Pavel K.

Pavel K.

Chief Information and Security Officer @ Capital.com

Country

United Kingdom

City

London

Industry

Computer & Network Security

Skill

Security Audits, Security, Information Security, Network Security, DLP, ESM, SIEM, Windows Server, Linux Server, Powershell, Bash, Firewalls, Active Directory, PCI DSS, Vulnerability Scanning, System Administration, Antivirus, IPS/IDS, Incident Investigation, Incident Management

Experience

Capital.com

Chief Information and Security Officer

Capital.com

LinkedIn
2025-1 - Present · 1 yr 9 mos

Greater London, England, United Kingdom

Capital.com

Head Of Security

Capital.com

LinkedIn
2019-3 - 2024-12 · 5 yrs 10 mos

Greater London, England, United Kingdom

Developed and executed the company’s global information security strategy to protect trading platforms, client data, and internal systems in compliance with FCA, CySEC, ASIC, DORA and other regulatory frameworks. Ensured security governance across all business units, aligning security programs with financial regulations and cybersecurity standards (ISO 27001, NIST, GDPR). Led the implementation of enterprise-wide security controls, including identity and access management (IAM), endpoint protection, and secure communication protocols. Oversaw the design and continuous improvement of security architecture for both client-facing systems (web/mobile trading platforms) and internal environments (CRM, back-office, payment systems). Established and maintained a comprehensive risk management program, including regular risk assessments, threat modeling, and business impact analyses. Directed incident response efforts, including detection, triage, containment, investigation, and reporting, ensuring transparency with regulators when required. Worked closely with compliance and legal teams to support audits, regulatory inquiries, and ensure ongoing adherence to jurisdictional cybersecurity and privacy laws. Implemented data protection strategies, including DLP, encryption, secure API design, and segregation of sensitive client information. Conducted vendor risk assessments and enforced third-party security requirements for technology partners, liquidity providers, and hosting providers. Promoted a strong security culture by delivering ongoing employee awareness programs, phishing simulations, and secure development training for engineers. Coordinated with DevOps, IT, and product teams to integrate security into CI/CD pipelines and development processes. Supervised internal and external penetration testing, vulnerability assessments, and red team exercises to evaluate the resilience of systems and processes.

Currency.com

Head Of Security

Currency.com

LinkedIn
2018-12 - 2025-3 · 6 yrs 4 mos

Greater London, England, United Kingdom

Led the design and implementation of the entire security architecture for the crypto exchange from the ground up, including infrastructure, applications, wallets (hot and cold), and internal systems. Developed the overall security strategy aligned with business objectives, regulatory requirements, and industry best practices (ISO 27001, NIST, etc.). Built and managed a security team responsible for DevSecOps, incident response, compliance, and internal audits. Designed and enforced secure development lifecycle (SSDLC) practices, including threat modeling, secure code review, CI/CD security integration, and automated vulnerability scanning. Implemented advanced monitoring, logging, and SIEM solutions to ensure real-time visibility into threats and abnormal behavior across the platform. Oversaw the deployment and hardening of key infrastructure components, including Kubernetes clusters, API gateways, and cloud-native services. Established secure key management and wallet infrastructure, including multi-signature wallets, hardware security modules (HSMs), and operational procedures for withdrawals. Coordinated penetration testing, red teaming, and third-party security assessments to continuously evaluate and strengthen the platform’s resilience. Led incident response and crisis management processes, including postmortems, root cause analysis, and long-term remediation planning. Defined and implemented security policies, access control models, and compliance procedures to meet legal and regulatory requirements (AML, GDPR, GFSC/DLT etc.). Conducted internal training and awareness programs to foster a strong security culture across engineering, operations, and customer-facing teams.

IAC

Information Security Architect

IAC

LinkedIn
2017-6 - 2018-12 · 1 yr 7 mos

Belarus

Designed and planned system architectures for SIEM and log management solutions in both on-premises and cloud environments (AWS, GCP). Engineered and maintained a large-scale Elastic Stack (ELK) infrastructure, ensuring high availability, scalability, and performance. Managed daily operations of ELK stack, including deployment and configuration of forwarders, log collectors, and servers. Performed system performance monitoring, troubleshooting, version upgrades, and patch management to ensure system stability and security. Led the initial deployment and configuration of new SIEM/logging systems to support enterprise-wide security monitoring. Automated infrastructure and configuration management processes using Ansible and Terraform to improve efficiency and consistency. Collaborated with SOC and CSIRT teams to troubleshoot complex issues and enhance incident detection and response capabilities. Developed custom filters and parsing logic to extract meaningful events from raw log data and support actionable insights. Wrote and maintained custom scripts and utilities to support log ingestion, parsing, and alert generation workflows. Created SIEM content, including correlation rules and data models, to support effective threat detection and security operations. Built and maintained Kibana dashboards to visualize key metrics and provide operational insights into ingested log data. Diagnosed and resolved infrastructure-level and system-related issues to maintain service continuity and system integrity.

Wargaming

Information Security Engineer

Wargaming

LinkedIn
2015-10 - 2017-6 · 1 yr 9 mos

Researched, designed, and introduced next-generation security solutions to enhance the company’s cybersecurity posture and adapt to evolving threat landscapes. Deployed technical tools and platforms to automate security operations and assurance processes, improving efficiency and response times. Developed and implemented a comprehensive incident management framework, including detection, triage, escalation, and post-incident review. Took part in the design and development of a Security Operations Center (SOC), including toolset selection, process definition, and incident workflows. Responded to security incidents, conducted in-depth investigations, and coordinated mitigation and remediation efforts. Created and maintained custom detection rules, use cases, and correlation logic within the SIEM system to improve threat detection capabilities. Continuously monitored and analyzed SIEM logs and event data for signs of anomalies or malicious activity. Authored and updated information security policies, procedures, and strategic security plans aligned with business needs and regulatory requirements. Oversaw antivirus protection strategies and ensured effective deployment, updates, and compliance across endpoints. Led the implementation of Next-Generation Firewalls (NGFW), including rule tuning, traffic segmentation, and threat prevention capabilities.

Приорбанк

IT Security Officer

Приорбанк

LinkedIn
2012-11 - 2015-10 · 3 yrs

Беларусь

Conducted regular vulnerability scanning and analysis to identify security gaps and recommend mitigation strategies. Deployed and configured technical solutions to monitor and control privileged access across critical systems. Implemented two-factor authentication (2FA) mechanisms to strengthen user identity verification and access protection. Rolled out a Data Loss Prevention (DLP) system to safeguard confidential information and ensure compliance with data protection policies. Participated in security incident response processes, including investigation, root cause analysis, and coordination of remediation actions. Developed and maintained detection rules and use cases for the Security Information and Event Management (SIEM) system to enhance threat visibility. Assisted in planning and execution of penetration tests, supporting vulnerability identification and remediation. Reviewed security architecture and technical designs for newly implemented systems and solutions to ensure secure deployment. Contributed to the development and refinement of information security policies, procedures, and strategic plans. Performed regular monitoring and internal audits to verify compliance with corporate security standards and regulatory requirements. Supported cybersecurity awareness initiatives, including staff training and promotion of secure practices across the organization.

JSC Belinvestbank

Acquiring specialist

JSC Belinvestbank

2010-11 - 2012-11 · 2 yrs 1 mo

Led the installation and configuration of Cisco routers, switches, and firewalls across multi-site enterprise environments, ensuring seamless integration with existing infrastructure. Proactively monitored network performance and resolved L2/L3 connectivity issues, significantly reducing downtime and improving service reliability. Conducted in-depth root cause analysis of recurring network incidents, implemented preventive measures, and improved incident resolution time by 30%. Developed and maintained detailed network topology diagrams, IP address management plans, and change documentation in line with ITIL best practices, enhancing team collaboration and audit readiness. Collaborated with cross-functional teams on infrastructure upgrades, security policy enforcement, and capacity planning to support organizational growth and security compliance.

Education

Belarusian State University of Informatics and Radioelectronics

Belarusian State University of Informatics and Radioelectronics

LinkedIn

Technical security

2006 - 2011 · 5 yrs

Pavel K.'s Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.