// SENIOR INFORMATION SECURITY ENGINEER

Petar Yankov

17+ years on the front lines of security — leading incident response for global enterprises and critical financial infrastructure, hunting threats before they become breaches, and breaking applications so attackers can't.

17+years in security
1000sof incidents led & resolved
SANS · CHFIcertified IR & forensics
Globalenterprise & finance clients

# Expertise

🛡️

Incident Response & Forensics

Leading high-priority incidents end to end — from APTs and zero-days to supply chain attacks and VIP impersonation. Memory and disk forensics, malware analysis, and GDPR-compliant eDiscovery with chain of custody.

  • DFIR
  • Malware analysis
  • Memory forensics
  • eDiscovery
📡

Threat Hunting & SOC

Intel-driven threat hunts, detection tuning and security operations with CrowdStrike Falcon, Splunk, Microsoft Defender and next-gen SIEM. OSINT collection of IOCs and TTPs that turns reports into findings.

  • CrowdStrike
  • Splunk
  • SIEM / EDR
  • Threat intel
⚔️

Penetration Testing

Web, API and mobile application testing against OWASP Top 10 — manual and automated, from Burp Suite and Nmap to Frida and Objection. Findings delivered as clear reports with an executive summary and fix plan.

  • OWASP Top 10
  • Web & API
  • Mobile (Frida)
  • Burp Suite
☁️

Security Engineering & Cloud

Managing and integrating the defensive stack — EDR, DLP, SIEM and mail protection — across Azure and AWS environments. Security automation, tooling development in Python and PowerShell, and vendor collaboration.

  • Azure & AWS
  • Automation
  • Python
  • DLP / EDR

# Experience

2021 — present

Senior Information Security Engineer · PROS

Security operations and threat hunting for corporate and customer environments. Leading security incidents and internal penetration tests, running intel-based threat hunts, and managing the EDR / SIEM / DLP stack across Azure and AWS.

2022 — 2026

Senior CIRT Consultant · Euroclear

Front-line defense of one of Europe's most critical financial infrastructures. Led responses to supply chain attacks and sophisticated malware, supported TIBER-led red team exercises, and conducted GDPR-compliant eDiscovery investigations using CrowdStrike and Splunk.

2016 — 2021

Penetration Testing Consultant · independent contracts

Led and delivered penetration tests of web, SOAP/REST and mobile applications following OWASP Top 10 — automated scanning plus deep manual testing, summarized in actionable reports.

2018 — 2021

Security IR Expert & Forensic Examiner · DXC Technology

Incident response and forensic investigation for global enterprise clients, continuing the HPE global CIRT mission after the spin-off.

2008 — 2017

IR & Forensics Specialist · Hewlett Packard / HPE

Global CIRT: led investigations of hacking, phishing, zero-day and APT incidents; reverse-engineered malware (static and dynamic), performed memory forensics for rootkit detection, and built the team's malware lab tooling in Python and Bash.

# Certifications & training

  • SANS SEC504 — Hacker Tools, Techniques, Exploits and Incident Handling (course + certification)
  • EC-Council CHFI — Computer Hacking Forensic Investigator (course + certification)
  • FireEye — Junior Systems Engineer certification; Platform Deployment & Fundamentals
  • Trend Micro TCSP — OfficeScan & Control Manager certifications

Working knowledge aligned with CEH and CISSP bodies of knowledge.

# About

I'm a security engineer based in Sofia, Bulgaria, working with global enterprises and European financial institutions. I started in HP's global incident response team in 2008 and have spent my career where security gets real: live incidents, forensic investigations, malware labs, threat hunts and penetration tests.

That mix matters. Because I've reverse-engineered the malware and run the intrusions myself, my detection rules, hunts and recommendations are grounded in how attacks actually unfold — and my reports are written so both engineers and leadership know exactly what to do next. Lately I also build security automation and experiment with locally-hosted LLMs to speed up analysis workflows.

# Contact

Dealing with an incident, planning a pentest, or building out detection? Drop me a line — I usually reply within one business day.

> peteyankov@gmail.com

> linkedin.com/in/petar-yankov