Every named engagement
133 named projects and engagements across 25+ years. Filter by domain or jump to a role from the career timeline. References and case-study detail available for qualified mandates.
PIR2-IT — Chief Innovation Officer / CTO
Worldwide / Remote · Full-timepir2-it.com ↗Designed AI- and Zero-Trust-enabled platforms for sovereign / institutional clients and large-scale banking transformation for top-tier banks. Senior technical authority on cybersecurity platforms with measurable MTTR reduction.
Digital Public Infrastructure Trust Platform — Single Point of Trust
DLT-enabled, AI-supported, Zero Trust eGovernment platform designed for national-scale digital public infrastructure. Treats trust as a system property rather than a policy statement — centralising identity assurance, policy enforcement, evidence generation and service integrity. Architecture prototype (validated concept) applied to a European government transformation programme.
Key capabilities
- DLT evidence layer — immutable audit trails for transactions, access decisions and service states; verifiable receipts; real-time audit readiness
- Zero Trust as operating model — continuous authorisation, least privilege, policy-as-code enforcement, tamper-evident logging
- AI under governance — guided digital journeys, anomaly detection, case routing and explainable operational analytics; all outputs policy-bounded and reviewable
- Interoperability — legacy systems, APIs, event-driven patterns and cross-institution workflows under controlled compliance rules
- Cross-institution accountability at national scale — traceable decisions, structured evidence, aligned service integrity
Frameworks: Digital Public Infrastructure · DLT evidence architecture · Zero Trust (NIST SP 800-207) · AI governance / explainability · EU eIDAS interoperability
4× security posture · 4× elimination of operational dead time · 72% less duplication · 12% fraud reduction · 45% less information loss
DLT-enabled, AI-supported, Zero Trust eGovernment platform designed for national-scale digital public infrastructure. Treats trust as a system property rather than a policy statement — centralising identity assurance, policy enforcement, evidence generation and service integrity.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Zero Trust adoption over existing legacy infrastructure without service disruption
- AI model governance and explainability requirements under regulatory or institutional oversight
Governance Execution Framework — GARI Accountability Architecture
Execution-ready governance framework with AI-assisted oversight for public institutions and multilateral programmes. Transforms governance from recommendation-based activity into structured accountability architecture. Delivered across 35 institutional engagements; flagship reference programme: ~250–300 personnel, USD 45M+ annual budget.
Key capabilities
- Single Point of Institutional Clarity — aligns mandate, execution and oversight without centralising operational authority
- Auditability by default — decisions, processes and resource flows traceable through structured accountability chains and embedded reporting logic
- AI-assisted analysis — dependency mapping, anomaly and inefficiency detection, accountability-chain analysis, workflow optimisation; all outputs reviewable and institutionally controlled
- RACI-aligned governance layers, evidence-based execution monitoring and institutional learning loops
- Cross-institution integration for ministries, agencies and multilateral programmes
Frameworks: Governance execution architecture · Algorithmic audit principles · RACI · AI-assisted analytical oversight · Evidence-based execution monitoring
41 contracts renegotiated · 21 terminated · 29 irregularities identified · 6 non-operational positions · −36% OPEX · USD 1.33M costs avoided
Execution-ready governance framework with AI-assisted oversight for public institutions and multilateral programmes. Transforms governance from recommendation-based activity into structured accountability architecture.
- AI model governance and explainability requirements under regulatory or institutional oversight
- Hardware-software co-design with hard real-time constraints and limited compute resources
- Navigating institutional autonomy and political sensitivities in a multilateral governance context
Sensor Fusion & Autonomous Mobility Platform — Mission-grade AI
Prototype AI platform combining high-performance computer vision, radar + camera sensor fusion and audit-ready reporting for regulated mission environments. Master–agent orchestration model with modular architecture. Currently in iterative hardening and integration validation.
Key capabilities
- Radar + high-performance camera fusion — improved confidence scoring, reduced false positives, anomaly detection
- AI perception and event detection optimised for edge deployment in demanding field conditions
- Multi-sensor detection picture: radar, RF direction finding, EO/IR cameras, acoustic — fused into single operating picture
- AI-assisted classification with confidence scoring, traceable evidence (time, location, sensor provenance, decision logs)
- Geofencing, policy-defined alerting and escalation workflows with human governance
- Automatic evidence trails and structured logs for oversight, accountability and post-event analysis
- GNSS-challenged resilience — redundancy and graceful degradation
- Zero Trust security across sensors, edge compute and services; tamper-evident logging
- V&V discipline: requirements → design → implementation → test evidence traceability; regression controls; configuration baselines
Boundary: detection, awareness, secure integration, governance, V&V. No weaponization or interception.
Prototype platform · Zero Trust · Audit-ready · Edge AI
Prototype AI platform combining high-performance computer vision, radar + camera sensor fusion and audit-ready reporting for regulated mission environments. Master–agent orchestration model with modular architecture.
- Implementing Zero Trust architecture at institutional scale with multi-stakeholder governance
- AI model governance and explainability requirements under regulatory or institutional oversight
- Edge AI deployment under constrained compute and power budgets in field environments
Governed Autonomous Systems Architecture — AI-Enabled Modular UAS
Modular AI-enabled UAS demonstrator built around a mothership coordinating multiple deployable sub-vehicles under governed operating logic. Treats autonomy as an engineering, governance and assurance problem — not novelty. Architecture, AI systems engineering, cybersecurity, integration and V&V delivered as a validated demonstrator for regulated operational environments.
Key capabilities
- Mothership + sub-vehicle distributed operations — modular subsystem boundaries for reconfiguration, maintainability and lifecycle control
- Edge AI onboard: real-time perception, situational awareness, sensor fusion and tracking to reduce false positives
- Autonomy support for routing, task allocation and contingency handling within non-lethal, governed scope
- Multi-vehicle coordination; anomaly detection and interference awareness
- Predictive health monitoring for reliability and maintainability across test cycles
- AI outputs logged, traceable and explainable — designed for oversight and post-event review
- Threat-informed design, Zero Trust principles, security-by-design
- Traceability from requirements to architecture, implementation and test evidence; configuration baselines; decision logs
- Resilience in GNSS-challenged environments through graceful degradation
- Interoperability considerations aligned with coalition and multi-stakeholder environments
Boundary: architecture, AI systems engineering, cybersecurity, integration, governance, assurance. No weaponization or interception.
Advanced demonstrator · Modular · Distributed · Explainable AI · Zero Trust
Modular AI-enabled UAS demonstrator built around a mothership coordinating multiple deployable sub-vehicles under governed operating logic. Treats autonomy as an engineering, governance and assurance problem — not novelty.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Implementing Zero Trust architecture at institutional scale with multi-stakeholder governance
- AI model governance and explainability requirements under regulatory or institutional oversight
23 international and Romanian banks — transformation & cybersecurity
Large-scale banking transformation and cybersecurity programmes — core-banking migrations, data-centre consolidation, cybersecurity modernisation. Named clients: UNFCU, EIB, Société Générale, HSBC, BNP Paribas, Credit Suisse.
23-bank portfolio
Large-scale banking transformation and cybersecurity programmes — core-banking migrations, data-centre consolidation, cybersecurity modernisation. Named clients: UNFCU, EIB, Société Générale, HSBC, BNP Paribas, Credit Suisse.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Programme coordination across geographically distributed teams and regulatory environments
Enterprise PAM / IAM — satellite + Azure AD + AD FS
Enterprise PAM/IAM solutions integrating satellite networks, Azure AD and on-prem AD FS — improving privileged-access governance and authentication security.
—
Enterprise PAM/IAM solutions integrating satellite networks, Azure AD and on-prem AD FS — improving privileged-access governance and authentication security.
- Identity and access integration across heterogeneous directories (AD, LDAP, satellite, cloud)
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
- Multi-cloud vendor-neutral architecture design to avoid lock-in while maintaining SLA commitments
Palo Alto · CyberArk · CrowdStrike · DLP · SIEM · DDoS
Product Owner & senior technical authority across cybersecurity platforms (Palo Alto, CyberArk, CrowdStrike, DLP, SIEM, vulnerability management, DDoS). Automation and advanced diagnostics.
MTTR reduced by up to 58%
Product Owner & senior technical authority across cybersecurity platforms (Palo Alto, CyberArk, CrowdStrike, DLP, SIEM, vulnerability management, DDoS). Automation and advanced diagnostics.
- Programme coordination across geographically distributed teams and regulatory environments
Romanian Ministry of Energy — AI engine + energy modelling
AI natural-language engine and online energy-system modelling platform supporting EU energy-transition planning.
—
AI natural-language engine and online energy-system modelling platform supporting EU energy-transition planning.
- Coordinating multi-stakeholder delivery under time and resource constraints
eJustice AI — Armenia 2025–2026 (Phase 2 AI Agentic Upgrade)
Phase 2 AI agentic upgrade for the National Police criminal justice platform — direct continuation of the 2014–2015 full-lifecycle eJustice programme. Deliverables: AI case routing and decision-support (NLP-based); EU AI Act governance framework (bias assessment, transparency, auditability, human-in-the-loop safeguards); national trainer certification in responsible AI; supervision and audit of implementation.
EU AI Act compliance framework · ~€60M programme (cumulative Phase 1 + 2)
Phase 2 AI agentic upgrade for the National Police criminal justice platform — direct continuation of the 2014–2015 full-lifecycle eJustice programme. Deliverables: AI case routing and decision-support (NLP-based); EU AI Act governance framework (bias assessment, transparency,...
- Policy and standards harmonisation across multiple sovereign jurisdictions
- AI model governance and explainability requirements under regulatory or institutional oversight
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
eJustice AI — Georgia 2026 (Phase 2 AI Agentic Upgrade)
Phase 2 AI agentic upgrade for the 112 Emergency Services / eJustice platform — direct continuation of the 2014–2015 full-lifecycle programme. Deliverables: AI dispatch optimisation and predictive resource allocation; AI transparency and accountability framework; national trainer certification in AI adoption; supervision and audit of implementation.
UNDP / EU frameworks · ~$50M programme (cumulative Phase 1 + 2)
Phase 2 AI agentic upgrade for the 112 Emergency Services / eJustice platform — direct continuation of the 2014–2015 full-lifecycle programme. Deliverables: AI dispatch optimisation and predictive resource allocation; AI transparency and accountability framework; national trai...
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
AI Governance & Agentic eJustice — 35 States (EU AI Act Aligned)
AI-enabled eJustice and DPI governance across 35 states, fully aligned to the EU AI Act. Scope: NLP case routing and triage; predictive court scheduling; AI-assisted legal document processing; automated cross-border judicial cooperation flows (e-CODEX/ECRIS-compatible); digital evidence chain-of-custody; citizen-facing identity-verified portal; human-in-the-loop safeguards; full audit trails. National governance domains: justice and law enforcement, public administration, healthcare, financial regulation, energy and critical infrastructure, defence. Full ToR lifecycle delivered (diagnostic → vision → architecture → governance → roadmap → delivery → M&E → supervision and audit → continual improvement).
Role: supported clients in producing financing, M&E and supervision documentation required by multilateral institutions — no direct contract with WBG, JBIC, Asian Development Bank or EBRD.
Frameworks: WBG | JBIC | ADB | EBRD | EU | FIDIC
AI-enabled eJustice and DPI governance across 35 states, fully aligned to the EU AI Act. Scope: NLP case routing and triage; predictive court scheduling; AI-assisted legal document processing; automated cross-border judicial cooperation flows (e-CODEX/ECRIS-compatible); digita...
- Policy and standards harmonisation across multiple sovereign jurisdictions
- AI model governance and explainability requirements under regulatory or institutional oversight
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
Digital Public Infrastructure — 35 States
eIDAS-compatible digital identity and trust services; data exchange and interoperability (API/iPaaS/ESB/eventing); e-signature, electronic notary, and national PKI; citizen-facing portals. Phased roadmaps, funding strategies, M&E frameworks, and supervision of implementation for each engagement across 35 states. Professional services delivered throughout the full project lifecycle for the majority of citizens in each country.
Role: supported clients in producing financing, M&E and supervision documentation required by multilateral institutions — no direct contract with WBG/ID4D, UNDP/UNOPS or EBRD.
Frameworks: WBG ID4D | EU Structural Funds | FIDIC | UNDP/UNOPS
eIDAS-compatible digital identity and trust services; data exchange and interoperability (API/iPaaS/ESB/eventing); e-signature, electronic notary, and national PKI; citizen-facing portals. Phased roadmaps, funding strategies, M&E frameworks, and supervision of implementation f...
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
- Programme coordination across geographically distributed teams and regulatory environments
eAI-PR / MAPE — AI Publishing Governance Ecosystem
AI-driven publishing governance ecosystem of specialised AI personas under strict human-in-the-loop design, serving content strategy across editorial, multilingual, compliance and performance dimensions. Built on experience at UN, NATO, EEAS and IBM. Orchestrated via LangGraph · AutoGen · AWS Bedrock · Azure AI Studio. One consolidated implementation ~45% of full scope in production with four further modules in active testing. Scale: ~1,000–3,000 platform users; 200–600 concurrent operators; 27+ languages.
Five capability groups
- A — Editorial Excellence: multi-tier automated editing, intelligent abstracting, narrative fluency tuning, multimodal asset blueprinting, AI graphics, editorial scheduler, content classification. KPI: 53% content cycle-time improvement
- B — Logical Auditing & Credibility: mathematical/logical sanity auditing, source verification and provenance mapping, dynamic citation engine, reputation intelligence and OSINT. KPI: −27% content/governance errors; zero statistical hallucinations before publication
- C — Institutional Alignment & Political Risk: geopolitical sensitivity screening, diplomatic localisation (border/territory nomenclature enforcement, dual-agent back-translation, confidence scoring for human veto), EU AI Act / ISO 42001 / NIST AI RMF compliance. KPI: zero reputational/political incidents
- D — Web Performance & Real-Time Interaction: behavioural click/heatmap tracking, real-time KPI dashboarding, A/B testing automation, deep engagement scoring. KPI: +32–45% active users; +21% UX optimisation
- E — Format Analysis & UI/UX: automated layout auditing, WCAG accessibility scanning, multi-device responsive QC. KPI: consistent cross-device reading experience worldwide
Stack: LangGraph · AutoGen · AWS Bedrock · Azure AI Studio · Adobe Analytics · GA4 · Hotjar · EU AI Act · ISO/IEC 42001 · NIST AI RMF
53% cycle-time reduction · −27% errors · +32–45% active users · 1,750+ hours saved · USD 3.9M structural value optimised · 27+ languages · zero diplomatic incidents
AI-driven publishing governance ecosystem of specialised AI personas under strict human-in-the-loop design, serving content strategy across editorial, multilingual, compliance and performance dimensions. Built on experience at UN, NATO, EEAS and IBM.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- AI model governance and explainability requirements under regulatory or institutional oversight
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
Freelancer — Chief Information Officer
Greater London, England, UK · Part-time, on-siteAI-driven governance application
AI-driven governance application designed to strengthen accountability, transparency and decision traceability across complex public- and private-sector organisations. Integrates AI, automation and governance principles to support responsible decision-making, risk management and compliance with legal, ethical and operational requirements. Provides an end-to-end view of decision processes, linking strategic objectives, policies, responsibilities and measurable outcomes into a coherent governance framework.
—
AI-driven governance application designed to strengthen accountability, transparency and decision traceability across complex public- and private-sector organisations. Integrates AI, automation and governance principles to support responsible decision-making, risk management a...
- AI model governance and explainability requirements under regulatory or institutional oversight
Romania Government / European Union — Specialist Advisor (B2B)
Romania (B2B) · Government & EU ProgrammesAdvisory services across 38+ ministries / public-sector stakeholders covering governance, enterprise architecture, cybersecurity and project implementation. Smart outsourcing / IT-service procurement initiatives.
Romania Govt & EU Programmes — AI policy & smart-outsourcing advisory
Research and policy initiatives on the impact of AI and emerging technologies on national and organisational strategies. Advisory on governance, enterprise architecture, cybersecurity and project implementation across multi-stakeholder environments. Smart outsourcing / IT-service procurement initiatives.
Key activities
- Led research on AI impact across national strategy, governance and operating models
- Delivered advisory across enterprise architecture and cybersecurity for regulated multi-stakeholder programmes
- Supported smart-outsourcing / IT procurement: requirements, evaluation criteria, operational constraints
- Aligned proposals with EU programme constraints and national policy direction
Frameworks: TOGAF · ISO 27001 · NIST CSF · GDPR · EU AI Act readiness · ITIL v3
38+ ministries / public-sector stakeholders
Research and policy initiatives on the impact of AI and emerging technologies on national and organisational strategies. Advisory on governance, enterprise architecture, cybersecurity and project implementation across multi-stakeholder environments.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- AI model governance and explainability requirements under regulatory or institutional oversight
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
NATO / NCIA — Head of Section (interim) · NDW / CPS
The Hague, NL · B2B – IWC PE · short-termInterim Head of the Content Collaboration Section at NATO/NCIA, accountable for the end-to-end service lifecycle (SLAs / OLAs) of collaboration and cybersecurity platforms across classified environments. NIST 800-53, ISO 27001, PCI DSS and NCA ECC alignment. Bridge between mission leaders, engineers and compliance teams.
NATO CS-NDW — Governance Framework · Cloud Adoption · DevSecOps
Defined and operationalised the governance framework for the Content Services — NATO Digital Workplace (CS-NDW) programme. Covered cloud adoption strategy, security cloud architecture and DevSecOps integration across a classified NATO environment.
- CS-NDW governance framework — decision authority, accountability chains, escalation paths, ARB integration
- Cloud adoption roadmap for NATO classified and unclassified environments — hybrid cloud boundaries, policy-as-code
- Security cloud architecture — Zero Trust alignment, classification-aware access controls, compartmentalisation
- DevSecOps pipeline design — security gates, automated compliance checks, release governance in NATO Secret domain
- STANAG and NAF alignment across architecture decisions; CD&E methodology applied to capability requirements
- Stakeholder governance across 32 NATO nations — executive reporting, audit evidence, decision registers
Frameworks: NAF · STANAG · NATO INFOSEC · Zero Trust · DevSecOps · CD&E · PRINCE2 · ISO 27001
📄 Letters of recommendation available · Named contacts provided upon request · NDA applies to classified details
Defined and operationalised the governance framework for the Content Services — NATO Digital Workplace (CS-NDW) programme. Covered cloud adoption strategy, security cloud architecture and DevSecOps integration across a classified NATO environment.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Implementing Zero Trust architecture at institutional scale with multi-stakeholder governance
- Hybrid cloud architecture design spanning on-premises, private and public cloud environments
NATO NDW / CPS — Content Collaboration Section (interim head)
Interim Head of Section accountable for the end-to-end service lifecycle of Content Collaboration platforms (Semantic MediaWiki and associated). Direct accountability for SLAs / OLAs across classified environments, service-change governance, CAB representation, KPI definition and reporting.
Key activities
- Coordinated and monitored 2nd- / 3rd-line support, incident investigation and root-cause resolution
- Served as first point of escalation for major incidents affecting the services
- Coordinated change enablement and release / deployment, representing services at CABs by delegation of the SAO
- Authorised new release packages and supported transition into service operation
- Defined and reported KPIs and associated service metrics; proactively monitored them
Frameworks: NIST 800-53 · ISO 27001 · PCI DSS · NCA ECC · ITIL v3 (service lifecycle) · PRINCE2
SLA / OLA portfolio · classified environments
Interim Head of Section accountable for the end-to-end service lifecycle of Content Collaboration platforms (Semantic MediaWiki and associated). Direct accountability for SLAs / OLAs across classified environments, service-change governance, CAB representation, KPI definition ...
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
NATO content-collaboration hybrid-cloud migration
Migrated all NATO content-collaboration systems to hybrid cloud. Immutable / audit-ready versioning patterns. PAM/IAM, SIEM/SOAR and GRC platforms integrated with satellite and terrestrial networks for mission-critical environments.
Key activities
- Designed secure-infrastructure architecture aligning controls with NIST 800-53, ISO 27001, PCI DSS and NCA ECC
- Delivered 3rd-line operational support and advanced troubleshooting across classified estates
- Integrated satellite-enabled PAM/IAM with SIEM/SOAR and GRC for cross-domain access governance
- Translated complex security-architecture concepts into actionable guidance for stakeholders
Frameworks: NIST 800-53 · ISO 27001 · PCI DSS · NCA ECC · Hybrid-cloud reference architecture
—
Migrated all NATO content-collaboration systems to hybrid cloud. Immutable / audit-ready versioning patterns.
- Cloud migration complexity across heterogeneous on-premises environments with minimal downtime
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
- Identity and access integration across heterogeneous directories (AD, LDAP, satellite, cloud)
InfoSec policy, phishing exercises & PII handling
Oversaw all InfoSec policies tied to Content Collaboration lifecycle management. Designed and led phishing / social-engineering exercises and awareness training. Managed privacy complaints and internal risk registers. Conducted internal audits and served as escalation point for incidents affecting PII.
Frameworks: ISO 27001 · GDPR · NIST CSF · NATO information-handling directives
—
Oversaw all InfoSec policies tied to Content Collaboration lifecycle management. Designed and led phishing / social-engineering exercises and awareness training.
- Coordinating multi-stakeholder delivery under time and resource constraints
European External Action Service (EEAS) — Technical Project Manager / hybrid Cloud / Cyber Security
Brussels, BE · B2B – IWC (Aubay) · 50+ member teamEEAS Portfolio Manager of Infrastructure with focus on cyberspace environment (incl. EUMIL military C3). Cloud security and architecture across AWS, Azure and GCP. Apps migration, networking, satellite and cybersecurity engineering. ISO 27001 · PCI DSS · GDPR · HIPAA · TOGAF.
EEAS Cyber Security & Architecture programme
Co-led the EEAS Portfolio Manager of Infrastructure function focusing on technical aspects, integration and operation of critical mission systems. Defined yearly EEAS portfolio (Technical Coherence, Digital Transformation, Cyber Defence) and aligned projects / programmes for cross-EEAS coherence.
Key activities
- Led a 50+ member team across apps migration, networking, satellite and cybersecurity engineering
- Deployed NGFW (Palo Alto, FortiGate, Check Point), WAF, IDS/IPS, sandbox, EDR, DLP, vulnerability management, PAM, IAM and DDoS protection
- Served as escalation point for 3rd-line troubleshooting and architecture validation; single point of contact with vendor 3rd-line
- Established cloud-governance frameworks, cost-optimisation and performance-monitoring practice
- Performed TOGAF modelling, architecture and design across capability targets, operational requirements and interoperability requirements
Frameworks: TOGAF · ISO 27001 · PCI DSS · GDPR · HIPAA · NIST 800-53 · COBIT · ITIL · IIBA · IREB · PRINCE2 · Agile
Team 50+ · multi-domain portfolio
Co-led the EEAS Portfolio Manager of Infrastructure function focusing on technical aspects, integration and operation of critical mission systems. Defined yearly EEAS portfolio (Technical Coherence, Digital Transformation, Cyber Defence) and aligned projects / programmes for c...
- Cloud migration complexity across heterogeneous on-premises environments with minimal downtime
- Identity and access integration across heterogeneous directories (AD, LDAP, satellite, cloud)
- Cost optimisation under institutional budget constraints while maintaining delivery quality
EU BICES — intelligence networking support
Support and architecture for EU BICES (Battlefield Information Collection and Exploitation System) within EEAS portfolio. Secure intelligence networking and cross-domain interoperability across member-state and partner-organisation feeds.
Frameworks: NATO STANAG · NAF · TOGAF · ISO 27001
—
Support and architecture for EU BICES (Battlefield Information Collection and Exploitation System) within EEAS portfolio. Secure intelligence networking and cross-domain interoperability across member-state and partner-organisation feeds.
- Coordinating multi-stakeholder delivery under time and resource constraints
EU Space & satellite security architecture
Security architecture for EU Space programmes and hybrid satellite / terrestrial networks. PAM/IAM, SIEM/SOAR and GRC platforms integrated with satellite communications for mission-critical EU operations.
Frameworks: ISO 27001 · NIST 800-53 · TOGAF · PCI DSS · GDPR
—
Security architecture for EU Space programmes and hybrid satellite / terrestrial networks. PAM/IAM, SIEM/SOAR and GRC platforms integrated with satellite communications for mission-critical EU operations.
- Identity and access integration across heterogeneous directories (AD, LDAP, satellite, cloud)
EU Intelligence Applications — architecture & security
Architecture, security and integration support for the EEAS Intelligence Applications portfolio. Controlled-access models and cross-domain integration patterns.
Frameworks: TOGAF · ISO 27001 · NIST 800-53
—
Architecture, security and integration support for the EEAS Intelligence Applications portfolio. Controlled-access models and cross-domain integration patterns.
- Coordinating multi-stakeholder delivery under time and resource constraints
EEAS C3 cyberspace requirements & architecture
Manage cyberspace environment (including EUMIL military sector C3) and analyse upcoming cyberspace requirements. Develop architectural diagrams, block diagrams and systems-engineering artefacts for capability evolution.
Key activities
- Capture, develop, analyse and evaluate capability requirements
- Maintain requirements traceability and version / configuration control
- Develop PoCs using hypothesis testing, MCDA, experimentation and wargaming
- Collaborate with 24 national / international military and civilian organisations including 9 Centres of Excellence and 5 universities
Frameworks: TOGAF · NATO STANAG · NAF · IIBA · IREB · ISO 31000
—
Manage cyberspace environment (including EUMIL military sector C3) and analyse upcoming cyberspace requirements. Develop architectural diagrams, block diagrams and systems-engineering artefacts for capability evolution.
- Policy and standards harmonisation across 24 sovereign jurisdictions
EEAS Disaster Recovery Centre
Disaster Recovery Centre design and implementation for EEAS critical mission systems. RTO / RPO definition, failover testing and continuity evidence.
Frameworks: ISO 22301 · ISO 27031 · NIST CSF
—
Disaster Recovery Centre design and implementation for EEAS critical mission systems. RTO / RPO definition, failover testing and continuity evidence.
- Coordinating multi-stakeholder delivery under time and resource constraints
EEAS Document Management System
Document Management System architecture and secure integration for EEAS, with traceability and audit-ready versioning across institutional content lifecycle.
Frameworks: ISO 27001 · GDPR · ISO/IEC 24760 (identity) · TOGAF
—
Document Management System architecture and secure integration for EEAS, with traceability and audit-ready versioning across institutional content lifecycle.
- Coordinating multi-stakeholder delivery under time and resource constraints
EEAS Oracle EBS upgrade with encryption & identity governance
Secure cloud migration and Oracle E-Business Suite upgrade with embedded encryption (AES-256), tokenisation, identity governance and data-protection controls.
Frameworks: ISO 27001 · PCI DSS · GDPR · NIST 800-53
—
Secure cloud migration and Oracle E-Business Suite upgrade with embedded encryption (AES-256), tokenisation, identity governance and data-protection controls.
- Cloud migration complexity across heterogeneous on-premises environments with minimal downtime
- Hardware-software co-design with hard real-time constraints and limited compute resources
EEAS apps migration & hybrid-cloud adoption
Cloud-security and architecture programmes across AWS, Azure and GCP. Apps migration combined with containerisation, serverless and hybrid-cloud patterns for scalability, automation and operational resilience.
Frameworks: AWS Well-Architected · Azure CAF · GCP Cloud Adoption · DevSecOps · ITIL v3 · ISO 27001
—
Cloud-security and architecture programmes across AWS, Azure and GCP. Apps migration combined with containerisation, serverless and hybrid-cloud patterns for scalability, automation and operational resilience.
- Cloud migration complexity across heterogeneous on-premises environments with minimal downtime
- Multi-cloud vendor-neutral architecture design to avoid lock-in while maintaining SLA commitments
IBM — Section Head — Digital & AI · Innovation Center
Worldwide · 39 direct / indirect reportsLead the Innovation Center. Information-security strategy and large-scale systems initiatives for Innovation Center and its sensitive clients. SIEM operation with AI/ML threat-hunting. Cyber Crisis Management programme delivery.
U.S. DoD JEDI / JWCC — Cloud Access Management (CAM)
Advisory architect for Cloud Access Management (CAM) within the U.S. Department of Defense JEDI / Joint Warfighter Cloud Capability (JWCC) programme — subcontract via Innovation Center, no direct DoD contract. Designed a zero-trust multi-cloud access layer spanning AWS, Azure, GCP, and OCI — ITAR, FedRAMP, and DoD IL5 compliant. Architecture aligned to JADC2 (Joint All-Domain Command and Control) interoperability requirements.
Key activities
- Zero-trust CAM architecture across four hyperscalers (AWS GovCloud, Azure Gov, GCP GovCloud, OCI)
- FedRAMP High and ITAR compliance design; DISA STIG alignment
- JADC2 interoperability integration — multi-domain, multi-classification
- Product Owner across agile delivery streams; architecture governance and ADR authority
Frameworks: FedRAMP · ITAR · DISA STIG · NIST 800-53 · Zero Trust (NIST SP 800-207) · JADC2
Classified programme value
Advisory architect for Cloud Access Management (CAM) within the U.S. Department of Defense JEDI / Joint Warfighter Cloud Capability (JWCC) programme — subcontract via Innovation Center, no direct DoD contract.
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
- Multi-cloud vendor-neutral architecture design to avoid lock-in while maintaining SLA commitments
IT audits & security assessments — banks & multinationals
Lead IT audits and security assessments for clients across Financial Services (Citibank, DB, Group Société Générale, Raiffeisen), Service Industry, Public Sector (Interpol, EU), Healthcare, and Manufacturing (Mercedes Benz, EADS).
—
Lead IT audits and security assessments for clients across Financial Services (Citibank, DB, Group Société Générale, Raiffeisen), Service Industry, Public Sector (Interpol, EU), Healthcare, and Manufacturing (Mercedes Benz, EADS).
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Cyber Crisis Management programme
Advise, implement and manage the Cyber Crisis Management programme — strategic crisis decision-making, large-scale crisis response. One of the largest, most respected teams of crisis and continuity management professionals.
—
Advise, implement and manage the Cyber Crisis Management programme — strategic crisis decision-making, large-scale crisis response. One of the largest, most respected teams of crisis and continuity management professionals.
- Coordinating multi-stakeholder delivery under time and resource constraints
- Balancing security hardening requirements with operational continuity
SIEM platforms with AI / ML threat-hunting
Operate SIEM platforms with threat-hunting capabilities. Combined proactive and reactive incident management using AI, Machine Learning, Elastic Search, cloud technology to rapidly adapt and respond to cyber disruptions. Real-time decisioning for ongoing security incidents.
—
Operate SIEM platforms with threat-hunting capabilities. Combined proactive and reactive incident management using AI, Machine Learning, Elastic Search, cloud technology to rapidly adapt and respond to cyber disruptions.
- Coordinating multi-stakeholder delivery under time and resource constraints
Global Security Operations Center oversight
Oversee Global SOC positions in daily tasks and projects. Selection of technology (cloud, SOA, etc.), devices and software for the network and information security infrastructure. Cryptographic key management in support of CIO function as Single Point of Authority.
—
Oversee Global SOC positions in daily tasks and projects. Selection of technology (cloud, SOA, etc.), devices and software for the network and information security infrastructure.
- Coordinating multi-stakeholder delivery under time and resource constraints
CyberPro — AI-driven cybersecurity platform
Designed, developed and operationalised "CyberPro", an AI-driven cybersecurity platform integrating SIEM (Splunk, QRadar), SOAR (Cortex XSOAR, IBM Resilient), EDR (CrowdStrike, Carbon Black, Defender for Endpoint) and DLP (Symantec, Microsoft Purview) for real-time threat correlation and automated incident response.
Key activities
- Network defence with Palo Alto, FortiGate, Check Point, IDS/IPS (Snort, Suricata), Zscaler, Proofpoint
- Unified risk dashboard integrating SIEM + GRC metrics
- Third-party risk assessments, policy mapping, SOC 2 / ISO 22301 business-continuity validation
- ISO 27001 audit readiness, PCI DSS gap analyses, GDPR compliance
Frameworks: ISO 27001 · PCI DSS · NIST 800-53 · ISO 22301 · SOC 2 · GDPR · COBIT 5 · ITIL v3
+53% improvement · 1,750+ hours saved
Designed, developed and operationalised "CyberPro", an AI-driven cybersecurity platform integrating SIEM (Splunk, QRadar), SOAR (Cortex XSOAR, IBM Resilient), EDR (CrowdStrike, Carbon Black, Defender for Endpoint) and DLP (Symantec, Microsoft Purview) for real-time threat corr...
- AI model governance and explainability requirements under regulatory or institutional oversight
- Simultaneous compliance with GDPR, PCI, ISO 27001 frameworks across programme scope
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
IBM Zero Trust · micro-segmentation · HSM key management
Zero Trust architectures, network micro-segmentation and encryption programme (TLS 1.3, AES-256, HSM-based key management) for defence and financial-services clients of the Innovation Center.
Key activities
- Architected hybrid and multi-cloud environments (Azure, AWS, GCP) with secure connectivity, monitoring and identity governance
- Centralised IAM (Azure AD, Okta, CyberArk PAM) with cloud-native monitoring (Azure Sentinel, AWS GuardDuty, Security Hub)
- Enforced secure-design standards across requirements, design and deployment with teams of 25+ engineers / architects
Frameworks: Zero Trust (NIST 800-207) · ISO 27001 · NIST 800-53 · PCI DSS · TOGAF
—
Zero Trust architectures, network micro-segmentation and encryption programme (TLS 1.3, AES-256, HSM-based key management) for defence and financial-services clients of the Innovation Center.
- Implementing Zero Trust architecture at institutional scale with multi-stakeholder governance
- Multi-cloud vendor-neutral architecture design to avoid lock-in while maintaining SLA commitments
IBM DevSecOps pipeline — containers + secrets management
Containerised workloads (Docker, Kubernetes, OpenShift) with DevSecOps pipelines (Jenkins, GitLab CI/CD, HashiCorp Vault) enforcing security-as-code across Innovation Center delivery.
Frameworks: DevSecOps · CIS Kubernetes Benchmark · OWASP · ISO 27001 · NIST 800-53
—
Containerised workloads (Docker, Kubernetes, OpenShift) with DevSecOps pipelines (Jenkins, GitLab CI/CD, HashiCorp Vault) enforcing security-as-code across Innovation Center delivery.
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
Romanian Electronic Passport — sovereign programme (€30M)
Architecture and programme management for the new Romanian ePassport sovereign programme — €30M contract. PKI infrastructure, biometric system, ICAO Doc 9303 compliance, chip personalisation, border control integration. Training for 500+ users. ISO 27001 and EU security standards. Distinct from the 2008–2010 initial deployment.
€30M contract · 500+ users trained
Architecture and programme management for the new Romanian ePassport sovereign programme — €30M contract. PKI infrastructure, biometric system, ICAO Doc 9303 compliance, chip personalisation, border control integration.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
Romanian National Agency of Cadastre & Land Registration — NACLR
Digital transformation of the National Agency of Cadastre and Land Registration — national land registry digitisation, workflow automation, PKI-secured records, cross-agency data integration. EU-funded programme delivered within Innovation Center.
EU-funded national programme
Digital transformation of the National Agency of Cadastre and Land Registration — national land registry digitisation, workflow automation, PKI-secured records, cross-agency data integration. EU-funded programme delivered within Innovation Center.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
Ministry of Finance — Single Window (cross-border trade Romania / EU)
Single Window platform for cross-border trade between Romania and EU — Ministry of Finance integration. Streamlined customs declarations, multi-agency data exchange, EU interoperability framework compliance.
National DPI · EU interoperability
Single Window platform for cross-border trade between Romania and EU — Ministry of Finance integration. Streamlined customs declarations, multi-agency data exchange, EU interoperability framework compliance.
- Simultaneous compliance with NIST frameworks across programme scope
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
United Nations HQ — Senior Information Technology Officer
New York, NY, USA · 16 direct reports · Fixed-term, full-timeLead UN Cybersecurity Requirements and Operation. Direct reporting to CITO. ISO 900X, Agile, PMI, Prince2, TOGAF, COBIT, ITIL, ISO 31000, ISO 2700X, NIST, ISO 2000, DevOps.
UN cyberspace concept & member-state recognition
Defined UN cyberspace concept and influenced UN member states to recognise UN as Single Point of Authority for UN and member-state cyberspace. Stakeholder management with budget secured to develop the collective cyberspace, cyber-security programme planning, and cyber-risk implementation.
US$125M (2015) + US$124M (2016) member-state budgets
Defined UN cyberspace concept and influenced UN member states to recognise UN as Single Point of Authority for UN and member-state cyberspace. Stakeholder management with budget secured to develop the collective cyberspace, cyber-security programme planning, and cyber-risk imp...
- Policy and standards harmonisation across multiple sovereign jurisdictions
UN SIEM platforms — real-time AI / ML threat-hunting
Designed, implemented and operated UN SIEM platforms with real-time, automated threat-hunting capabilities. Combined proactive and reactive incident management using AI, ML, Elastic Search, cloud. Real-time decisioning for security incidents.
—
Designed, implemented and operated UN SIEM platforms with real-time, automated threat-hunting capabilities. Combined proactive and reactive incident management using AI, ML, Elastic Search, cloud.
- Coordinating multi-stakeholder delivery under time and resource constraints
UN hybrid cloud (Azure + AWS), IoT, DLT, big data, virtualization
Drove cloud requirements, security controls and implementation (Azure and AWS), IoT, DLT, big data, virtualization, Office 365, BCP, code development, DevSecOps. Aligned security, technology, application and financial/business processes to new cloud environment and mobile.
Significant cost savings via Microsoft / Oracle / Cisco renegotiation
Drove cloud requirements, security controls and implementation (Azure and AWS), IoT, DLT, big data, virtualization, Office 365, BCP, code development, DevSecOps. Aligned security, technology, application and financial/business processes to new cloud environment and mobile.
- Reconciling DLT immutability with GDPR right-to-erasure and data sovereignty requirements
- Hybrid cloud architecture design spanning on-premises, private and public cloud environments
- Multi-cloud vendor-neutral architecture design to avoid lock-in while maintaining SLA commitments
DevSecOps automation with AI-driven answers
Automated DevSecOps with AI-driven security and vulnerability detection in continuous delivery workflow. Every build checked every time. Risk assessment based on actual libraries called in context of the environment and dependencies.
—
Automated DevSecOps with AI-driven security and vulnerability detection in continuous delivery workflow. Every build checked every time.
- Coordinating multi-stakeholder delivery under time and resource constraints
United ID — UN System inter-agency harmonisation
Worked at Enterprise level to increase system-wide harmonisation on ICT matters through inter-agency mechanisms (United ID). Common ICT security approaches and solutions (processes, standards) for the entire UN System. Liaised with Finance, HR and internal-affairs units across UN — Umoja system.
—
Worked at Enterprise level to increase system-wide harmonisation on ICT matters through inter-agency mechanisms (United ID). Common ICT security approaches and solutions (processes, standards) for the entire UN System.
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
UN blockchain community & strategy
Created a blockchain community and acted as leader to develop a strategy for the UN. Spoke at UN events on Digital ID solutions / Blockchain, Bitcoin / Ether / cryptocurrencies, TechNovation Day: Blockchain.
—
Created a blockchain community and acted as leader to develop a strategy for the UN. Spoke at UN events on Digital ID solutions / Blockchain, Bitcoin / Ether / cryptocurrencies, TechNovation Day: Blockchain.
- Reconciling DLT immutability with GDPR right-to-erasure and data sovereignty requirements
UN M365 E5 Security Suite deployment
Deployment of Microsoft 365 E5 Security Suite across UN workforce — DLP, MFA, Intune MDM, Conditional Access — supporting the global cybersecurity and digital-workplace transformation.
Frameworks: Microsoft Zero Trust · ISO 27001 · NIST 800-53 · GDPR
—
Deployment of Microsoft 365 E5 Security Suite across UN workforce — DLP, MFA, Intune MDM, Conditional Access — supporting the global cybersecurity and digital-workplace transformation.
- Coordinating multi-stakeholder delivery under time and resource constraints
- Balancing security hardening requirements with operational continuity
UN Oracle EBS R12 upgrade — tokenisation & database encryption
Oracle E-Business Suite R12 upgrade across UN estate with tokenisation and database encryption embedded, aligning ERP security to PCI DSS-grade controls.
Frameworks: PCI DSS · ISO 27001 · NIST 800-53
—
Oracle E-Business Suite R12 upgrade across UN estate with tokenisation and database encryption embedded, aligning ERP security to PCI DSS-grade controls.
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
- Hardware-software co-design with hard real-time constraints and limited compute resources
UN active-active data-centre architecture
Active-active data-centre architecture with automated failover using VMware SRM and Azure Site Recovery. Tested results: 99.98% availability, RTO < 4h, RPO 15 min.
Frameworks: ISO 22301 · ISO 27031 · NIST CSF
99.98% availability · RTO < 4h · RPO 15 min (tested)
Active-active data-centre architecture with automated failover using VMware SRM and Azure Site Recovery. Tested results: 99.98% availability, RTO < 4h, RPO 15 min.
- Virtualisation architecture design at a time of limited vendor maturity and tooling
UN Smart-Outsourcing programme (SOC · infrastructure · DevSecOps)
Smart-Outsourcing programme covering SOC, infrastructure and DevSecOps operations. Delivered USD 3.2M OPEX savings while maintaining PCI DSS Level 1 compliance.
Frameworks: ITIL v3 · PCI DSS · ISO 27001 · COBIT 5
USD 3.2M OPEX savings
Smart-Outsourcing programme covering SOC, infrastructure and DevSecOps operations. Delivered USD 3.2M OPEX savings while maintaining PCI DSS Level 1 compliance.
- Coordinating multi-stakeholder delivery under time and resource constraints
UN enterprise agreements — Microsoft + AWS with security / performance KPIs
Negotiated enterprise agreements with Microsoft and AWS embedding performance and security KPIs. Yielded ~20% annual cost optimisation across UN workloads.
Frameworks: Vendor governance · Microsoft Cloud Adoption Framework · AWS Well-Architected · ITIL v3
~20% annual cost optimisation
Negotiated enterprise agreements with Microsoft and AWS embedding performance and security KPIs. Yielded ~20% annual cost optimisation across UN workloads.
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
- Multi-cloud vendor-neutral architecture design to avoid lock-in while maintaining SLA commitments
- Cost optimisation under institutional budget constraints while maintaining delivery quality
UN Zero Trust + security-awareness enterprise programmes
Enterprise-wide Zero Trust programme combined with security-awareness training, improving organisational resilience and compliance maturity. ISO 27001 / PCI DSS / GDPR / SOC 2 audit findings reduced by 35% within one year.
Frameworks: Zero Trust (NIST 800-207) · ISO 27001 · PCI DSS · GDPR · SOC 2
-35% audit findings within 1 year
Enterprise-wide Zero Trust programme combined with security-awareness training, improving organisational resilience and compliance maturity. ISO 27001 / PCI DSS / GDPR / SOC 2 audit findings reduced by 35% within one year.
- Implementing Zero Trust architecture at institutional scale with multi-stakeholder governance
- Simultaneous compliance with GDPR, PCI, ISO 27001 frameworks across programme scope
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Freelance — eGovernment Blockchain engine designed, sold & integrated into IBM
Concurrent freelance B2B engagement during the UN HQ years. Conceptualised a state-of-the-art Blockchain engine tailored for e-government — cryptographic assurance, controlled access models, immutable evidence trails. Successfully negotiated the sale to IBM and coordinated its integration into IBM's global public-sector solution stack.
Frameworks: Hyperledger Fabric · Quorum · Corda · ISO/IEC 24760 · TOGAF · NIST 800-53
—
Concurrent freelance B2B engagement during the UN HQ years. Conceptualised a state-of-the-art Blockchain engine tailored for e-government — cryptographic assurance, controlled access models, immutable evidence trails.
- Reconciling DLT immutability with GDPR right-to-erasure and data sovereignty requirements
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
ICJ & ICC — International Courts Digitalisation (The Hague)
Senior IT Adviser and Architect for digitalisation programmes at the ICJ and ICC. Defined digital transformation vision, guiding principles (judicial independence, rule of law, security, accessibility), and KPI framework for each institution. Designed target architecture: multi-tier case management platform with classified document handling, e-filing with legally binding digital signature chain-of-custody, secure cross-border evidence exchange, encrypted judicial record repository, hearing management system, and interoperability with UN Secretariat, UNDP, and member-state delegations via secure API/ESB layer. Security-by-design for classified and highly sensitive judicial records; data governance model aligned to international judicial data protection standards; access control and full audit trail for judge, counsel, and registry workflows. Financed under UN internal budget; delivery supervised and audited against UN OICT standards.
UN internal budget (OICT standard)
Senior IT Adviser and Architect for digitalisation programmes at the ICJ and ICC. Defined digital transformation vision, guiding principles (judicial independence, rule of law, security, accessibility), and KPI framework for each institution.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
UNAT & UNDT — Digital Justice Strategy, Target Architecture & Delivery
Defined digital justice transformation strategy for the UN Administrative Tribunal (UNAT) and UN Dispute Tribunal (UNDT): strategic vision, guiding principles (user-centricity, rule of law, institutional independence, digital-by-default), measurable objectives, and KPI framework. Designed target architecture: multi-tier case management platform with API-first integration layer, identity federation (UN United ID), e-filing with digital signature chain-of-custody, secure document exchange (encrypted at rest and in transit), automated hearing scheduling engine, and interoperability with UN HR (PeopleSoft), legal registry, and finance (ERP) systems via ESB/API middleware. Security-by-design and privacy-by-design embedded throughout; GDPR-aligned data governance model for judicial records. End-to-end delivery through go-live with phased roadmap, change management plan (Prosci/ADKAR), M&E framework (case throughput, e-filing adoption, scheduling efficiency, user satisfaction), and supervision/audit of implementation. Outcome: full digitalisation of both tribunals serving UN staff globally across 190 countries.
UN internal budget (OICT standard)
Defined digital justice transformation strategy for the UN Administrative Tribunal (UNAT) and UN Dispute Tribunal (UNDT): strategic vision, guiding principles (user-centricity, rule of law, institutional independence, digital-by-default), measurable objectives, and KPI framewo...
- Policy and standards harmonisation across 190 sovereign jurisdictions
- Identity and access integration across heterogeneous directories (AD, LDAP, satellite, cloud)
- Simultaneous compliance with GDPR, NIST frameworks across programme scope
18-Country Digital Public Services Programme — Asia & Africa
Digital public services, national identity infrastructure, e-governance platforms, and capacity building across 18 UN member states in Asia and Africa. Professional services delivered throughout the full project lifecycle — diagnostic, strategic vision, governance framework, phased roadmap, target architecture, change management plan, M&E framework, supervision and audit of implementation — for the majority of citizens in each country.
OPEX US$56M / CAPEX US$12M (UN HQ portfolio)
Digital public services, national identity infrastructure, e-governance platforms, and capacity building across 18 UN member states in Asia and Africa. Professional services delivered throughout the full project lifecycle — diagnostic, strategic vision, governance framework, p...
- Policy and standards harmonisation across multiple sovereign jurisdictions
NATO HQ / NCIA / CSU BRX — Principal NNHQ IT Services Coordinator
Brussels, BE · 13 direct reports · Fixed-term, full-timeCoordination of personnel and equipment migration into the New NATO HQ. ANWI / AVI / ESS contractor coordination. NNHQ Target Architecture & Baseline Architecture. ISO 900X, Agile, PMI, Prince2, TOGAF, COBIT, ITIL, ISO 31000, ISO 2700X, NIST, ISO 2000, ISO/IEC 24760, DevOps.
NNHQ Target Architecture & ICT migration
Coordinate with NNHQ Transition Office (HQTO) for migration of personnel and equipment into the NNHQ. Coordinate with ANWI project (Infrastructure-as-a-Service hosting all business and applications). Comment and propose ICT migration paths. Maintain ICT technical drawings, space allocation and inventory. Contribute to NNHQ Target Architecture (TA) → Baseline Architecture (BA).
US$67M+ budget executed
Coordinate with NNHQ Transition Office (HQTO) for migration of personnel and equipment into the NNHQ. Coordinate with ANWI project (Infrastructure-as-a-Service hosting all business and applications).
- Coordinating multi-stakeholder delivery under time and resource constraints
- Ensuring architecture consistency across independently governed work streams
ANWI / AVI / ESS contractor coordination
Coordinate with NNHQ contractors — Active Network Infrastructure (ANWI) for IaaS, Audio-Visual Infrastructure (AVI), Electronic Security Services (ESS). Vendor relationships and IT-related contracts.
—
Coordinate with NNHQ contractors — Active Network Infrastructure (ANWI) for IaaS, Audio-Visual Infrastructure (AVI), Electronic Security Services (ESS). Vendor relationships and IT-related contracts.
- Policy and standards harmonisation across multiple sovereign jurisdictions
Disaster recovery + 90% server virtualization
Designed and executed first disaster-recovery centre fail-over. Successful DR plan and business continuity plan. Led server virtualization effort — virtualized 90% of systems infrastructure. AIS audits and system accreditation for classified systems.
—
Designed and executed first disaster-recovery centre fail-over. Successful DR plan and business continuity plan.
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
- Virtualisation architecture design at a time of limited vendor maturity and tooling
Freelance — IT Expert / IT Adviser (eight framework contracts)
Bucharest base · Worldwide · up to 39 direct reportsEight independent advisory framework contracts spanning banking, EU institutions, UN agencies, defence and digital identity.
INTERPOL Global Complex for Innovation — IT Security Advisor
Led six task forces to deliver strategy, observations and recommendations for enhancing institutional, operational, legal and technical frameworks for digital identity and cybercrime. Business analysis, strategic and security challenges, new concept and strategy translated into business and technical requirements for the National Cyber Review II (NCR) — spanning 197 INTERPOL member states. Drafted methodology for cyber-defence policy, concepts and capabilities at national level. Engagement via a top-tier international management consultancy, Singapore.
National Cyber Review II · 197 member states
Led six task forces to deliver strategy, observations and recommendations for enhancing institutional, operational, legal and technical frameworks for digital identity and cybercrime. Business analysis, strategic and security challenges, new concept and strategy translated int...
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Senior IT Adviser — EU Regulation 910/2014 (eIDAS)
Senior IT advisory framework contract on Regulation (EU) No 910/2014 — electronic identification and trust services for electronic transactions in the internal market (repealing Directive 1999/93/EC).
—
Senior IT advisory framework contract on Regulation (EU) No 910/2014 — electronic identification and trust services for electronic transactions in the internal market (repealing Directive 1999/93/EC).
- Coordinating multi-stakeholder delivery under time and resource constraints
SSEDIC — Single European Digital Identity Community (5-year programme)
5-year consultation period with 200+ European and international eID experts and stakeholder organisations. Recommendations and roadmap for the Single European Digital Identity Community supporting Horizon 2020.
—
5-year consultation period with 200+ European and international eID experts and stakeholder organisations. Recommendations and roadmap for the Single European Digital Identity Community supporting Horizon 2020.
- Policy and standards harmonisation across multiple sovereign jurisdictions
Emergency services architecture — Georgia (112)
Architecture, coding, security, operation and data-protection of emergency services. Enterprise Architecture Strategy & Roadmap. Technical roadmap for emergency video-call service. BMC Remedy Suite + Kinetics framework. Established a Center for Secure Information Systems & Digital Identity. Trained the trainers. http://112.ge
M50$ committed
Architecture, coding, security, operation and data-protection of emergency services. Enterprise Architecture Strategy & Roadmap.
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
National digital identity for Armenia — Police IT system
Armenian Government & Armenian Police — new IT system: digital identity architecture, cyber-security, data centre, DRC, personal data protection, risk management. Single secured and unified information environment (e-Governance). Roadmap and budget for interoperability with criminal justice, voting, idCard, passport, cadastre, justice, car registration, insurance.
M60$ committed
Armenian Government & Armenian Police — new IT system: digital identity architecture, cyber-security, data centre, DRC, personal data protection, risk management. Single secured and unified information environment (e-Governance).
- Policy and standards harmonisation across multiple sovereign jurisdictions
Digital identity, people registration & voting — Afghanistan
Validate business model, functional requirements, and obtain support for new digital identity management for people registration and voting. Solution Design Team management. Technical roadmap for implementation. Lead consulting team (3 experts). Risk assessment and mitigation.
M36$ budget
Validate business model, functional requirements, and obtain support for new digital identity management for people registration and voting. Solution Design Team management.
- Coordinating multi-stakeholder delivery under time and resource constraints
ECB cloud / digital architecture & cryptocurrency
Lead Solution Design team for modern cloud / digital and cryptocurrency architecture. Identify and document business flows, data exchanges, identity authorisation and security level. Integrations with European and governmental agencies. Updated Business Continuity Plan.
—
Lead Solution Design team for modern cloud / digital and cryptocurrency architecture. Identify and document business flows, data exchanges, identity authorisation and security level.
- Identity and access integration across heterogeneous directories (AD, LDAP, satellite, cloud)
ENISA — National Cyber Security Strategy framework
Member of expert advisory group defining the National Cyber Security Strategy (NCSS) framework and action plan to improve security and resilience of EU national infrastructures and services. Part of the task force ensuring that national eIDs work for cross-border public-service access in EU.
—
Member of expert advisory group defining the National Cyber Security Strategy (NCSS) framework and action plan to improve security and resilience of EU national infrastructures and services. Part of the task force ensuring that national eIDs work for cross-border public-servic...
- Policy and standards harmonisation across multiple sovereign jurisdictions
VAUBAN — IT PMO Head / IT Director, Banking Transformation
PMO effective operation, IT Strategic Planning and Banking Transformation Programme. Set-up Center for Secure Information Systems. Enterprise Architecture Strategy & Roadmap. Coordination with PMOs/CSICs in Croatia, France, Russia, Bulgaria, Moldova. New Core Banking — INFOSYS Finacle / Oracle Flexcube. Cards & alternative channels (Mobile/Internet Banking, WU@ATM, WU@POS, prepaid). 900+ servers, 550+ applications, 120+ audit recommendations closed (89%).
US$3.93M IT savings · US$2.88M vendor negotiations · US$63M budget · OPEX -44.2%
PMO effective operation, IT Strategic Planning and Banking Transformation Programme. Set-up Center for Secure Information Systems.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Cernavoda NPP (Nuclearelectrica / SIVECO) — IT Advisor
Restructured entire SMS system (BMC 8.5 → 9), new workflows. Reengineered processes for Change & Service Request, Unified Event Management with event correlation, Service Catalogue and Service Level Management. Cyber-security audit per NRC Title 10 §73.54, NRC RG 5.71, NEI 08-09, NEI 13-10, 10 CFR 73.54, NIST SP800-53/82, ISO 2700x. Audit of DCS, HMI, PLC, RTU, SCADA. 100% audit compliance achieved.
—
Restructured entire SMS system (BMC 8.5 → 9), new workflows. Reengineered processes for Change & Service Request, Unified Event Management with event correlation, Service Catalogue and Service Level Management.
- Coordinating multi-stakeholder delivery under time and resource constraints
Document Management & Portal System — Romanian Immigration
SMC implementation based on IBM Tivoli Suite. EU Secret level — implications for information security and technical design (Approved products, certification, homologation). Solution design with Azure cloud, Microsoft 2008 Suite, MS SQL 2008. Custom software development (700 person-days). WEB Services / XML integration. Enterprise IBM servers, Enterprise SAN, LTO, LAN/WAN, CA IAM, PKI. Established small PMO.
—
SMC implementation based on IBM Tivoli Suite. EU Secret level — implications for information security and technical design (Approved products, certification, homologation).
- Cloud migration complexity across heterogeneous on-premises environments with minimal downtime
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
- Identity and access integration across heterogeneous directories (AD, LDAP, satellite, cloud)
IT Health System — ePrescription, ePatientFolder
Solution design with Oracle WebLogic and DB 11g. Custom software development (700 person-days, Java). Integration via Web Services / XML. IBM Cloud, Mobile devices, VMware, Oracle Finance, BPM, IBM servers, Enterprise SAN, LTO, LAN/WAN, IAM Oracle, PKI, BCP. Data centre relocation. SAP NW Identity Management implementation. Center for Secure Information Systems with trained trainers. ISO 2700x compliance support. PMO setup.
—
Solution design with Oracle WebLogic and DB 11g. Custom software development (700 person-days, Java).
- Identity and access integration across heterogeneous directories (AD, LDAP, satellite, cloud)
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
- Virtualisation architecture design at a time of limited vendor maturity and tooling
IBM — Senior IT Adviser / CoE Manager · EMEA CoE Defence & Security · CoE eGovernment
Bucharest, RO · Worldwide · up to 52 direct reports / 120 indirectLead the IBM EMEA Centre of Excellence for Defence & Security and Centre of Excellence for eGovernment / Digital Identity. Subject-matter expert for sovereign DPI rollouts.
Transfond — electronic payment & inter-banking compensation
IT system for electronic payment (T24, Murex, TI+) and inter-banking compensation. Process design and compliance with international mechanisms. Data protection. PCI-DSS & ISO 27001 certification. 30T transactions/day. 99.9998% availability.
—
IT system for electronic payment (T24, Murex, TI+) and inter-banking compensation. Process design and compliance with international mechanisms.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Simultaneous compliance with ISO 27001, PCI frameworks across programme scope
IBM Data-Center — Tier 4 (~8000 m²)
Led from business case through Go Live: new IBM Data-Center (~8000 m², 99.995%/year). Defined and implemented business and operational processes. Service Catalogue, Budget management, SLA monitoring. Service-provider processes for PaaS, AaaS, SaaS, IaaS (cloud private, hybrid, public). ISO 27001/27002 risk assessment. PCI-DSS & ISO 2700x certification support.
SD consolidation: 45 small SD → 1 central · €500K/year saving
Led from business case through Go Live: new IBM Data-Center (~8000 m², 99.995%/year). Defined and implemented business and operational processes.
- Simultaneous compliance with PCI, ISO 27001 frameworks across programme scope
ECB · EU · CE · ING · Citibank · JPM · Raiffeisen · Société Générale · CEC Bank
IT Risk Analysis System (ISO 2700x). Solution design of new Core Banking. Cloud private/public PoC. Data centre relocation, HW/SW/MW/NW/SAN consolidation. Set-up Business Intelligence Competence Center (Data Architecture, Quality, Governance, BI & Executive Dashboard).
—
IT Risk Analysis System (ISO 2700x). Solution design of new Core Banking.
- Coordinating multi-stakeholder delivery under time and resource constraints
Raiffeisen — Risk & Card upgrade + CSIS
Upgraded Risk Analysis System (Murex), Card System (Murex), RISC and x86 server infrastructure. Center for Secure Information Systems: SIEM, DB Security, ISMS & ISR, MDM, Managed Security Services. Process improvement (ITIL).
—
Upgraded Risk Analysis System (Murex), Card System (Murex), RISC and x86 server infrastructure. Center for Secure Information Systems: SIEM, DB Security, ISMS & ISR, MDM, Managed Security Services.
- Coordinating multi-stakeholder delivery under time and resource constraints
Romanian Ministry of Internal Affairs — National Cyber Security
Large-scale cyber-defence system (>€4M, EU funds). Unitary mechanism of reaction and response to security incidents. Risk reduction, knowledge, capabilities and decision mechanisms in the Romanian Government. 250 offices / 500,000 assets across the country. Service Management System (Tivoli Business Service Manager), SLA monitoring. ISO 2700x, NIST. http://www.natowatch.org/node/1532
>€4M (EU funds)
Large-scale cyber-defence system (>€4M, EU funds). Unitary mechanism of reaction and response to security incidents.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
- Simultaneous compliance with NIST frameworks across programme scope
Romanian Electronic Passport — sovereign programme
Architecture + project management of large-scale system covering full ePassport lifecycle. Sensitive environment. Training for 500+ users. 4 main sites / 4 Tier-3 data centres, 45+ offices in Romania, 250+ offices worldwide. Business continuity. New business and operational processes. ISO 27001 risk assessment, audit, policy.
>€30M
Architecture + project management of large-scale system covering full ePassport lifecycle. Sensitive environment.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
Romanian National Agency of Cadastre & Land Registration
Roll-out of enterprise IT system (infrastructure, application, business processes) for cartographic products and Ortophotoplan coverage (GIS), cadastral plans, topographic plans for the entire country.
>€7M
Roll-out of enterprise IT system (infrastructure, application, business processes) for cartographic products and Ortophotoplan coverage (GIS), cadastral plans, topographic plans for the entire country.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Single Window — cross-border trade Romania / EU
European Commission and Romanian Ministry of Finance. Single Window application and infrastructure (design, project management, training, change management). Set-up Business Intelligence Competence Center.
>€2.3M (EU funds)
European Commission and Romanian Ministry of Finance. Single Window application and infrastructure (design, project management, training, change management).
- Coordinating multi-stakeholder delivery under time and resource constraints
IBM Blue Gene Supercomputer
Only supercomputer of its size in Romania and one of 3 in Central / Eastern Europe at the time. 13.9 TFlops compute power: 1024 processors, 4096 cores, 4 TB RAM, 32 I/O nodes.
—
Only supercomputer of its size in Romania and one of 3 in Central / Eastern Europe at the time. 13.9 TFlops compute power: 1024 processors, 4096 cores, 4 TB RAM, 32 I/O nodes.
- Coordinating multi-stakeholder delivery under time and resource constraints
National ePassport programmes (multi-country)
Subject-matter expert for national biometric travel-document architecture, secure issuance chain, ICAO-compliant chip personalisation, PKI trust services, border-control integration.
Multi-country sovereign programmes
Subject-matter expert for national biometric travel-document architecture, secure issuance chain, ICAO-compliant chip personalisation, PKI trust services, border-control integration.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
National eID and citizen identity (multi-country)
Sovereign citizen-identity platforms — authentication, credential issuance, national PKI integration. End-to-end Digital Public & Private Business — citizen onboarding and cross-border eID access (eIDAS interoperability).
Multi-country sovereign programmes
Sovereign citizen-identity platforms — authentication, credential issuance, national PKI integration. End-to-end Digital Public & Private Business — citizen onboarding and cross-border eID access (eIDAS interoperability).
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Identity and access integration across heterogeneous directories (AD, LDAP, satellite, cloud)
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
National eHealth — patient registration & ePrescription
Patient registration, ePrescription, EHR exchange, identity-linked patient access, audit-ready clinical data flows.
—
Patient registration, ePrescription, EHR exchange, identity-linked patient access, audit-ready clinical data flows.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
Cadastre / land-registry digitalisation (multi-country)
Sovereign land-registry digitalisation — geospatial data integrity, registration workflows, judiciary and notary interoperability.
—
Sovereign land-registry digitalisation — geospatial data integrity, registration workflows, judiciary and notary interoperability.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
eJustice Romania
Citizen access to justice services based on digital identification.
—
Citizen access to justice services based on digital identification.
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
National PKI Romania
Root and subordinate CAs, certificate lifecycle, trust anchors for sovereign identity and document services.
—
Root and subordinate CAs, certificate lifecycle, trust anchors for sovereign identity and document services.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
eNotar — Bulgaria + Moldova
Electronic notary services — identity-bound electronic signatures, document integrity, registry-of-acts interoperability.
—
Electronic notary services — identity-bound electronic signatures, document integrity, registry-of-acts interoperability.
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
EURODAC + Asylum DB
Senior IT Adviser on EURODAC — fingerprint datasets to determine responsibility for examining asylum applications across EU States.
—
Senior IT Adviser on EURODAC — fingerprint datasets to determine responsibility for examining asylum applications across EU States.
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Telekom Romania — NGN, MPLS, M2M, OSS/BSS upgrade
Framework contract upgrade and extension of NGN, MPLS, M2M, OSS/BSS. Whole-system transformation. IT Security audit (ISO 27001).
FwC >€30M
Framework contract upgrade and extension of NGN, MPLS, M2M, OSS/BSS. Whole-system transformation.
- M2M/IoT protocol diversity and reliability over unreliable network conditions
IBM + Vodafone — M2M / Cloud & Virtualisation / IoT PoC
Proof of concept for M2M system: private hosted virtualisation (VMware ESX / IBM POWER LPAR) and private cloud PoC (2010–2011), M2M connectivity, AaaS, BSS/OSS integration and transformation plan. Security architecture.
—
Proof of concept for M2M system: private hosted virtualisation (VMware ESX / IBM POWER LPAR) and private cloud PoC (2010–2011), M2M connectivity, AaaS, BSS/OSS integration and transformation plan. Security architecture.
- M2M/IoT protocol diversity and reliability over unreliable network conditions
- Virtualisation architecture design at a time of limited vendor maturity and tooling
- Programme coordination across geographically distributed teams and regulatory environments
IBM EMEA Center of Excellence — Defence & Security (internal CoE leadership)
Led the IBM EMEA Center of Excellence for Defence and Security. Defined and managed business and technical requirements; architected / designed critical military systems; co-led development, verification and validation across 28+ IT upgrade / migration projects.
Key activities
- Defined yearly IBM Portfolio across Technical Coherence, Digital Transformation and Cyber Defence
- Performed TOGAF modelling, architecture and design across capability targets and interoperability requirements
- Direct support of national / international / multi-national C2, C3, C5 activities
- Collaborated with 146 national / international military and civilian organisations including 36 Centres of Excellence
Frameworks: TOGAF · COBIT · ITIL · PRINCE2 · RUP · ISO 900X · ISO 27K · ISO 31000 · NIST · C2I / C3I / C4ISR / C5I · VMware ESX/vSphere · IBM POWER LPAR · IBM z/VM · Hyper-V · Virtualisation architecture
28+ IT upgrade / migration projects · 146 orgs · 36 CoEs
Led the IBM EMEA Center of Excellence for Defence and Security. Defined and managed business and technical requirements; architected / designed critical military systems; co-led development, verification and validation across 28+ IT upgrade / migration projects.
- Policy and standards harmonisation across 146 sovereign jurisdictions
- Programme coordination across geographically distributed teams and regulatory environments
IRIS — SNCFR National Railway Digital Transformation
Enterprise IT architecture for national railway digital transformation. Scope: safety-critical systems, passenger services, operations infrastructure, and IT/OT integration. Architecture definition, technology roadmap, and delivery oversight for one of Romania's largest state-owned transport enterprises.
IBM Romania national programme
Enterprise IT architecture for national railway digital transformation. Scope: safety-critical systems, passenger services, operations infrastructure, and IT/OT integration.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Freescale / Motorola — Program Manager
Bucharest, RO + Austin, TX · 31 direct / 110+ indirect reportsMotorola Center of Excellence for Cybersecurity (CoE-CS). Crypto-X and digital/biometric identity programs. CMM/CMMI Level III software process improvement. ISO 900X, Agile, PMI, Prince2, TOGAF, COBIT, ITIL, NIST, ISO 27xxx, CMMI, SDLC, DevOps.
Motorola Center of Excellence for Cybersecurity (CoE-CS)
Developed and led Motorola CoE-CS. Strategy and design of major systems initiatives around information security worldwide. Recognised as main pillar — invested in: US$18M (2006) and US$26M (2007). 35 experts directed; 23 new experts hired with 108 internationally recognised certifications.
US$18M (2006) + US$26M (2007)
Developed and led Motorola CoE-CS. Strategy and design of major systems initiatives around information security worldwide.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Hardware-software co-design with hard real-time constraints and limited compute resources
- Programme coordination across geographically distributed teams and regulatory environments
Crypto-X program — digital / biometric identity & authorisation
Established the Crypto-X programme and digital / biometric identity and authorisation initiatives. Coordinated Linux software developers across USA, Canada, Brazil, China, India, UK, France, Germany on cores, peripherals and device drivers (crypto devices, digital identification, IP Security protocols).
—
Established the Crypto-X programme and digital / biometric identity and authorisation initiatives. Coordinated Linux software developers across USA, Canada, Brazil, China, India, UK, France, Germany on cores, peripherals and device drivers (crypto devices, digital identificati...
- Programme coordination across geographically distributed teams and regulatory environments
Motorola estate cyber-rationalisation + CSIS
Assessed >3,000 legacy applications, consolidated 839. Defined Motorola Cybersecurity policy and standards (zero-trust concept). Redesigned Internet Access Point and network topology (firmware rules, VPNs, router security, SSL). Established Center for Secure Information Systems (CSIS). Implemented Motorola's first internal/external cybersecurity audit and compliance program.
—
Assessed >3,000 legacy applications, consolidated 839. Defined Motorola Cybersecurity policy and standards (zero-trust concept).
- Hardware-software co-design with hard real-time constraints and limited compute resources
- Programme coordination across geographically distributed teams and regulatory environments
Oracle PeopleSoft — HRMS, FMS, SCM, CRM, EPM
Implemented Oracle PeopleSoft (HRMS, Financial Management Solutions, SCM, CRM, Enterprise Performance Management) and Oracle ESB at organisational level.
US$45M budget executed
Implemented Oracle PeopleSoft (HRMS, Financial Management Solutions, SCM, CRM, Enterprise Performance Management) and Oracle ESB at organisational level.
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
- Programme coordination across geographically distributed teams and regulatory environments
CMM/CMMI Level III + Motorola Romania PMO (120+ resources)
Led CMM/CMMI software process improvement programme — achieved Level III. Set up local Motorola PMO (120+ resources) aligned with Freescale's PMO framework. Lean Six Sigma process improvement.
US$2.93M IT savings · 9.88% below budget
Led CMM/CMMI software process improvement programme — achieved Level III. Set up local Motorola PMO (120+ resources) aligned with Freescale's PMO framework.
- Hardware-software co-design with hard real-time constraints and limited compute resources
Alcatel — Senior Architect / CoE-PM Manager
Timișoara · Paris · Bucharest · 45 direct / 144 indirect reports(Co)Lead Alcatel Center of Excellence for Banking, Security & Intelligence + Regional Centre of Excellence for eGovernment. 27+ large-scale projects (US$98.84M total).
EURODAC — Romania (EU funds)
EURODAC system — EU asylum-applicant identification via fingerprint datasets. Business-intelligence flows and implementation. EU Secret.
>€3M (EU funds)
EURODAC system — EU asylum-applicant identification via fingerprint datasets. Business-intelligence flows and implementation.
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Border Protection integrated system
Border Protection integrated system — radars, mobile surveillance, military equipment. OSS modernisation. EU Secret.
>€13M (EU funds)
Border Protection integrated system — radars, mobile surveillance, military equipment. OSS modernisation.
- Security architecture design within classified NATO/defence constraints (COSMIC/NATO Secret)
Ucka Tunnel — modernization of integrated electronic safety system
Croatia Ministry of Transportation — Ucka Tunnel modernization of integrated electronic safety system.
>€1M
Croatia Ministry of Transportation — Ucka Tunnel modernization of integrated electronic safety system.
- Coordinating multi-stakeholder delivery under time and resource constraints
Bulgarian Min. Transportation — Corridor IV GSM-R rail
New integrated telecom rail system (including GSM-R) on Corridor IV Pan European.
>€29M (EU funds)
New integrated telecom rail system (including GSM-R) on Corridor IV Pan European.
- Coordinating multi-stakeholder delivery under time and resource constraints
Bulgarian Min. Energy — optical fibre + tele-transmission + CSIS
New optical fibre and tele-transmission system. Established a Center of Security Information Systems (ISO 2700x). Designed and executed audit on enterprise network, VPN and key applications. Automated continual auditing system/database.
>€3M (EU funds, FIDIC)
New optical fibre and tele-transmission system. Established a Center of Security Information Systems (ISO 2700x).
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Black Sea + Danube surveillance
Black Sea and Danube surveillance — CCTV, radars, telecom, special devices, GIS.
—
Black Sea and Danube surveillance — CCTV, radars, telecom, special devices, GIS.
- Coordinating multi-stakeholder delivery under time and resource constraints
Metro Dubai — telecom solution offer
Prepared offer for Dubai Metro — telecom solution, risk identification/quantification/analysis, project estimation.
—
Prepared offer for Dubai Metro — telecom solution, risk identification/quantification/analysis, project estimation.
- Coordinating multi-stakeholder delivery under time and resource constraints
Teletrans — integrated IP + PABX telecom system
New integrated telecom system (IP, PABX). OSS/BSS integration and whole-system transformation.
>€3M (FIDIC)
New integrated telecom system (IP, PABX). OSS/BSS integration and whole-system transformation.
- Coordinating multi-stakeholder delivery under time and resource constraints
Paris Charles de Gaulle Airport — Borderless Networks
Borderless Networks infrastructure — routing, switching, network security, application delivery networking, Unified Computing System, Storage, Wireless, Security and Identity Services Engine.
—
Borderless Networks infrastructure — routing, switching, network security, application delivery networking, Unified Computing System, Storage, Wireless, Security and Identity Services Engine.
- Coordinating multi-stakeholder delivery under time and resource constraints
Romanian airports — telecom + IT security + SCADA
Otopeni Airport — unified telecommunication, IT security, IP. Cluj Airport — SCADA, telecom, IT security; audit of DCS/HMI/PLC/RTU/SCADA. Cogalniceanu Airport — unified telecom, SCADA, audit of control systems.
—
Otopeni Airport — unified telecommunication, IT security, IP. Cluj Airport — SCADA, telecom, IT security; audit of DCS/HMI/PLC/RTU/SCADA.
- Coordinating multi-stakeholder delivery under time and resource constraints
Orange Romania — backbone + GSM + OSS/BSS transformation
Telecom system: backbone & GSM systems, OSS/BSS, whole-system transformation.
FwC >€40M
Telecom system: backbone & GSM systems, OSS/BSS, whole-system transformation.
- Coordinating multi-stakeholder delivery under time and resource constraints
Telekom Romania — Borderless Networks + SAP IDM
Borderless Networks infrastructure (routing, switching, network security, application delivery, UCS, Storage, Wireless, Security and Identity Services Engine, NGN, MPLS, PABX, M2M, OSS/BSS). SAP NLM and SAP NW Identity Management implementation. Cyber investigations, computer forensics, threat intelligence, vulnerability assessments and incident response.
FwC >€40M
Borderless Networks infrastructure (routing, switching, network security, application delivery, UCS, Storage, Wireless, Security and Identity Services Engine, NGN, MPLS, PABX, M2M, OSS/BSS). SAP NLM and SAP NW Identity Management implementation.
- M2M/IoT protocol diversity and reliability over unreliable network conditions
Traumatology Hospitals — IP + telemedicine PoC
Telecom solution (IP) and telemedicine proof of concept across the network.
<€1M (EU funds)
Telecom solution (IP) and telemedicine proof of concept across the network.
- Coordinating multi-stakeholder delivery under time and resource constraints
Kozloduy Nuclear Power Plant — SCADA + telecom audit
Audit and modernisation of SCADA and telecommunications systems. Process optimisation. Roadmap definition.
—
Audit and modernisation of SCADA and telecommunications systems. Process optimisation.
- Coordinating multi-stakeholder delivery under time and resource constraints
Cernavoda NPP — telecom roadmap + IT security audit
SIVECO subcontractor — audit and roadmap for telecommunication system. IT security audit. IT infrastructure and I&C system: DCS, HMI, PLC, RTU, SCADA.
—
SIVECO subcontractor — audit and roadmap for telecommunication system. IT security audit.
- Coordinating multi-stakeholder delivery under time and resource constraints
OMV Petrom — Tier 3 data centre + DR
New data centre (Tier 3), cyber security, business continuity and disaster-recovery data centre.
>€250K
New data centre (Tier 3), cyber security, business continuity and disaster-recovery data centre.
- Coordinating multi-stakeholder delivery under time and resource constraints
National ePassport — France · Germany · Morocco · South Africa
Subject-matter expert for national biometric travel-document — secure issuance, PKI trust services.
>€32M
Subject-matter expert for national biometric travel-document — secure issuance, PKI trust services.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
National eID and citizen identity (multi-country)
National eID and digital identity — sovereign citizen-identity platforms, authentication, credential issuance.
Multi-country sovereign programmes
National eID and digital identity — sovereign citizen-identity platforms, authentication, credential issuance.
- Policy and standards harmonisation across multiple sovereign jurisdictions
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
DigiNotar — Romania
DigiNotar — electronic notary trust services for Romania.
—
DigiNotar — electronic notary trust services for Romania.
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
Civil registration — France · Romania · Germany · Morocco · South Africa
Civil registration — births, marriages, deaths, identity-linked registry.
—
Civil registration — births, marriages, deaths, identity-linked registry.
- Sovereign interoperability with eIDAS 2.0, EUCS and cross-border digital identity standards
Société Générale — telecom & secure-banking network integration
Alcatel-era engagement with Groupe Société Générale: secure banking network integration, OSS/BSS modernisation and core-banking telecom infrastructure (predecessor to the later VAUBAN programme delivered as freelance 2011 – 2013).
Frameworks: ITIL v3 · COBIT · ISO 27001 · PCI DSS
—
Alcatel-era engagement with Groupe Société Générale: secure banking network integration, OSS/BSS modernisation and core-banking telecom infrastructure (predecessor to the later VAUBAN programme delivered as freelance 2011 – 2013).
- Coordinating multi-stakeholder delivery under time and resource constraints
BCR Bank — Alcatel-era core-banking & telecom network integration
Alcatel-era BCR Bank engagement: core-banking telecom and network integration, secure-network projects across the European banking estate.
Frameworks: ITIL · ISO 27001 · PCI DSS · TOGAF
—
Alcatel-era BCR Bank engagement: core-banking telecom and network integration, secure-network projects across the European banking estate.
- Coordinating multi-stakeholder delivery under time and resource constraints
BNR — National Bank of Romania — telecom & network
Alcatel-era engagement with BNR (National Bank of Romania): telecom and secure-network integration for central-bank operations.
Frameworks: ITIL · ISO 27001 · TOGAF · Central-bank operational standards
—
Alcatel-era engagement with BNR (National Bank of Romania): telecom and secure-network integration for central-bank operations.
- Policy and standards harmonisation across multiple sovereign jurisdictions
CEC Bank — Alcatel-era telecom & network integration
Alcatel-era CEC Bank engagement: telecom and secure-network integration for the Romanian state savings bank estate.
Frameworks: ITIL · ISO 27001 · TOGAF · PCI DSS
—
Alcatel-era CEC Bank engagement: telecom and secure-network integration for the Romanian state savings bank estate.
- Coordinating multi-stakeholder delivery under time and resource constraints
Alcatel Center of Excellence — Defence, Security & Intelligence (internal CoE leadership)
(Co-)Led the Alcatel Center of Excellence for Defence, Security and Intelligence markets, with the Alcatel Romania Enterprise Architecture function. Defined the yearly Alcatel Romania Technical Portfolio across ICT Architecture, Digital Workplace, Digital Transformation and Cyber Defence.
Key activities
- Aligned portfolio across Alcatel Information Enterprise; identified programmatic / technical touchpoints
- Performed TOGAF modelling, architecture and design for completeness, consistency and clarity
- Developed PoCs using hypothesis testing, MCDA, experimentation, wargaming and simulation
- Collaborated with 46 national / international military and civilian organisations including 17 Centres of Excellence
Frameworks: TOGAF · COBIT · ITIL · PRINCE2 · PMI · ISO 900X · ISO 31000 · NIST · VMware ESX · Network virtualisation · VLAN · MPLS · SCADA
—
(Co-)Led the Alcatel Center of Excellence for Defence, Security and Intelligence markets, with the Alcatel Romania Enterprise Architecture function. Defined the yearly Alcatel Romania Technical Portfolio across ICT Architecture, Digital Workplace, Digital Transformation and Cy...
- Policy and standards harmonisation across 46 sovereign jurisdictions
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
Helinick SRL — Senior System Engineer / IT Director
Bucharest, RO · 5–14 direct reports35 projects on time and on budget. Hands-on systems engineering, infrastructure and secure operations. Biometric / control-access projects (iris, fingerprint, face recognition, barcode/proxy cards).
Magurele nuclear research lab — SCADA + biometric security + I&C
SCADA system, biometric security systems, instrumentation & control.
—
SCADA system, biometric security systems, instrumentation & control.
- Coordinating multi-stakeholder delivery under time and resource constraints
Cernavoda Nuclear Power Plant — biometric security
Biometric security system for Cernavoda NPP (via UTI).
—
Biometric security system for Cernavoda NPP (via UTI).
- Coordinating multi-stakeholder delivery under time and resource constraints
Citibank — biometric security + Building Automation
Biometric security systems and Building Automation System for Citibank.
—
Biometric security systems and Building Automation System for Citibank.
- Coordinating multi-stakeholder delivery under time and resource constraints
BRD Bank · BCR Bank — security systems + BAS
Security systems and Building Automation System for BRD Bank and BCR Bank.
—
Security systems and Building Automation System for BRD Bank and BCR Bank.
- Coordinating multi-stakeholder delivery under time and resource constraints
Orange Romania — security + site rehabilitation + data center
Security systems, site rehabilitation, data centre.
—
Security systems, site rehabilitation, data centre.
- Coordinating multi-stakeholder delivery under time and resource constraints
Ericsson — security + I&C + telecom systems
Security system, I&C installation, telecommunication systems.
—
Security system, I&C installation, telecommunication systems.
- Coordinating multi-stakeholder delivery under time and resource constraints
Philip Morris — SCADA + WMS + BAS + HVAC
Security systems, warehouse management system, SCADA, Building Automation System, HVAC.
—
Security systems, warehouse management system, SCADA, Building Automation System, HVAC.
- Coordinating multi-stakeholder delivery under time and resource constraints
BAT — security + warehouse mgmt + BAS
Security systems, warehouse management system, Building Automation System.
—
Security systems, warehouse management system, Building Automation System.
- Coordinating multi-stakeholder delivery under time and resource constraints
Retail — Sodexho pass · Selgros · Metro
Security systems and Building Automation System for retail clients Sodexho pass, Selgros and Metro.
—
Security systems and Building Automation System for retail clients Sodexho pass, Selgros and Metro.
- Coordinating multi-stakeholder delivery under time and resource constraints
Baneasa · Henri Coanda · Tarom — airport security + BAS + PSS
Security systems, Building Automation Systems, and PSS (Tarom) for Romanian airports and airline.
—
Security systems, Building Automation Systems, and PSS (Tarom) for Romanian airports and airline.
- Coordinating multi-stakeholder delivery under time and resource constraints
Romanian Ministry of Defence + Ministry of Internal Affairs
Security systems, Building Automation System, PKI for the Ministry of Defence and Ministry of Internal Affairs.
—
Security systems, Building Automation System, PKI for the Ministry of Defence and Ministry of Internal Affairs.
- Simultaneous compliance with NIST frameworks across programme scope
Helinick IT strategy, roadmap & ERP selection
Current-state assessment, IT strategy and roadmap. Evaluation and selection of new ERP. Reorganisation of Technical Services and Applications teams. Annual IT business plan and budget. System & networking administration. Database design (Windows / Linux / UNIX). Cyber investigations, computer forensics, vulnerability assessments and incident response.
US$200K+ Y1 OPEX savings · US$150M+ annual budget · 35 projects on time / on budget
Current-state assessment, IT strategy and roadmap. Evaluation and selection of new ERP.
- Legacy system integration and ERP transition with zero tolerance for business continuity disruption
References, certifications and recognitions available upon request. Engagement-confidential metrics and case-study detail available for qualified mandates. Contact for advisory mandates →