My path into security began about 15 years ago, when instead of following my aerospace degree, I decided to try turning my hobby, information security, into my work.
I started in offensive security: researching vulnerabilities, doing pentests, and digging into complex systems and devices. Over that time I received acknowledgments from international companies for contributing to their security.
Until 2023, I worked at companies focused on offensive security. At some point, though, I realized I wanted to understand what happens after a vulnerability is found: how products, processes, and approaches to protection change.
That led me to Yandex, where today I lead the cybersecurity teams for Alice, Autonomous Transport, and, of course, our lovely robots.
I also spent 6 years writing a regular column and articles for Xakep, as well as for company blogs. I still write for industry publications, maintain this personal blog, and run the Telegram channel @dukebarmanpro.
I am a geek: I know my way around Star Wars and Warcraft lore, I love technology, and I like figuring out new things. That was how it went with Android device and application security when Android had just appeared and it was not yet clear how all of it should be protected. I wanted to dive into that field and, over time, became a specialist in it.
A similar stage is happening now with AI. I am interested again in being where the technology is still taking shape, the risks are not fully understood, and security should be built in from the beginning instead of catching up after the fact.
This site is my personal archive of essays and notes.
