Navigation überspringen

Hasty Atashzar

Angestellt, Lead I&T Security Risk Manager, INFOAMN Consulting Group (IT Management and Security Consulting)
Königstein im Taunus, Deutschland

Fähigkeiten und Kenntnisse

Team work
Project Management
MS Office
Communication skills
Information Security
ISMS
iso27001
CObIT
soc2
IT Risk Management
Information Security Management System
SIEM
DevSecOps
SDLC
NIST 800-53
NIST 800-218
OWASP ZAP
Burp Suite
Nikto
Checkmarx
SonarQube
Vulnerability Scanner
Vulnerability management
Information Security Engineering
IT Security
Cloud Security
Amazon Web Services (AWS)
Web Security
Risk management
IT Security Audits
Risk Management / Risk Control
Risk Analysis
Management
Consulting
Compliance
Reporting
Security Management
Risk Controlling
Business Continuity Management
TISAX
Machine Learning
Penetration Testing
Incident Management
IT-Security
IT-Incident Management
Threat analysis
ability to work under pressure
Negotiation skills
Python pandas
Python NumPy
Python programming
TensorFlow
SOC
PMBOK

Werdegang

Berufserfahrung von Hasty Atashzar

  • Bis heute 4 Jahre und 9 Monate, seit Okt. 2020

    Lead I&T Security Risk Manager

    INFOAMN Consulting Group (IT Management and Security Consulting)

    • Implemented COBIT 2019-aligned risk management processes, reducing organizational risk exposure by 25% through data analysis and dynamic dashboards. • Led end-to-end SOC 2 Type II audits, streamlining control implementation and cutting compliance timelines by 20%. • Developed CI/CD pipeline-integrated tools for early vulnerability detection, ), ensuring alignment with ISO 27001 and NIST (NIST800-53, NIST 800-218) standards. reducing manual review efforts by 30%.

  • 4 Jahre und 2 Monate, Sep. 2016 - Okt. 2020

    Information Security Risk Manager

    Faradis Alborz Informatics Group (Banking Service Provider)

    • Led ISO 27001 implementation, resolving all non-conformities and reducing security incidents by 30%. • Developed risk treatment plans using Cobit5 and achieved 95% stakeholder buy-in for mitigation strategies. • Trained 100+ staff on threat modeling, cutting phishing susceptibility by 40%

  • 2 Jahre und 1 Monat, Sep. 2014 - Sep. 2016

    Network Security Specialist

    System Group (Enterprise Software Provider)

    • Conducted 50+ network/web app assessments using Kali and Acunetix, mitigating critical vulnerabilities in banking/telecom sectors. • Reduced SLA breaches by 25% through optimized log analysis with Wireshark, Splunk, SolarWinds, and malware forensics. • Developed and maintained SOPs for IAM systems, improving access control compliance by 25%.

  • 1 Jahr und 3 Monate, Juli 2013 - Sep. 2014

    Advanced Metering Infrastructure Risk Management Leadership

    Monenco Iran (Consulting Engineer)

    -Global AMI Risk: Led enterprise risk for 500K+ smart meters, ensuring ISO/NIST/GDPR compliance. Cut vulnerabilities 25% via AI monitoring (0 incidents/24mo). -BCM: Deployed frameworks, slashing downtime 30% (99.9% uptime) & RTO 45%. -Critical Sector Mitigation: Remediated risks (healthcare/energy), reducing exposure 20%.

  • 5 Jahre und 6 Monate, Apr. 2009 - Sep. 2014

    • Web Application Firewall Evaluator

    Telecomm. Research Center (ITRC) (Leading telecom. research institute)

    • Conducted evaluations of a commercial ML-based Web Application Firewall (WAF) using ASVS standards. • Executed penetration testing on web applications following OWASP Top 10 guidelines. • Generated diverse network traffic for WAF training and cross-validation at ITRC

Ausbildung von Hasty Atashzar

  • 1 Jahr und 7 Monate, Sep. 2008 - März 2010

    ICT, Secure Telecommunication Engineering

    Iran University of Science and Technology

  • 4 Jahre und 5 Monate, Sep. 2000 - Jan. 2005

    Electrical Engineering

    University of Tabriz

  • 10 Monate, Sep. 1999 - Juni 2000

    Mathematics

    National Organization for Development of Exceptional Talents

  • 2 Jahre und 10 Monate, Sep. 1996 - Juni 1999

    Mathematics

    National Organization for Development of Exceptional Talents

Sprachen

  • Englisch

    Fließend

  • Deutsch

    Grundlagen

  • Farsi

    Muttersprache

XING – Das Jobs-Netzwerk

  • Über eine Million Jobs

    Entdecke mit XING genau den Job, der wirklich zu Dir passt.

  • Persönliche Job-Angebote

    Lass Dich finden von Arbeitgebern und über 20.000 Recruiter·innen.

  • 22 Mio. Mitglieder

    Knüpf neue Kontakte und erhalte Impulse für ein besseres Job-Leben.

  • Kostenlos profitieren

    Schon als Basis-Mitglied kannst Du Deine Job-Suche deutlich optimieren.

21 Mio. XING Mitglieder, von A bis Z