Incident Response & Forensics
Leading high-priority incidents end to end — from APTs and zero-days to supply chain attacks and VIP impersonation. Memory and disk forensics, malware analysis, and GDPR-compliant eDiscovery with chain of custody.
// SENIOR INFORMATION SECURITY ENGINEER
17+ years on the front lines of security — leading incident response for global enterprises and critical financial infrastructure, hunting threats before they become breaches, and breaking applications so attackers can't.
Leading high-priority incidents end to end — from APTs and zero-days to supply chain attacks and VIP impersonation. Memory and disk forensics, malware analysis, and GDPR-compliant eDiscovery with chain of custody.
Intel-driven threat hunts, detection tuning and security operations with CrowdStrike Falcon, Splunk, Microsoft Defender and next-gen SIEM. OSINT collection of IOCs and TTPs that turns reports into findings.
Web, API and mobile application testing against OWASP Top 10 — manual and automated, from Burp Suite and Nmap to Frida and Objection. Findings delivered as clear reports with an executive summary and fix plan.
Managing and integrating the defensive stack — EDR, DLP, SIEM and mail protection — across Azure and AWS environments. Security automation, tooling development in Python and PowerShell, and vendor collaboration.
Security operations and threat hunting for corporate and customer environments. Leading security incidents and internal penetration tests, running intel-based threat hunts, and managing the EDR / SIEM / DLP stack across Azure and AWS.
Front-line defense of one of Europe's most critical financial infrastructures. Led responses to supply chain attacks and sophisticated malware, supported TIBER-led red team exercises, and conducted GDPR-compliant eDiscovery investigations using CrowdStrike and Splunk.
Led and delivered penetration tests of web, SOAP/REST and mobile applications following OWASP Top 10 — automated scanning plus deep manual testing, summarized in actionable reports.
Incident response and forensic investigation for global enterprise clients, continuing the HPE global CIRT mission after the spin-off.
Global CIRT: led investigations of hacking, phishing, zero-day and APT incidents; reverse-engineered malware (static and dynamic), performed memory forensics for rootkit detection, and built the team's malware lab tooling in Python and Bash.
Working knowledge aligned with CEH and CISSP bodies of knowledge.
I'm a security engineer based in Sofia, Bulgaria, working with global enterprises and European financial institutions. I started in HP's global incident response team in 2008 and have spent my career where security gets real: live incidents, forensic investigations, malware labs, threat hunts and penetration tests.
That mix matters. Because I've reverse-engineered the malware and run the intrusions myself, my detection rules, hunts and recommendations are grounded in how attacks actually unfold — and my reports are written so both engineers and leadership know exactly what to do next. Lately I also build security automation and experiment with locally-hosted LLMs to speed up analysis workflows.
Dealing with an incident, planning a pentest, or building out detection? Drop me a line — I usually reply within one business day.