Leading Information Security Engineer Azerbaijan Railways
Improved security-stack effectiveness by approximately 60% through MITRE ATT&CK-based exposure management, mapping detection and prevention coverage against adversary techniques and closing gaps and misconfigurations. Leads incident response for critical infrastructure using self-authored incident-response playbooks and SOPs across on-premises, Azure, and AWS environments.
Shapes identity security architecture by leading IAM rollout with SSO and RBAC across five platforms, onboarding 80% of users, and administering PAM for more than 150 privileged accounts. Assesses controls against NIST CSF and ISO 27001, runs access reviews, maintains audit evidence, and automates control checks and reporting with Python and PowerShell.
Embeds security into the SDLC across more than five development projects through STRIDE threat modelling and SAST/DAST in GitHub Actions pipelines. Hardens Linux, Kubernetes, and Docker workloads, and maintains 99.9% availability of customer-facing websites through WAF and DDoS protection configuration and automation.