Über Vladimir
Who I help
What I do
How I work
Englisch
Muttersprachlich oder zweisprachig
Deutsch
Muttersprachlich oder zweisprachig
Projekt- und Berufserfahrung
- BioNTech AGManager Cloud SecurityBIOTECHNOLOGIEFebruar 2024 - Heute (2 Jahre und 4 Monate)Mainz, Deutschland
- Lead cloud security across AWS & Azure for regulated biotech workloads; align guardrails with ISO/IEC 27001:2022/27002, GxP/CSV, CIS and emerging NIS2 expectations.
- Strengthen Kubernetes (EKS/AKS) security: cluster hardening, secrets/image scanning, workload policies.
- Drive vulnerability & dependency management: SAST for IaC/SBOM integrated into CI/CD (secure pipelines), developer enablement and fix-path prioritization.
- Implement and tune CSPM/CNAPP programs (policy baselines, noise reduction, risk triage) with clear remediation SLAs and dashboards.
- Design and operate multi-account landing zones: IAM least privilege, network segmentation, encryption, centralized logging, backup/DR.
- Own the cloud ISMS (risk assessments, SoA, policies/procedures) and prep/support internal & external audits.
- DATEVApplication Security Lead and Software ArchitectHIGHTECHMai 2022 - Januar 2024 (1 Jahr und 8 Monate)Nuremberg, Deutschland
- Security Lead & Software Architect, hands-on full-stack engineer for a payroll platform. Built a microservice- and modulith-oriented architecture using Domain-Driven Design (>45 microservices).
- Authored the DATEV Security Guideline and embedded it into the SDLC of 12 development teams.
- Led a virtual team of 4 Cloud Security Engineers; set standards, code reviews, coaching, and threat modeling.
- Implemented DevSecOps controls: SAST, DAST, dependency/SBOM hygiene, secrets management, secure coding checklists aligned to OWASP ASVS & ISO/IEC 27001.
- Drove vulnerability management and remediation SLAs; defined risk triage & risk acceptance processes.
- Partnered with architecture guild on security patterns (authn/authz, crypto, logging/monitoring).
- Results: fewer critical findings in pipelines, consistent control baselines across teams, faster audit readiness.
- DATEVSecurity Champion and hands-on Software ArchitectHIGHTECHMai 2019 - Oktober 2020 (1 Jahr und 5 Monate)Nuremberg, Deutschland
- Security Champion & hands-on Software Architect for a microservice-oriented payroll platform.
- Built an automated secure SDLC for 9 development teams: threat modeling, application security testing (SAST/DAST), software composition analysis (dependency & license mgmt.), and continuous optimization of analysis workflows (noise reduction, triage, SLAs).
- Chaos engineering initiatives to validate resilience and security controls in production-like environments.
- Optimized the company’s online development security guideline; co-authored the DATEV Security Guideline and embedded it into team workflows and checklists.
- Company-wide rollout of dependency/license management and dynamic application security testing integrated into CI/CD.
- Trained engineers & local security champions; created playbooks and review checklists; partnered with architecture & platform teams.
- Results: standardized security practices across teams, fewer critical findings, faster pipeline feedback, better audit readiness.
Empfehlungen
Sei die erste Person, die Vladimir empfiehlt
Teile Deine Erfahrung aus der Zusammenarbeit mit diesem Freelancer.
Diese Freelancer passen auch zu Ihren Kriterien
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Ausbildung und Abschlüsse
- Master of Science Computer ScienceFriedrich-Alexander University Erlangen–Nuremberg2016