Expert Profile: cms02007
cms02007
Profile title:IT Sicherheitsberatung
JoinVision-ID:cms02007
Citizenship:Austria
Year of birth:1983
 
Languages:German: native speaker
English: perfect
Spanish: basics
Education
Date:since: January 2010
Type of training:Certification, CISA, ISACA
 
Date:November 2008 - November 2008
Type of training:Cours, Presentation, Knotek Training
 
Date:July 2008 - July 2008
Type of training:Certification, ITILv3 Foundation
 
Date:March 2008 - March 2008
Type of training:Cours, Architecture Essentials Training at Les Fontaines, Capgemini
 
Date:February 2008 - February 2008
Type of training:Cours, Change Management Training, Capgemini Austria & CEE
 
Date:December 2007 - December 2007
Type of training:Cours, Consulting Skills Workshop at Les Fontaines (Paris), Capgemini
 
Date:November 2007 - November 2007
Type of training:Cours, Presentation - Moderation, Knotek Training
 
Date:March 2006 - March 2006
Type of training:Certification, CCNA, WIFI
Details:

Skills: TCP/IP, ATM, Frame Relay.

 
Date:October 2005 - July 2007
Institution:FH Hagenberg, Sichere Informationssysteme
Final degree:Bachelor / Master (polytechnic university, university), ISCED 5
Details:

Skills: BSI - IT-Grundschutz, ISO 17799, Netzwerk, COBIT, ITIL.

 
Date:October 2002 - July 2005
Institution:FH Hagenberg, Computer und Mediensicherheit
Final degree:Bachelor / Master (polytechnic university, university), ISCED 5
Details:

Skills: Sicherheit, Kryptografie, Netzwerk, Programmiersprachen.

Professional experience
Date:August 2009 - January 2010
Occupation or position held:Project: Architecture Roadmap Planning
Company:Raiffeisen Bank Aval (Employee)
Details:

Review and update of the Target Application Architecture for 2012 on the basis of an architecture reference model, business principles and IT goals. Development of a project implementation plan (high risk milestones, project dependencies) to meet the requirements of the defined target architecture. Elaboration of recommendations and rules to operationalize the roadmap. Final board level presentation. Means: Questionnaires, Focused Interviews, Strategy Workshops with PMs, PMO and technical experts Role: Enterprise Architect

 
Date:February 2009 - August 2009
Occupation or position held:Project: Application Access Control
Company:International Atomic Energy Agency (IAEA) (Employee)
Details:

Rightshore project with Capgemini India, responsible for the final delivery of the master data administration and access control part of a custom developed software product based on Microsoft Sharepoint 2007 and MS SQL 2005, functional / non-functional requirements specification, test plan definition, test case specification and execution for the main stream application as well as data migration application (unit test, system test, integration test, UAT), data migration planning, team coordination, status reporting, user training preparation and execution, Role: Domain Manager, Data Migration Lead, (alternate) PM

 
Date:December 2007 - January 2009
Occupation or position held:Project: Requirements Analysis
Company:International Atomic Energy Agency (IAEA) (Employee)
Details:

Rightshore project with Capgemini India, Elaboration of detailed functional (use cases, interfaces, logical data model, user interfaces, information security classification) and non-functional requirements for an analysis application by means of workshops and presentations as well as coordination of off-site Indian team, Role: Business Analyst, alternate PM

 
Date:October 2006 - May 2007
Occupation or position held:Thesis: Web Gateway Security
Company:DREI-BANKEN-EDV GmbH (Employee)
Details:

Responsible for the evaluation of several web gateway security solutions (Bluecoat Proxy SG, Ironport S350, McAfee SWG, Aladdin eSafe GW, Secure Computing Webwasher, Websense Enterprise) and comparison with the existent internet perimeter infrastructure regarding security controls and implementation costs. Focus areas: network security, identity and access management (incl. SSO, centralized access management), high availability (Cache Load Balancing, Content switching), URL screening, content filtering, SSL scanning, Role: Project Lead

 
Date:August 2006 - September 2006
Occupation or position held:Project: MPLS-Network Design
Company:NexitraOne Austria GmbH (Employee)
Details:

Responsible for designing and supporting the implementation of a MPLS VPN network including Provider Edge and Customer Edge routers (Cisco 7600, 6500, 2800) considering confidentiality, integrity and availability services (QoS), verification of QoS parameters with IxChariot Software from IXIA (Quality assurance), recommending security controls based on best practices (NIST), Role: IT Security expert

 
Date:March 2006 - July 2006
Occupation or position held:Project: Web Application Security Testing
Company:TÜV Austria (Employee)
Details:

Development of a detailed technical guideline to perform a web application security test according to OWASP and ÖNORM 17700 including recommendations on mitigating critical security issues, Role: team member security team

 
Date:October 2005 - February 2006
Occupation or position held:Project: Penetration Test
Company:Anonymous (Employee)
Details:

Planning and enforcement of a penetration test on the basis of the guideline “A penetration testing model” published by the german Federal Office for Information Security. Conduction of technical (sniffing, mail spoofing, trojan horses, vulnerability assessment etc.) and social engineering attacks, Role: Tiger Team Member

 
Date:August 2005 - September 2005
Occupation or position held:Project: Endpoint Security Assessment
Company:DREI-BANKEN-EDV GmbH (Employee)
Details:

Evaluation of several endpoint security solutions (e.g. Cisco Security Agent, McAfee Entercept) and development of a deployment strategy for the installation of approximately 3000 Cisco Security Agents, Role: IT-Security expert

 
Date:February 2005 - June 2005
Occupation or position held:Internship: .NET Software Development
Company:Voestalpine IT GmbH (Employee, Intern)
Details:

Responsible for the implementation (Managed C++, .NET, MySQL) of an integrated, centralized firewall documentation tool (Cisco PIX, Checkpoint FW-1) in order to meet regulatory requirements, Role: Software Developer

 
Date:October 2004 - February 2005
Occupation or position held:Project: Security Performance Test
Company:NextiraOne Austria (Employee)
Details:

Execution of performance tests on network infrastructure components (Checkpoint NGX, Cisco PIX, Phion Netfence) with regards to encryption and VoIP (SIP, SCCP, H.323) followed by a recommendation of performance enhancements

 
Date:March 2004 - July 2004
Occupation or position held:Project: VPN Security
Company:Spitz GmbH (Linz) (Employee)
Details:

Establishment of a site-to-site VPN with products like Checkpoint FW-1 NG, Checkpoint Edge, Cisco PIX 501 and Sonicwall SOHO-3 and giving recommendations on security controls regarding VPNs

Resume - additional data
  • Assistance at the development of the annual Capgemini IT Security Trend Study 2008 and 2009
  • Internal lectures with regards to Enterprise Security Architektur, SOA Security and Security Aspects of the Software Development Lifycycle
Experience Profile
Field of activityExperience [years]
Consulting/Education 3.0
IT Organisation / Analysis 1.2
Project Management 1.0
Quality Management 1.0
Software Development 1.5
SkillExperience [years]
Security / Cryptography 5.0
ISO 27001 3.0
Methods/Architecture 3.0
IT-Consulting/IT-Support 2.5
Programming Languages 2.0
Network 2.0
ITIL 1.5
Data Modeling 1.5
BSI - IT-Basic Protection 1.0
COBIT 1.0
Banking 0.5
Career aspiration
Type of occupation:Regular employee
available from:04/01/2010 at 100 %
Desired position(s):Co-worker, Project manager, Team leader
Desired field of activity: Consulting/Education
IT Organisation / Analysis
Project Management
IT Architecture
Mobility:high
Assignment location:Austria, Croatia, Czech Republic, Germany, Poland, Romania, Russia, Slovakia, Switzerland, Ukraine, United Kingdom