Defensive mindset, offensive expertise. In IT and security since 2012: from server rooms and a Security Operations Centre to the audit table, and now to Dokimos.
Story
Proof over promises.
I started in 2012 as a system administrator: networks, servers, virtualisation, and a lot of night-time migrations. Over the following years, at a fintech group, I moved from administration into security. I founded its Security Operations Centre, built vulnerability management, and ran a PCI DSS programme through its audits.
Today I am an Information Security Manager. Alongside that, through CyberTwierdza, I work on security architecture, penetration testing and compliance readiness for regulated organisations.
Dokimos comes out of that work. Every framework asks for proof, and every request starts from scratch, usually in a spreadsheet. I want compliance and DevSecOps teams to collect evidence once, validate it once and reuse it everywhere.
Certifications
Tested, and found current.
Governance and offensive security, cloud and AI. Each one is a stated test, passed.
Governance and risk
- CISSPCertified Information Systems Security Professional · ISC2
- CCCertified in Cybersecurity · ISC2
- PCI DSS LIPCI DSS Lead Implementer · IBITGQ
AI
- CCAR-FClaude Certified Architect – Foundations · Anthropic · September 2026Newest
- AWS Certified AI PractitionerAmazon Web Services
Offensive security
- CPTSCertified Penetration Testing Specialist · Hack The Box
- CWESCertified Web Exploitation Specialist · Hack The Box
- CRTOCertified Red Team Operator · Zero Point Security
- CJCACertified Junior Cybersecurity Analyst · Hack The Box
Cloud and infrastructure
- MCSAMicrosoft Certified Solutions Associate · Microsoft
- AZ-900 · SC-900Azure Fundamentals; Security, Compliance and Identity Fundamentals · Microsoft
- CCNACisco Certified Network Associate · Cisco
- LPIC-1Linux Administrator · Linux Professional Institute
Career
Fourteen years, one direction.
Employers and clients are not named here.
- Information Security Manager
A fintech and payments group.
- Security consultant, CyberTwierdza
Penetration testing of web, API, mobile, infrastructure, cloud and PCI DSS-scoped systems; compliance advisory.
- Lead Cybersecurity Specialist
Led the SOC and security team, ran risk assessments under ISO/IEC 27001 and ISO/IEC 42001, and managed the PCI DSS programme.
- Lead Cybersecurity Specialist
Founded a Security Operations Centre and built vulnerability management.
- Senior, then Lead System Administrator
Identity and access management, and a security baseline.
- System Administrator
Networks, servers and virtualisation.
- Engineer's degree, Information Technology
Belarusian State University of Informatics and Radioelectronics; then Cisco Networking Academy.
Selected work
What the work looks like.
Client names withheld.
- Security architectureDesigned and delivered security architecture for payment and cloud platforms, reviewed against CIS, NIST CSF and PCI DSS v4.0.
- Audit readinessLed readiness for, and supported, external audits against DORA, PCI DSS v4.0, ISO 9001, ISO/IEC 27001 and ISO/IEC 42001.
- AI assuranceBuilt an assessment method for generative-AI applications and RAG pipelines, based on ISO/IEC 42001 and the NIST AI RMF.
- LLM application testingTested LLM applications against the OWASP Top 10 for LLM Applications and MITRE ATLAS.
- Penetration testingWeb, API and cloud applications, reported against OWASP ASVS.
- Security operationsFounded a SOC: L1 and L2 processes, KPIs, SLAs and training.
Off the clock: Weiqi (1 kyu), scuba diving, drones, amateur radio and capture-the-flag.
Talk about Dokimos, or an engagement.
Early access, a readiness question or a penetration test: write, or find me on LinkedIn.