• File

Ілля

Information security analyst

Age:
20 years
City of residence:
Kyiv
Ready to work:
Remote

Contact information

The job seeker has entered a phone number .

Name, contacts and photo are only available to registered employers. To access the candidates' personal information, log in as an employer or sign up.

Uploaded file

Quick view version

This resume is posted as a file. The quick view option may be worse than the original resume.

Illia Merkulov
Information Security | Governance, Risk & Compliance

Kyiv, Ukraine • Open to Remote • [open contact info](look above in the "contact info" section)[open contact info](look above in the "contact info" section)

SUMMARY
IT professional with 2 years in system administration and Active Directory. Transitioning into GRC with hands-on knowledge of ISO/IEC 27001,
risk assessment, access reviews, and security controls. Technical background enables effective communication between IT and compliance
functions.

GRC KNOWLEDGE & PRACTICE
Risk Management Incident Management
▪ ISO/IEC 27001 risk assessments using 5×5 Likelihood × ▪ Practiced incident analysis using NIST SP 800-61
Impact methodology scenarios
▪ Developed Risk Registers and Risk Treatment Plans ▪ Developed Security Awareness recommendations
mapped to Annex A controls
▪ Conducted control effectiveness assessments Framework Knowledge
▪ ISO/IEC 27001:2022
Access Management ▪ NIST CSF 2.0
▪ Conducted User Access Review scenarios (Approve / ▪ SOC 2 (Foundational Knowledge)
Revoke / Modify) ▪ GDPR (Fundamentals)
▪ Implemented controlled temporary administrative
access with password rotation after task completion
▪ Applied RBAC and Principle of Least Privilege in daily
operations

EXPERIENCE
IT Infrastructure & Security Specialist | 2024 – Present | Kyiv, Ukraine

▪ End-to-end onboarding & offboarding: AD account ▪ Supported Windows Server 2019: Active Directory,
lifecycle, VPN provisioning/revocation, access cleanup DNS, DHCP, File Server
▪ Managed user access according to the Principle of ▪ Administered MikroTik: VPN, NAT rules, configuration
Least Privilege and departmental responsibilities backups
▪ Secure workstation reimaging before reassignment; ▪ Investigated infrastructure issues and identified root
maintained IT asset inventory causes

SKILLS

Risk & Compliance Frameworks IAM Infrastructure
▪ Risk Assessment ▪ ISO/IEC 27001 ▪ Active Directory ▪ Windows Server
▪ Risk Register ▪ NIST CSF ▪ RBAC ▪ MikroTik
▪ Risk Treatment ▪ SOC 2 ▪ Least Privilege ▪ VPN
▪ Access Reviews ▪ GDPR ▪ GPO ▪ RDP
▪ Incident Analysis ▪ TCP/IP
▪ DNS
▪ DHCP

Languages:
Ukrainian — Native
English — B1 (Intermediate)

Similar candidates

All similar candidates

Candidates at categories

Candidates by city


Compare your requirements and salary with other companies' jobs: