
Roman Potapov
Verified Expert in Engineering
Security Architect and Developer
Charlotte, NC, United States
Toptal member since April 23, 2026
Roman is an expert security architect with 20+ years of experience in cloud security architecture, DevSecOps, threat modeling, and compliance. He designs resilient, scalable systems to protect people, data, and infrastructure across industries. Roman has architected multicloud solutions for Fortune 500 clients (Adobe, Cisco, Target) and fintech leaders (SMBC Group, Equifax), ensuring alignment with PCI DSS, GLBA, HIPAA, GDPR, FedRAMP, and NERC CIP.
Portfolio
Experience
- GRC - 20 years
- Compliance - 20 years
- IT Security - 20 years
- Internal Audits - 18 years
- Enterprise Security Architecture - 10 years
- PCI DSS - 8 years
Preferred Environment
Cursor AI, Cloud Security, Enterprise Security Architecture, Web Application Security (Web AppSec), Agentic Security, Security Information and Event Management (SIEM), Azure Cloud Security, GCP Security, AWS Cloud Security, GRC
The most amazing...
...work I've done is securing Fortune 500 companies with millions of users and small businesses with tight budgets, and writing security apps like secugent.ai.
Work Experience
Lead Security Compliance & GRC Consultant
Hub International
- Led enterprise SOC 2 and PCI DSS gap analyses, evaluating cloud posture controls and establishing automated security policy frameworks.
- Authored and operationalized enterprise security policies, control mapping procedures, and compliance standards aligned with SOC 2 Trust Services Criteria (TSC).
- Integrated SAST, DAST, and SCA tooling into DevOps workflows across Azure DevOps and GitHub using Boost, Snyk, and Rapid7 AppSec, championing shift-left security principles throughout the development lifecycle.
- Validated technical security controls and evidence streams across cloud workloads, ensuring full compliance readiness for external auditor review.
- Developed and deployed DevSecOps policies across Azure DevOps and GitHub environments, codifying security best practices into automated pipelines.
- Integrated Agentic AI Security (Claude) and authored policies governing security guardrails, agent privilege boundaries, prompt protection mechanisms, agent sandbox configurations, and generation-logging controls across diverse application portfolios.
- Led the strategic optimization of the GitHub Advanced Security ecosystem and Claude setup, fine-tuning AI tools for enhanced precision while reducing disruptions in developer workflows.
- Designed governance for Claude's autonomous skills, ensuring AI-generated code and pull requests adhered to enterprise security and quality benchmarks prior to human oversight.
- Deployed automated scanning with CodeQL, secret scanning, and dependency checks integrated into CI/CD pipelines, using AI-powered auto-fixes to streamline vulnerability remediation.
- Served as a technical advocate for development teams, clarifying complex security issues and facilitating secure adoption of agentic processes through collaborative guidance.
Senior Compliance Controls & Audit Architect
SMBC Group
- Mapped and implemented GRC control matrices across multi-cloud environments, utilizing automated evidence collection tools and logging platforms to maintain continuous compliance.
- Architected and deployed a secure GCP landing zone using Terraform, embedding infrastructure-as-code security best practices and compliance guardrails from inception.
- Conducted comprehensive cloud posture reviews and risk assessments leveraging AWS Security Hub and GuardDuty, identifying and remediating critical misconfigurations.
- Integrated SAST, DAST, and SCA tools into DevOps workflows on Azure DevOps and GitHub, reinforcing shift-left security across development teams.
- Spearheaded compliance gap remediations and risk assessments against strict regulatory standards, ensuring seamless audit trail validation against GLBA and PCI DSS.
- Implemented native guardrails via automated scans (CodeQL, Secret Scanning, Dependabot) in GitHub Actions pipelines, leveraging AI auto-remediation to expedite fixes.
Cloud GRC & FedRAMP/SOC 2 Assessment Lead
Adobe
- Architected compliance controls for a high-stringency FedRAMP / SOC 2 environment, enforcing least-privilege IAM governance, MFA attestations, and secrets management.
- Enhanced application security within the FedRAMP Azure environment by implementing SAST/DAST tooling and conducting manual security reviews to identify and remediate vulnerabilities.
- Built a DevSecOps pipeline on Azure DevOps grounded in shift-left principles, integrating security gates and automated scanning into every stage of the delivery lifecycle.
Security Architect/Engineer
Lending Club
- Developed cloud security architecture for AWS, deploying Wiz, Security Hub, and GuardDuty for continuous security monitoring and automated posture management.
- Performed application security assessments encompassing SAST, DAST, and penetration testing, driving remediation of vulnerabilities across banking applications.
- Automated cloud infrastructure security with Terraform and HashiCorp Sentinel, enforcing policy-as-code controls on AWS IAM and VPC configurations.
- Architected a secure landing zone and implemented shift-left security procedures within Azure DevOps pipelines.
- Assessed cloud compliance posture and hardened environments using CloudTrail and Splunk for continuous audit and detection.
- Educated development teams on secure coding practices through targeted workshops and knowledge-sharing sessions, fostering a security-first culture.
Security Architect/Engineer
Equifax
- Architected the migration of cloud security solutions to GCP, integrating firewalls, forward and reverse proxies, and BigID to ensure robust data protection and regulatory compliance.
- Secured application migrations to GCP by integrating SAST and DAST tools alongside manual security reviews to validate the security posture of migrated workloads.
- Designed cloud operations runbooks and implemented firewall rulebase projects in GCP, standardizing incident response and change management procedures.
- Automated application security monitoring using Datadog dashboards and alert configurations, reducing mean time to detection.
- Led credential security projects with CyberArk and SailPoint, strengthening privileged access management and identity governance across the enterprise.
Security Architect/Engineer
Finix
- Designed cloud security architecture for AWS and Azure, implementing Microsoft Sentinel for SIEM and building security dashboards for centralized visibility across hybrid environments.
- Established a full SDLC application security program incorporating SAST, IAST, and penetration testing for Java and React application stacks.
- Designed DevSecOps pipelines in CircleCI and GitHub, integrating automated security tooling into continuous integration and delivery workflows.
- Architected cloud-based incident response and recovery programs, deploying alerting solutions to ensure rapid detection and containment of security events.
- Built a data protection program encompassing encryption orchestration and compliance monitoring to safeguard sensitive data at rest and in transit.
- Reviewed and optimized cloud authentication policies in HashiCorp Vault, strengthening secrets management and access controls.
Security Architect/Engineer
Oportun
- Architected cloud security for AWS using Sumo Logic SIEM and Terraform-configured security solutions, establishing centralized logging and threat detection capabilities.
- Conducted SAST, DAST, IAST, and penetration testing for mission-critical applications, identifying and remediating vulnerabilities across production and pre-production environments.
- Designed cloud compliance measures aligned with PCI DSS requirements, deploying McAfee ePO and FireEye HX for endpoint detection and response.
- Integrated security into DevOps workflows using chaos engineering tools and Terraform configurations, stress-testing resilience, and validating security controls under adversarial conditions.
- Developed a Python-based user interface for BigID data security monitoring, enabling operational teams to visualize data classification and protection status.
- Supported cloud-wide encryption orchestration and BigID implementation for sensitive data discovery and governance.
Security Architect/Engineer
Perspecta
- Designed cloud security architectures for embedded systems serving federal agencies, integrating Terraform-based infrastructure-as-code security configurations.
- Secured embedded systems and applications built in Java, C++, and Python using SAST and DAST tooling and manual code reviews, ensuring compliance with federal security requirements.
- Architected cloud security monitoring with Splunk, developing custom detection content and correlation rules for advanced threat identification.
- Integrated DevSecOps practices into Jenkins pipelines and Kubernetes clusters, automating security validation across containerized workloads.
- Configured cloud and on-premises security appliances (firewalls and proxies) using Ansible and Chef, maintaining consistent security baselines across environments.
- Conducted statistical analysis of application security tools to benchmark detection efficacy and optimize tool selection.
Security Architect/Engineer
Cisco
- Architected cloud-based SOC infrastructure for global clients using Splunk and a proprietary security analytics platform, enabling real-time threat monitoring and incident triage.
- Developed a Python back end for automating application security rules and alerts within the proprietary platform, increasing detection coverage and reducing analyst workload.
- Performed threat modeling and created security playbooks for application monitoring, including deep packet analysis and protocol inspection.
- Monitored cloud-embedded systems and delivered security operations support for Fortune 500 clients across diverse industry verticals.
Security Architect/Engineer
Xcel Energy
- Architected security frameworks for industrial control systems (ICS) environments, ensuring compliance with NERC CIP standards and integrating LogRhythm SIEM for continuous monitoring.
- Implemented application security frameworks tailored to operational technology, bridging IT and OT security requirements.
- Secured embedded systems within power grid infrastructure, designing defense-in-depth protections for critical energy delivery components.
Security Architect/Engineer
Target
- Redesigned security architecture post-breach, deploying ArcSight and Splunk clusters for enhanced log correlation and threat detection across the enterprise.
- Redesigned application security runtime monitoring using Contrast Security, ArcSight, and FireEye to establish continuous application-layer threat visibility.
- Implemented secure network segmentation and private virtual networks, strengthening isolation of sensitive environments and reducing lateral movement risk.
Security Architect/Engineer
Anywhere
- Established an application security program incorporating SAST and DAST testing for real-estate platforms, embedding security validation into the release cycle.
- Supported secure UX development for customer-facing real-estate applications, ensuring security controls did not compromise user experience.
- Supported headquarters in application security risk estimation.
Experience
Agentic Security Web App
sellwhat.ai
Forcash
https://apps.apple.com/us/app/forcash-daily-spend-forecast/id6738464156Education
Master's Degree in Econometrics and Statistics
The Socio-Economics Institute - Saint Petersburg, Russia
Bachelor's Degree in Accounting and Statistics
Kabardino-Balkarskii State University - Nalchik, Russia
Certifications
BigID Expert
BigID
FedRAMP PMO 3PAO
FedRAMP
Certified Information Security Auditor
ISACA
Certified Internal Auditor
The IIA
Skills
Libraries/APIs
Bitbucket API
Tools
OWASP Zed Attack Proxy (ZAP), Checkmarx, GCP Security, Splunk, CircleCI, Jenkins, HashiCorp Vault, Sumo Logic, Terraform, NGINX, SailPoint, AWS CloudTrail, AWS IAM, BigID
Frameworks
TOGAF, COBIT 5, Django, LangGraph, Boost
Paradigms
DevSecOps, Penetration Testing, Azure DevOps
Platforms
Burp Suite, Rapid7, Orca Security, LogRhythm, CrowdStrike, Django CMS, Mobile
Languages
Python 3, Swift 6, TypeScript 5, Bicep, Jira Query Language (JQL)
Storage
Redis, PostgreSQL, PostgreSQL 10
Other
Agentic Security, Web Application Security (Web AppSec), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), Software Composition Analysis (SCA), Secure Containers, Enterprise Security Architecture, CSPM, CNAPP, Wiz Cloud Security Platform, Azure Cloud Security, AWS Cloud Security, PCI DSS, FedRAMP, Security Information and Event Management (SIEM), GRC, Security Audits, Compliance, Cloud Security, IT Security, Vulnerability Assessment, Application Security, Promptfoo, GitHub Actions, Snyk, SABSA, Palo Alto Prisma Cloud, Microsoft Defender XDR, Microsoft Defender Cloud, Microsoft Sentinel, ISO 27001, NIST 800 Series, NERC CIP, General Data Protection Regulation (GDPR), HIPAA, Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), HashiCorp Sentinel, Kubernetes Security, Nix, LangChain, Cursor AI, OWASP Top 10, Statistics, Machine Learning, Analysis, Internal Audits, Cost Analysis, Cost Accounting, Accounting Tools, Software Development Lifecycle (SDLC), Agile DevOps, Cloud Migration, Firewalls, CloudArmour, Incident Response, Data Security, Threat Modeling, Data Privacy, Embedded Security, IT Governance, Security Operations Centers (SOC), Managed Security Service Providers (MSSP), Threat Analytics, Security Incident Triage, Incident Management, Monitoring, SecOps, Critical Infrastructure, Solution Architecture, Industrial Control Systems (ICS), SCADA, Azure IoT, Cyber Forensics, Web Application Firewall (WAF), Risk, SEO Tools, Software Architecture, Business Analysis, Full-stack
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring