Cloud & Platform Security
Hardening we ran, access we governed, and the report we will not sell on its own
Volodymyr directed an AWS Security Improvement Program and the CIS Benchmark hardening inside it, at a high-volume transaction platform under NDA. The hardening he ran there cut the cloud configuration and security tooling bill by about 30%.
Zero Trust and IAM governance are where his security work starts. Max ran IAM governance at a top-5 US bank: AWS Identity Center access for 500+ banking users across 50+ AWS accounts, with provisioning down from days to hours. Neither the CIS Benchmark hardening nor the bank’s access model was a documentation exercise. A posture assessment ends in a written finding, and we turn down the ones where the architecture behind that finding is off limits to us, because a signed report is then the only thing left to hand over.
Volodymyr’s live engagement runs through Volonaris Security, his own consultancy. A financial-services client has him under contract to design their cloud security controls and to keep the posture defensible under the regulations they answer to. Separate work under Volonaris Security put CNAPP and CSPM platforms through a scored proof-of-value, sandbox accounts first and production last, and closed with an executive readout.