Clients

Vaclav advised us on security for our iGaming platform. He's one of the few security experts I've met who can go deep into technical details and then zoom out to design processes that scale across a 500-person engineering org. What made him particularly effective in our case is his combination of security expertise and real anti-fraud experience — in iGaming that overlap is critical and hard to find. He understood our threat landscape without lengthy explanations and gave us a clear, actionable plan.
Igor Poltorak
Igor Poltorak
Vice President of iGaming
Client
Vaclav helped xAID as an independent advisor right after our pivot — we needed ISO 27001 readiness and to pass KYC to expand the business. He took ownership of the compliance project, moved fast, and guided our leadership through every key decision. For a startup with no in-house security team, having someone who combines deep expertise with a practical, no-overhead approach was exactly what we needed. Happy to recommend.
Kirill Lopatin
Kirill Lopatin
Founder & CEO, xAID
Client
ISO 27001 certification was an important milestone for our company, as several key clients required it. Vaclav led the initiative end-to-end: helped us define a pragmatic scope aligned with our data-focused business, prioritized controls based on our actual risk profile, and guided us smoothly through the audit process. We successfully passed the audit on the first attempt, and the framework he helped establish remains practical and sustainable for our team.
Mikhail Lipkovich
Mikhail Lipkovich
CTO & Head of AI/ML (PhD)
Client
Vaclav led a security audit of our online services — and he really delivered. He found vulnerabilities, explained everything clearly, and after his recommendations we were able to fix everything quickly. Communication was easy and straightforward: any question could be resolved fast, no unnecessary formalities or delays. It's a pleasure to work with him — both professionally and personally. We'll definitely reach out again and can confidently recommend him.
Denis Zakharov
Denis Zakharov
CTO at ykt.ru
Client
I would like to thank Vaclav for helping to improve the practical information security of Beeline digital services.
Alexey Volkov
Alexey Volkov
VP, CISO — Beeline
Client
Highly recommend Vaclav for cybersecurity advice — clear, practical, and extremely helpful.
Damir Ismakov
Damir Ismakov
Engineer, xAID
Client

Direct Manager & Company Peers

As CTO, I worked with Vaclav when he led security. He is highly proactive: he spots issues early, brings concrete options, and moves things forward without needing constant input. Vaclav is also fully autonomous in building security processes from scratch — he can align stakeholders, make pragmatic trade-offs, and deliver real improvements in how security works with engineering. On a personal note, it was genuinely great working with him — clear, reliable, and easy to partner with.
Michil Androsov
Michil Androsov
CTO, inDrive
now Co-Founder / CTO, Callie Care
Colleague
Working with Vaclav means working with a highly motivated person who is full of ideas for improvement. His proactivity and willingness to interact with any stakeholders far beyond the usual circle of technical specialists allows information security to function as a full-fledged business partner that anticipates and responds to real business challenges. Vaclav is able to take into account the maturity of the company, available resources, and key changes, which allows him to be a real driver of improvement rather than an abstract expert.
Denis Rybin
Denis Rybin
Application Security TechLead, inDrive
now Director of CyberSecurity, inDrive
Colleague
I led the AppSec team at inDrive reporting to Vaclav as CISO for over two years. He changed how I think about running security — not just what to do, but how to organize it. Using Team Topologies and Kanban STATIK for security teams, introducing Security Error Budget so engineers stopped chasing developers with daily "when will you fix this?" reminders, scaling the team without slowing down — I picked all of this up from him. We built the Security Architecture Review process together, and Vaclav's expertise is what made it work well enough for engineers to actually trust it. The team wouldn't have achieved what we did without his leadership — it's one of those rare cases where one person's direction truly shaped the result. Beyond our direct work together, I've watched Vaclav's practices — especially Security Error Budget and his approach to centralized vulnerability lifecycle management — get adopted across the industry after his HighLoad++ talk. I applied them myself at Yandex. The way he does AppSec is ahead of where most of the market is today, and the fact that these methods spread to other companies makes the whole field stronger. I'd be glad to work with him again and hope we get the chance someday.
Nikita Medvedev
Nikita Medvedev
AppSec Tech Lead, inDrive
AppSec Lead, Yandex
now Red Team & TI Lead, T-Bank
Colleague
Vaclav was a key partner on security and architecture. He actively helped build and sustain our architecture committee, bringing structure, consistency, and practical security input that fit how engineering actually works. Vaclav also created the Security Architecture Review process. It materially improved the quality of our designs and helped us avoid costly rework later by catching architectural security issues early. He occasionally went beyond pure security and supported teams on availability questions during SecArchReviews — rare, but always valuable and pragmatic. A special mention is his depth in “security-in-depth” design for proactive GDPR alignment, including crypto-shredding. In our multi-region active-active AWS architecture, Vaclav ensured the right approach to issuing and validating user JWTs across regions — making the design both secure and practical for real-world operations.
Alexander Lisachenko
Alexander Lisachenko
ex-inDrive
now Senior Director of Backend Development, TradingView
Colleague
I had the opportunity to work alongside Vaclav for several years at inDrive. During a period of rapid growth, I was building delivery and operating processes across Product and Engineering while Vaclav was building the company's security function from the ground up. What stood out to me was his ability to design security practices that worked with the organization rather than against it. Vaclav consistently found the balance between strong security standards and the speed required by a hypergrowth business. His approach was grounded in how teams actually work. As a result, security became part of the operating model rather than an external control function. Adoption came from understanding and trust rather than enforcement. Vaclav understood that effective security is not only about controls and policies, but also about processes, incentives, and collaboration. This allowed him to build a security function that scaled with the company while remaining trusted by product and engineering teams. I would highly recommend Vaclav to any organization looking for a security leader who can combine technical depth with a pragmatic approach to execution and organizational change.
Olya Kachalina
Olya Kachalina
Director of PMO
ex-inDrive, ex-Microsoft
Colleague
Vaclav transformed how my R&D organization thinks about security. Instead of bolting it on as a separate gate, he embedded AppSec and Pentest directly into our development rhythm — lightweight architecture reviews, actionable feedback, zero bureaucratic overhead. Having seen heavy-weight security processes in enterprise environments, I can say Vaclav's approach is refreshingly different. Teams actually trust and use it because it fits their context and velocity. His Security Error Budget metric became a real decision-making tool for me — one dashboard to see posture across all teams and allocate resources where they matter most. What sets Vaclav apart is his forward thinking. He's constantly exploring how AI can strengthen security — and equally important, how the rise of AI agents creates entirely new threat surfaces. He doesn't wait for incidents; he's already working on what's next.
Egor Miasnikov
Egor Miasnikov
Vice President of R&D, 01.Tech
Colleague
Vaclav has exceptional expertise in incident investigation and response process design. His direct technical contribution to SOC operations — not just oversight, but real investigative depth — helped our team navigate serious challenges and deliver faster, higher-quality results. He builds processes with zero busywork. Every workflow exists for a reason, and resources go where they create the most business value. Vaclav brought the expertise and made the business case for migrating to Splunk — which directly improved our analysts' speed and alert quality. As a leader, Vaclav stands out in how he handles the stress and uncertainty that comes with security work. Even during the hardest incidents, he sets the right tone for the team and keeps people from burning out. His management approach is structured and consistent: regular 1-on-1s across the hierarchy, OKRs and KPIs for teams, clear personal accountability for outcomes. This framework is what allows a security team to achieve more with the same resources.
?
Hidden
SOC Tech Lead, 01.Tech
Colleague
At City-Mobil Vaclav was one of the key people behind our security function during a period of rapid growth into 60+ cities. What I noticed as CEO is that security worked — we had no major incidents, the team operated efficiently on a lean budget, and it never became a blocker for the business. That combination is harder to achieve than it sounds, especially at our pace. Vaclav is someone who gets things done quietly and reliably, which is exactly what you want from security.
Vitaly Bedarev
Vitaly Bedarev
CEO, City-Mobil
now Operational Director, Dwelly
Colleague
I worked with Vaclav at Citymobil where his Common Security Pipeline was the backbone of our shift-left security. The architecture did its job well — reliable tooling, easy integration, and centralized findings in DefectDojo instead of chasing results across repos. When I moved to VK, that same approach let me get security scanning up and running across 1,000+ repositories fast, with early proof that the model works and delivers value. As we scaled further, we hit DefectDojo's limits and eventually rebuilt everything from scratch into what became VK Security Gate. But that's exactly the point — Common Pipeline was never meant to be the final product. It gave us a fast launch, real proof of value, and enough lessons to know what to build next.
Anatolii Kovalenko
Anatolii Kovalenko
Security Engineer, Citymobil
now Teamlead of Security Gate team, VK
Colleague

Industry Peers

I've worked with Vaclav across several dimensions — as a Program Committee member, as a podcast guest, and as a fellow industry professional I regularly exchange ideas with on complex technical and security challenges. What sets him apart is his ability to reason about security as a practical engineering and business problem, quickly moving from abstract discussion to concrete decisions, trade-offs, and execution. I highly value these conversations and consider him a strong, trusted peer.
Maxim Mošarov
Maxim Mošarov
CEO/CISO/CTO, Security Expert
Industry Peer
Vaclav is one of the top experts in his field, staying abreast of trends and possessing a deep understanding of modern practices and processes. He is a thought leader who regularly shares his insights and experiences, contributing significantly to the DevSecOps community. His expertise and commitment to advancing security practices make him a valuable asset to any organization. With over ten years of experience across AppSec, InfraSec, and DevSecOps, he tackles security challenges with a holistic perspective.
Igor Kurochkin
Igor Kurochkin
Expert at Enabling.team
Industry Peer
At Security Code I needed to build DevSecOps processes that would scale to thousands of repositories without drowning in per-repo MRs and approvals. Vaclav's Common Security Pipeline was the right foundation: simple parent-child architecture, proven open-source tools, easy CI/CD integration, and — critically — a centralized approach where all findings land in DefectDojo instead of being scattered across individual repos. We adapted it to our stack and got real security coverage running fast. Years after his ZeroNights 2021 talk, the core design still holds up — I kept developing the approach and presented my own results at HighLoad++ 2024. His work helped us achieve tangible security results in a short time. Thank you for the contribution to the industry.
Alexander Melnikov
Alexander Melnikov
Lead Application Security Specialist, Security Code
now DevSecOps Team Lead, Wildberries
Industry Peer
I've worked with Vaclav across multiple companies as an external security partner. Every time, his teams stood out — well-organized, fast, and focused on what actually matters. That's not something you see often in this industry. It's not just about compliance and rubber-stamping audit reports; his approach is practical and focused on real risks and security impact, while optimizing resources. Vaclav builds mature security functions without throwing money at the problem. Through repeat engagements and continuous processes, I've seen firsthand how quickly security maturity grows under his leadership. The progress between cycles is tangible. His expertise and well-structured processes are visible even from the outside — clear communication, no wasted effort.
Omar Ganiev
Omar Ganiev
External security partner
Web3 & Fintech security
Industry Peer
With Vaclav I can discuss security org problems that most people either oversimplify or overcomplicate: how to structure AppSec in a company that doubles engineering headcount every year, where Team Topologies actually works for security — and where it doesn't, how to design architecture review without it becoming a bottleneck. He thinks in operating models, not checklists, and backs it up with real results from building security programs at scale. Our conversations have directly influenced how I structure my own team.
Alexander Khamitov
Alexander Khamitov
Head of Product Security, Wildberries
Industry Peer
Vaclav delivered talks twice at DevOops, the conference where I act as a member of the Program Committee. I had the privilege to curate Vaclav's talks, helping to prepare them and supporting him during the conference. In both cases he demonstrated outstanding technological expertise coupled with very high presentation skills. This allowed him to attract and bring value to the very demanding audience of the conference attendees. His talks were always in the top list of the feedback ratings. For all those seeking an expert capable of explaining complex things in a simple way — seek no further, Vaclav will be your guy.
Alexey Akopyan
Alexey Akopyan
Program Committee, DevOops
Senior Engineering Manager
Industry Peer

You can verify the reviews on my LinkedIn. All reviews were received on LinkedIn and are real. To avoid overloading LinkedIn, some may be hidden. If you need to verify a review, contact me and I will enable all necessary reviews.

Some reviews are displayed anonymously at the author’s request. Details may be disclosed upon additional request to the portfolio owner, at their discretion.