The people who do the work.

Six specialists. Between them, ninety percent of what the five lines require.

Serhii A. — Platform & Security Architecture Lead

Builds the platform layer and sets the security standard the rest of the team works to. Ten years running enterprise Azure environments for global reinsurance and Fortune-class clients — API management, DBaaS, industrial IoT — and leading the engineering teams that operate them. Holds four Microsoft expert-level certifications, including Cybersecurity Architect Expert.

Covers — 1 Technical Measures · 2 Detection and Testing

Zero-Trust architecture, IAM/RBAC/MFA, IT/OT segmentation · Azure (AKS, API Management, Key Vault, Firewall, WAF, DDoS Protection), AWS, Kubernetes · Terraform, policy-as-code, GitOps · Azure Monitor and Log Analytics anomaly detection, automated incident response · DORA, NIS2

Certifications — Azure Solutions Architect Expert · Azure Cybersecurity Architect Expert · Azure DevOps Engineer Expert · Azure Security Engineer Associate · CKAD · HashiCorp Terraform Associate · Certified Backstage Associate

Serhii F. — Cloud Infrastructure & Compliance Architect

Designs cloud environments that can survive an audit. Eight years specialising in AWS, GCP and Azure security, building infrastructure against DORA and SOC 2 from the ground up rather than retrofitting it. Automates the scanning layer — Trivy, Prowler, AWS Inspector, GitLeaks — so findings surface in the pipeline instead of in a quarterly report. Cut one client’s monthly infrastructure spend from 75,000 to 25,000 euros without reducing coverage. Speaks German.

Covers — 1 Technical Measures · 3 Evidence Check

DORA and SOC 2 infrastructure design, CIS Benchmarks, Zero-Trust, IAM/RBAC · Automated vulnerability scanning (Trivy, Prowler, AWS Inspector, GitLeaks, SonarQube) · Perimeter defence — AWS WAF, Cloudflare, GuardDuty, network ACLs, VPC isolation · AWS, GCP, Azure, Kubernetes (EKS/ECS), Terraform, Terragrunt · Centralised logging and threat analysis — OpenSearch, Datadog, CloudTrail, ELK

Certifications — AWS Security Champion · AWS Well-Architected Proficient · AWS Security Essentials · AWS Cloud Practitioner · Microsoft Certified: Azure Fundamentals

Alex M. — Infrastructure & Network Security Engineer

The one who draws the line between the corporate network and the production floor. Ten years across AWS, Azure and OCI, with a network engineering background deep enough to design multi-vendor data centres — Cisco ACI, Nexus, Juniper QFX, VXLAN — which is what IT/OT segmentation actually requires and what most cloud engineers cannot do. Built DORA and NIS2 compliance frameworks end to end. Runs the patch management and penetration test coordination.

Covers — 1 Technical Measures · 2 Detection and Testing

IT/OT network segmentation, multi-vendor data centre design (Cisco ACI, Nexus, Juniper QFX, VXLAN) · Identity-first security — IAM/PAM, Zero Trust, MFA · Anti-DDoS (AWS Shield, Cloudflare), perimeter defence, anti-phishing and email security (SPF/DKIM/DMARC) · Automated patch and vulnerability management (Qualys, Wazuh, Grype, Trivy) · Terraform, Pulumi, Ansible, Kubernetes (EKS, AKS, OpenShift) · Prometheus, Grafana, OpenTelemetry, ELK · DORA, NIS2

Certifications — Cisco CCNP Enterprise · Cisco CCNA · AWS Solutions Architect Associate (in progress)

Ruslan T. — Offensive Security Lead

The person who breaks things before an attacker does. Twenty-five web, API and network engagements delivered, twelve critical vulnerabilities found. Writes his own exploits — buffer overflow, use-after-free, ROP chains — and reverse-engineers malware in Ghidra and x64dbg rather than reading someone else’s report about it. Built a full SIEM and SOC stack on ELK, Wazuh and MITRE ATT&CK that cut incident response from five hours to twenty-five minutes. Also runs local-LLM tooling for adversarial prompt testing, which is where offensive security is going next.

Covers — 2 Detection and Testing

Exploit development, red-team tradecraft · Reverse engineering (Ghidra, x64dbg, Frida), malware analysis, anti-debugging bypass · Web and API penetration testing (Burp Suite Pro, OWASP ZAP, Nuclei, SQLmap), OWASP Top 10, GraphQL, JWT, SSRF · SIEM and detection engineering (ELK, Wazuh, Sysmon, auditd, MITRE ATT&CK) · AI and LLM security, adversarial prompt engineering · SAST/DAST pipeline integration, CI/CD policy gates · PCI DSS v4.0, ISO/IEC 27001, GDPR

Mykyta L. — DevOps & Cloud Infrastructure Engineer

Keeps the delivery pipeline and the monitoring honest. Built CI/CD and observability from nothing on more than one project, and has operated IoT infrastructure at a scale of millions of connected devices — which is the failure mode most platforms never get tested against. Handles SOC 2 readiness work and the vulnerability tooling that sits inside the pipeline.

Covers — 1 Technical Measures

Kubernetes (EKS), Docker, Helm · Terraform, CloudFormation, Ansible, Packer · CI/CD — GitHub Actions, GitLab CI, Jenkins, CircleCI · Observability — Datadog, New Relic, Grafana · Vulnerability tooling — Snyk, SonarQube, HashiCorp Vault · SOC 2 readiness, IAM, incident response · AWS, Azure, large-scale IoT infrastructure

Yurii Sh. — Security Analyst, SOC

Blue team. Watches what the others build. Handles the firewall and VPN layer directly — Cisco ASA and Firepower, Fortinet FortiGate — and runs the vulnerability and code scanning that gates the pipeline. The junior member of the team, and the one on the console.

Covers — 1 Technical Measures · 2 Detection and Testing

Firewall and perimeter configuration — Cisco ASA/Firepower, Fortinet FortiGate NGFW, ACL management · VPN (SSL/IPSec), UTM, IPS/IDS, web and email filtering · Vulnerability management (Qualys), code scanning (SonarQube, Checkmarx), dependency control (JFrog Artifactory) · Secure CI/CD (Jenkins, GitLab CI), IAM, threat modelling · Python, Bash, Ansible, Terraform · AWS, GCP, Docker, Kubernetes, Linux hardening