You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Dragan StevanovićDS

Durchschnittliche Reaktionszeit: 1h

Über Dragan

AI Security Architect with 20+ years in enterprise security, threat modeling and risk management. I help organizations safely adopt and scale AI/LLM solutions by assessing risks, reviewing architectures and establishing practical AI security governance aligned with EU AI Act, ISO/IEC 42001 and NIST AI RMF. I support AI, Data Science, engineering and security teams with clear guidance, actionable controls and fast, outcome‑driven reviews.
  • Englisch

    Muttersprachlich oder zweisprachig

  • Serbisch

    Muttersprachlich oder zweisprachig

  • Bosnisch

    Verhandlungssicher

  • Kroatisch

    Verhandlungssicher

Nur remote
Führt Projekte hauptsächlich remote aus

Projekt- und Berufserfahrung

  • Allianz Tech SE
    AI Security Architect/Consultant — securing AI adoption from PoC to Production.
    TECH
    Mai 2018 - Heute (8 Jahre und 2 Monate)
    Munich, Deutschland
    With 20 years in enterprise cyber security architecture, threat modeling and risk management across regulated industries, I help AI engineering and security teams understand AI capabilities, assess risks and establish security governance for AI/LLM initiatives aligned with current threats and regulations (EU AI Act, ISO/IEC 42001, NIST AI RMF).
    AI Governance & Lifecycle Assessment (max 2 weeks)
    Input: Current AI adoption state (questionnaire). Gap analysis: NIST AI RMF, EU AI Act, ISO/IEC 42001.
    Deliverables: AI Security Gaps (processes, technologies, skills), AI Security Governance Strategy, Acceptable AI Use Policy, Project Lifecycle Security Playbook, AI risk register, SDLC/MLOps (runtime) concepts, Incident Response runbook (model drift, prompt injection, LLM data exfiltration).
    AI Security Architecture Review (within 1 week)
    Review AI/LLM service architecture, identify design flaws, real life threats, assessed risks and defined a risk‑prioritized remediation plan.
    Input: AI service purpose, use cases 7FRs, architecture diagrams, data stores/flows, user access, APIs, vector stores, RAG pipelines, agent tool permissions, identity & secrets.
    Deliverables: Prioritized threats list mapped to design flaws and safeguards, annotated architecture diagram, actionable mitigation strategy and costs estimated - all included in Architecture Decision Proposals (ADP).
    Threat Modeling Workshop (1 or 2 days)
    AI‑assisted hands‑on training using STRIDE +LINNDUN+MAESTRO frameworks. Covers prompt injection, data poisoning, model extraction, data leakage, insecure plugins, supply‑chain risk, jailbreaks.
    Deliverables: Methodologies, case study (threat actors, vectors, AI + traditional kill chains, risk scoring), mitigations mapped to engineering tasks.
    Background: Security Architecture · AI Security · Cloud Security · Pentesting · Threat Modeling · AI Governance · CISO risks reporting
    Free 1h consultation - concerns & needs. Book: https://calendar.app.google/PqEqJw9FddP4Q1eQ6

Empfehlungen

Sei die erste Person, die Dragan empfiehlt

Teile Deine Erfahrung aus der Zusammenarbeit mit diesem Freelancer.

Diese Freelancer passen auch zu Ihren Kriterien

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Zertifizierungen

  • CISSP, ID: 1750339
    ISC2
    2023
    https://www.isc2.org/verify-a-member
    Security & Risk Management Identity & Access Management Communication & Network Security Asset Security Security Architecture & Engineering Software Development Security Security Operations Security Assessment & Testing
  • Certificate of Cloud Security Knowledge v.4
    Cloud Security Alliance
    2024
    https://www.credly.com/badges/10eff22e-79b3-4dbf-908a-9d2444ca3eb5/linked_in_profile
    Incident Response in Cloud Environments Identity, Access & Key Management Cloud Governance (CSA CCM & ENISA) Virtualization & Container Security Cloud Architecture & Data Security Cloud Security Fundamentals Cloud Application & API Security Cloud Risk Management & Compliance

Fähigkeiten

Kategorien