• Файл

Станiслав

Infrastructure Architect, DevOps, DevSecOps specialist

Вік:
40 років
Місто проживання:
Харків
Готовий працювати:
Дистанційно

Контактна інформація

Шукач вказав: ТелефонМесенджер

Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.

Завантажений файл

Версія для швидкого перегляду

Це резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.

Stanislav Kurmanov
Security Architect | Infrastructure Security Lead
[відкрити контакти](див. вище в блоці «контактна інформація») [відкрити контакти](див. вище в блоці «контактна інформація») Ukraine

26/07/1986 Cordoba, Argentina (Open to Remote)

[відкрити контакти](див. вище в блоці «контактна інформація») github.com/zenthracore

zenthracore.github.io mastodon.social/@zenthracore

Summary

Infrastructure Security Architect with 20+ years of hands-on experience designing and hardening production
environments. Sole security and infrastructure architect for a production AWS SaaS platform — designed a Zero Trust
Docker Swarm architecture with mTLS enforced across all services, survived 4 rounds of independent penetration
testing with zero infrastructure-layer critical findings, and implemented post-quantum cryptographic transport using
ML-KEM and Falcon.
Comfortable bridging infrastructure, security, and development teams — translating architectural decisions into clear
technical requirements for engineering teams to implement.
Core Strengths
Security Architecture & Zero Trust Design
•

Infrastructure Hardening (Linux, Gentoo Hardened, Container Security)
•

DevSecOps & Secure CI/CD Pipelines
•

Threat Modeling & Security Reviews
•

Vulnerability Management (Trivy integration)
•

TLS 1.3, mTLS, PKI, Certificate Lifecycle Management
•

Docker, Docker Swarm, Kubernetes Concepts
•

AWS Infrastructure & Cloud Security
•

Incident Investigation & Security Operations
•

Post-Quantum Cryptography (ML-KEM, Falcon, OQS Provider)
•

Data Protection & Memory Security Controls
•

Endpoint Security Hardening
•

Advanced Data-at-Rest Encryption (LUKS2/LVM)
•

Professional Experience
08/2018 – Present iDeus, Infrastructure Architect / Infrastructure Security Lead
Kharkiv Served as the sole security and infrastructure architect for a production enterprise SaaS
platform deployed on AWS. Designed the full security architecture from the ground up and
directed implementation through the development team.
Architecture & Design
Designed and owned a Zero Trust Docker Swarm architecture with 8+ hardened
microservices, segmented overlay networks, and mTLS enforced on every service
communication path — no service communicates without mutual certificate
authentication.
Architected AWS VPC with custom routing, NLB in TCP passthrough mode preserving end-
to-end TLS, and Security Group policies — maintaining full TLS trust chain without
termination at the load balancer.
Migrated backend to Laravel Octane + FrankenPHP, resulting in measurable throughput
improvements validated via Apache Benchmark testing.

Stanislav Kurmanov [відкрити контакти](див. вище в блоці «контактна інформація»)

Security Validation
Independent pentesters with server access were unable to escape Docker containers to the
host system — validating kernel-level and container hardening effectiveness.
Implemented Gentoo Hardened as the host OS with custom kernel compilation, LSM
configurations, and compiler-level security flags.
DevSecOps
Built CI/CD pipeline with automated Trivy vulnerability scanning and hard build gates
blocking deployment of images with critical CVEs.
Authored 120-page internal security architecture documentation covering all platform
components, threat boundaries, and security controls.

02/2010 – 07/2018 kelb.bike, System Engineer / Webmaster
Kharkiv • Infrastructure Design: Designed, deployed, and maintained the company’s core server
infrastructure, ensuring high availability and secure operations for integrated business
systems.
• Linux Server Administration: Managed Linux-based web environments and backend
systems, focusing on performance optimization, access control, and network security.
• E-commerce Platform Architecture: Engineered and customized the backend
architecture for the company's online store.
• Network Management: Administered the corporate network and internal technical
systems, establishing secure baseline configurations and access policies.

05/2008 – 02/2009 KEA "Kabelmontazh"
Kharkiv Administered the corporate local network and managed Linux-based office servers to
•

ensure secure and continuous internal connectivity.
Deployed and maintained the company's web platforms, handling server-side
•

configuration, security baselines, and performance monitoring.

Education
09/2022 – 06/2026 Kharkiv National Automobile and Highway University (KNAHU),
Kharkiv https://www.khadi.kharkov.ua/en/
Bachelor's Degree in Management
•

09/2008 – 03/2011 Kharkiv University of Economics and Law (KhUEL), https://khu.kharkiv.ua/
Kharkiv Law (Completed 2.5 years of study)
•

Languages

English Ukrainian Russian
Reading and technical Native Native
comprehension strong; spoken
communication developing

Spanish
Spoken communication developing

Stanislav Kurmanov [відкрити контакти](див. вище в блоці «контактна інформація»)

Certificates

CISSP Specialization (InfoSec OWASP Top 10 Specialization DevOps on AWS: Code, Build, Test
Institute / Coursera, 2025) — Advanced training focused on & Operate
completed training across all identifying, mitigating, and Technical training focused on cloud
eight ISC2 CISSP domains. preventing critical application infrastructure automation, CI/CD
Complete 8-domain comprehensive security risks (Broken Access pipeline deployment, monitoring,
program covering Security & Risk Control, Cryptographic Failures, and operating secure, scalable
Management, Asset Security, Injection, Insecure Design). workloads on AWS.
Architecture, Network Security, IAM,
Assessment, Operations, and
Software Development Security.

AWS Cloud Technical Essentials

Comprehensive core technical
course covering AWS foundational
services (compute, networking,
storage, database) and security
baselines.

Projects

Post-Quantum Segmented Transport Architecture
Designed and implemented production-grade segmented transport architecture using ML-KEM and Falcon.
•

Built custom OpenSSL + OQS Provider environments.
•

Created custom NGINX and Stunnel integrations supporting PQC transport.
•

Defined cryptographic trust boundaries and downgrade-resistance controls.
•

Published technical architecture documentation and validation materials.
•

Zero Trust Docker Swarm Platform
Designed end-to-end encrypted service communication using mTLS.
•

Implemented encrypted overlay networking and strict service isolation.
•

Integrated Docker Secrets and hardened deployment standards.
•

Applied defense-in-depth strategy across infrastructure layers.
•

Publications
2026 Hardened Swarm & Gentoo: Security Architecture , Stanislav Kurmanov
A practical guide to deploying high-security infrastructure. Strict network segmentations,
customized Gentoo Hardened Linux compilation/LSM configurations, and mTLS
enforcement across all communication paths.

2026 When the Linux System Started Lying , Stanislav Kurmanov
Investigation of a suspected kernel-level compromise in a BrainyCP production
environment. Outbound DNS flood, falsified command output, empty lsmod, and the only
way out — swapping the kernel on a live compromised system.

2026 Post-Quantum Segmented Transport Architecture , Stanislav Kurmanov
A formal security whitepaper detailing ZenthraCore's hybrid public edge + strict internal
post-quantum transport enclave using ML-KEM and ML-DSA cryptographic standards.

Stanislav Kurmanov [відкрити контакти](див. вище в блоці «контактна інформація»)

2026 Live Post-Quantum Verification Report , Stanislav Kurmanov
Independent cryptographic verification of ZenthraCore's production PQ transport enclave.
Real terminal outputs from a live system demonstrating ML-KEM-768 key exchange, Falcon-
512 signatures, and strict classical rejection.

2025 Why I Hardened My Linux Laptop Like a Vault (and How You Can Too) , dev.to
DEV Community (dev.to/zenthracore ) | Jul 2025
A comprehensive guide detailing OS-level and hardware-level endpoint hardening
configurations.
Explains strict data-at-rest isolation (LUKS2 over LVM), anti-forensics controls (Nuke key
implementation with DoD-pattern disk wiping under duress), RAM sanitization scripts
against Cold Boot attacks, forced hibernation workflows, and OS-level Tor routing controls.

Stanislav Kurmanov [відкрити контакти](див. вище в блоці «контактна інформація»)

Схожі кандидати

Усі схожі кандидати


Порівняйте свої вимоги та зарплату з вакансіями інших підприємств: