - Kazyna, Nur-Sultan,
Akmolinskaya
• Report to Board of Directors.
• Infrastructure Security.
• Information Security Program Development and
Management.
• Active Directory, McAfee DLP, IBM Lotus,
Bookkeeping software administration.
• Updating and development of internal policies and
procedures.
• Ensure IT Architecture meets security requirements.
• Information Security Awareness Training.
• Ensure that risk assessments, vulnerability
assessments, and threat analysis are conducted
consistently.

Senior IT Specialist في Stroiengineering Astana LLP
  • كازاخستان - Nur-Sultan
  • أكتوبر 2010 إلى نوفمبر 2013

Stroiengineering Astana LLP, Nur-Sultan, Akmolinskaya
• Participation in development of National Standards
of Republic of Kazakhstan in Quality of Systems
(telecommunication field).
• Work with international standard organization such
as NFPA, ISO, ASME, etc. in order to adapt
international standards in Republic of Kazakhstan.
• Audit of third-party companies.
• Development of Information Security Program
Development and Management internally.

الخلفية التعليمية

ماجستير, Networked Systems
  • في University Of California, Irvine
  • يونيو 2015

بكالوريوس, Radio Engineering,Electronics, and Telecommunication
  • في K.i. Satbayev Kazakh National Technical University
  • يونيو 2010

Specialties & Skills

Comissioning
Networks
Information Security Management
Cyber Security
Communication
Network

اللغات

الانجليزية
متمرّس
الروسية
متمرّس

التدريب و الشهادات

TOGAF 9 Certified Level (الشهادة)
تاريخ الدورة:
October 2018
“Intermediate Cyber Security for the IT Professionals” training (Dec 16, 2019 – Dec 29, 2019) at Ind (تدريب)
معهد التدريب:
IIT Kanpur
تاريخ الدورة:
December 2019
المدة:
96 ساعة
BSI ISO/IEC 27001:2013 Information Security Management Systems (Implementation and Internal Auditor) (تدريب)
معهد التدريب:
BSI
تاريخ الدورة:
February 2018
المدة:
40 ساعة
Certified Information Security Manager (CISM) (الشهادة)
تاريخ الدورة:
July 2020
صالحة لغاية:
January 2024
Certified Information System Security Professional (CISSP) (الشهادة)
تاريخ الدورة:
August 2020
صالحة لغاية:
July 2023
Certified Information Systems Auditor (CISA) (الشهادة)
تاريخ الدورة:
September 2020
صالحة لغاية:
January 2024
Global Industrial Cyber Security Professional (GICSP) (الشهادة)
تاريخ الدورة:
August 2021
صالحة لغاية:
August 2025