Security & Resilience¶
Achieving PCI-DSS Compliance
Implemented CIS hardening standards and internal security policies to meet PCI-DSS requirements across enterprise environments.
My Role
Role: Security & Compliance Lead Scope: CIS hardening, vulnerability management, and governance across enterprise environments Ownership: standards → enforcement → continuous compliance
Key Contributions
- Applied CIS benchmarks and infrastructure hardening across servers
- Added vulnerability management and security monitoring (Wazuh)
- Established policy enforcement and governance processes
Lessons Learned
Compliance is a continuous process, not a project. Automation and hardening standards make it sustainable.
Building Business Continuity & Disaster Recovery
Implemented a backup and DR strategy with Veeam — replicating virtual machines to a DR site plus on-site backups, with recovery that is actually tested.
My Role
Role: Business Continuity Lead Scope: backup architecture (Veeam), DR-site replication, recovery testing Ownership: design → deployment → tested recovery
Key Contributions
- Deployed Veeam Backup & Replication — VM replication to DR and on-site backups
- Built and exercised recovery procedures
Lessons Learned
Backups without restore tests are just hope. Test your DR regularly or it won't work when you need it.