
Martins Akermanis
Verified Expert in Engineering
Cybersecurity Engineer and Developer
Riga, Latvia
Toptal member since February 19, 2026
Martins is a security leader with over 20 years of experience building enterprise security programs from the ground up. Martins combines technical depth, including zero-trust architecture, SIEM/XDR, and AI-driven automation, with strategic vision and compliance expertise. His professional background includes 13 years of military service, specializing in executive protection and risk management, as well as a law degree in cyber warfare and AI humanitarian law.
Portfolio
Experience
- Incident Response - 5 years
- Security Architecture - 5 years
- Cloud Security - 4 years
- SIEM - 4 years
- Identity & Access Management (IAM) - 4 years
- ISO Compliance - 3 years
- PCI Compliance - 3 years
- Zero Trust - 3 years
Preferred Environment
OWASP Top 10, Threat Modeling, Risk Management, Infrastructure as Code (IaC), GitOps, Vulnerability Management, Penetration Testing, Zero Trust, Security Information and Event Management (SIEM), Compliance
The most amazing...
...solution I've built is an AI-driven security platform that reduced investigation time by 70% by automating alert triage and executive reporting.
Work Experience
Cybersecurity Operations Engineer
Gravity Team
- Deployed CrowdStrike Falcon Insight XDR and Elastic Security SIEM, achieving full endpoint and log visibility across more than 200 enterprise assets.
- Replaced legacy VPNs with Zscaler Zero Trust architecture (ZIA/ZPA) and implemented PAM, reducing the external attack surface by 60%.
- Established GitOps-based configuration management with Terraform and Ansible, enabling compliance as code across all environments.
- Built an AI-assisted security operations platform using Claude Code agents, reducing security investigation time by approximately 70%.
- Led adversary emulation exercises using MITRE Caldera, mapping coverage gaps against ATT&CK and hardening over 15 detection rules.
- Facilitated STRIDE threat modeling sessions with engineering teams, identifying more than 30 design-level risks before production deployment.
- Automated executive security briefings and vulnerability triage workflows using AI agents, saving over eight hours of manual reporting weekly.
Cybersecurity Specialist
Proxy Live Solutions
- Implemented Elastic Security SIEM with custom integrations and ILM policies, centralizing monitoring for more than 1,500 devices across three countries.
- Automated vulnerability management by integrating Netbox and Greenbone APIs, eliminating manual Excel tracking with real-time dashboards.
- Conducted more than 20 penetration tests encompassing web, API, and WebSocket, covering 100% of the game portfolio before each production release.
- Executed deepfake proof-of-concept attacks and MFA bypass simulations using Evilginx 3.0, demonstrating real-world phishing risks to leadership.
- Supported bimonthly ISO 27001 and PCI DSS compliance audits across a regulated multi-country iGaming environment.
- Managed security operations for more than 1,500 endpoints across multiple Kubernetes clusters, IoT, and multi-cloud infrastructure with a 24/7 uptime SLA.
Penetration Tester
Wearedots
- Automated phishing campaign infrastructure deployment with Ansible and Azure, reducing setup time from one day to 10 minutes, which is a 98% reduction.
- Executed more than 20 social engineering engagements, including phishing and smishing campaigns, measurably improving client security awareness scores.
- Performed OWASP Top 10 penetration tests for more than five client web applications, identifying critical vulnerabilities before public exposure.
- Developed custom phishing templates capable of bypassing enterprise email filters, demonstrating realistic attack scenarios to executives.
System Manager
Tele2
- Managed SAP SuccessFactors operations for over 1,000 users across Latvia, Lithuania, Estonia, and Sweden with 99.9% system uptime.
- Maintained GDPR compliance for cross-border HR data processing across four countries, coordinating with global SAP consultants on incidents.
- Planned and coordinated complex release management cycles across multiple countries, minimizing operational risk during system updates.
Infrastructure Engineer
Smaser AG
- Maintained high-availability Nutanix infrastructure supporting mission-critical connected car services for BMW, Rolls-Royce, and Volvo.
- Implemented Ansible automation and monitoring with CheckMK and the ELK Stack for approximately 100 servers, reducing manual effort and improving incident response.
- Executed zero-downtime software deployments for JBoss and Docker-based microservices across production environments.
Developer
Codelex
- Built a full-stack emergency response app with React Native, Spring Boot, and PostgreSQL, automating patrol dispatch to the nearest unit.
- Developed a cross-platform mobile application, enabling security guards to trigger real-time alerts directly from the field.
- Created a centralized React. monitoring dashboard providing live situational awareness for security dispatch operations.
Experience
Security Orchestration Platform with MCP Agents
The system exposes CrowdStrike Falcon, Elastic Security SIEM, and internal asset inventories as MCP servers, enabling Claude Code agents to autonomously query alerts, correlate indicators across data sources, and draft incident reports.
I also built specialized MCP servers for each security tool: one for endpoint telemetry (CrowdStrike detections, device inventory), one for log correlation (Elastic queries, saved searches, detection rules), and one for asset context (ownership, criticality, network topology).
The orchestration layer routes incoming alerts to the appropriate agent chain encompassing triage, enrichment, and reporting, reducing mean investigation time from 45 minutes to under 12 minutes per alert. The platform also generates weekly executive security briefings by aggregating trends across all connected data sources. It was built entirely in Python with a modular architecture that allows new MCP servers to be added as the security stack evolves.
Automated Vulnerability Management Platform
The platform integrates Greenbone (OpenVAS) for vulnerability scanning with Netbox as the single source of truth for asset inventory, automatically enriching each vulnerability finding with asset ownership, business criticality, network zone, and compliance scope (PCI DSS vs general).
I also developed a Python-based GUI orchestration layer that schedules scans by asset group, deduplicates findings across scan cycles, calculates risk scores weighted by asset criticality and exploit availability, and pushes results into Elastic Security for visualization.
In addition, I built Kibana dashboards showing vulnerability trends by business unit, SLA compliance for remediation timelines, and aging reports for overdue findings. I added Ansible playbook integration for one-click remediation of common misconfigurations (expired certificates, weak SSH ciphers, missing patches).
The system reduced the vulnerability management cycle from a two-week manual process to a continuous, near-real-time operation.
Modular Phishing Simulation Framework
The framework uses Ansible playbooks to provision Azure VMs, configure Postfix mail servers with valid SPF/DKIM/DMARC records, deploy GoPhish with client-specific templates, and set up the Evilginx AiTIM framework for advanced credential-harvesting scenarios.
I built a Python-based template engine that generates phishing emails by combining interchangeable components (configured in YAML files): sender personas, pretexts (IT helpdesk, HR policy, CEO urgent request), and payload types.
Each campaign automatically collects granular metrics and generates a branded PDF report with risk scores for each department.
I also added callback detection to measure which employees reported the phishing attempt through proper channels.
The framework was used in 20+ client engagements, with infrastructure teardown fully automated post-engagement to eliminate operational residue. It reduced the engagement setup from a full day of manual configuration to a single Ansible command, completing in under 10 minutes.
Education
Master's Degree in Law, Lawyer Professional Qualification in Law and Justice Administration
Riga Stradins University - Riga, Latvia
Bachelor's Degree in Law in Law and Justice Administration
Riga Stradins University - Riga, Latvia
Certifications
Cybersecurity: Managing Risk in the Age of AI
Harvard University
Zscaler Digital Transformation Administrator (ZDTA)
Zscaler
Certified Information Systems Security Professional (CISSP)
ISC2
Zscaler Zero Trust Cyber Associate (ZTCA)
Zscaler
Microsoft Certified: Azure Fundamentals
Microsoft
Web Attack and Defence
NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE)
International Law of Cyber Operations
NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE)
Principles of Resistance in Modern Warfare
US Army Joint Special Operations University
Information Related Capabilities
US Army Joint Special Operations University
Skills
Tools
ELK (Elastic Stack), Elastic, Terraform, Ansible, Claude Code, NMap, SAP SuccessFactors, Grafana, Kibana
Paradigms
Automation, Penetration Testing, Security Orchestration, Automation, and Response (SOAR), Model Context Protocol (MCP), REST
Languages
Falcon, Python, JavaScript, HTML
Frameworks
OpenVAS, React Native, SPF
Platforms
Zscaler, Azure, CrowdStrike, Linux, Amazon Web Services (AWS), Burp Suite, Kubernetes, Google Cloud Platform (GCP), Docker, iOS, Android
Industry Expertise
Cybersecurity
Storage
Microsoft Entra ID, PostgreSQL
Other
Zero Trust, Security Information and Event Management (SIEM), IT Security, Security Architecture, SIEM, Incident Response, Security, SecOps, OWASP Top 10, Threat Modeling, Infrastructure as Code (IaC), GitOps, Vulnerability Management, Compliance, Cloud Security, Identity & Access Management (IAM), Detection Engineering, Red Teaming, Risk Management, General Data Protection Regulation (GDPR), Cyber Law, Artificial Intelligence (AI), Cyber Warfare, Autonomous Robots, Autonomous AI, Cyber Security Leadership, OT Security, Security Management, Zero Trust Network Access (ZTNA), ZIA, ZPA, ZDX, Web Security, IT Governance, Data Governance, Cloud, Information Warfare (IW), Okta, MITRE ATT&CK, NetBox, ISO 27001, PCI DSS, Evilginx, AiTM, Phishing Simulation & Analysis, Deepfake, Social Engineering, Internet of Things (IoT), Gophish, Vishing, Smishing, SAP, Management Systems, HRIS, System Administration, Data Privacy, Nutanix, Virtualization, PCI Compliance, ISO Compliance, Endpoint Detection and Response (EDR), NetBackup, APIs, DomainKeys Identified Mail (DKIM), DMARC
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring