Cyber security professional with 13 years of experience in various technical, methodological, and management roles — with a particular focus on building teams, operations, and services from the ground up, while staying business-driven and customer-oriented.
Specializing in the design of secure architectures and end-to-end security solutions, from HLD/LLD and policy to deployment and operational monitoring, alongside in-depth cyber security and privacy risk assessments for organizations, systems, and processes.
I'm a senior cyber security expert with a rare combination of deep technical hands-on experience and architectural, legal, compliance regulation and business fluency. My work spans InfoSec management, cyber security architecture, security research, SOC/IR operations, cloud security, and Web Application and API Protection — with a consistent throughline: building things from scratch that provide value.
Previously at PwC NEXT (PwC Israel), I designed and delivered security architecture and consulting services, guiding organizations through complex compliance landscapes and building security programs that are both solid and practical.
I hold a B.Sc. in Computer Science and an M.A. in Law (Technology), as well as CISO and DPO certifications, giving me an edge at the intersection of technical risk and legal and regulatory exposure.
From a targeted architecture review to a full security program — I bring a practitioner's precision and a consultant's structure.
Fractional security leadership — ongoing security program ownership, regulatory liaison, policy writing, vendor evaluation, team building, and board-level risk reporting.
Structured risk assessments for organizations, systems, and processes — building a threat profile, analyzing likelihood and impact, and producing a residual risk report with actionable treatment recommendations.
Assessing where an organization stands against a target framework, identifying gaps, and producing a prioritized remediation roadmap.
End-to-end guidance through the certification process — scoping, policy writing, control implementation, evidence collection, and working alongside auditors to achieve certification.
HLD/LLD design of secure systems, cloud environments, and hybrid infrastructures — from policy and procedures to deployment and operational monitoring.
AWS security architecture, configuration review, incident response, and maturity assessment.
Web and API security architecture design and testing — covering WAF design, tuning and bypass testing, web security architecture review, and OWASP ASVS assessments.
Building AppSec programs from scratch — defining policy, selecting tooling, and embedding security into the SDLC. Also assessing existing programs against OWASP SAMM to identify gaps and prioritize improvements.
Regulatory advisory covering GDPR and the Israeli Protection of Privacy Regulations. DPO advisory, privacy impact assessments, and data protection program design.
SOC design, buildout, and maturity assessment — covering IR readiness, AWS incident response, SIEM engineering, and threat hunting.
Designed and developed new security architecture and consulting services within a new PwC technology company, while building methodology, optimizing for efficiency and customer value, and driving go-to-market and sales processes.
Established Salt Security's API Security SOC from scratch, overseeing the Salt API Security SaaS platform — monitoring and investigating API attacks, tuning detection mechanisms, and leading API incident response and threat hunting operations.
Led Red Button to become the 3rd AWS DDoS Test Partner globally — a rare designation held by only a handful of companies worldwide at the time.
Co-authored the LED-it-GO academic paper on covert data exfiltration from air-gapped computers via hard drive LEDs, published by the BGU Cyber Security Research Center.
Founded and built a DFIR lab within the Directorate of Military Intelligence from the ground up, leading digital forensics and incident response operations.
Design and development of new architecture and consulting services within a new PwC technology company, while developing methodology, optimizing for better efficiency and customer value, and performing marketing and sales processes.
Establishment and management of Salt Security's API Security SOC.
As the 2nd person in this role, I took a major part developing it.
I led Red Button to become an AWS DDoS Test Partner — the third one in the world.