Information security portfolio

Milos
Dimitrijevic

Information Security Officer

Security Governance · Risk Management · Infrastructure Security · Compliance

About / Security profile

Bridging policy, risk and implementation

I combine hands-on infrastructure experience with information security governance, risk management, regulatory responsibilities, technical security controls, awareness training and security documentation.

My work connects business requirements and regulatory expectations with practical controls across identity, endpoints, cloud platforms, secure remote access and internal processes. A background in quality engineering adds a structured approach to audits, risk mitigation, documentation, problem solving and continuous improvement.

Areas of responsibility

What I do

Responsibilities lead; technologies support them.

01

Security Governance & Risk

Risk identification, assessment, treatment, monitoring and security decision support.

02

Compliance & Audit Readiness

Regulatory responsibilities, control evidence, documentation and audit preparation.

03

Technical Security

Security control implementation, small-scale penetration testing and technical review.

04

Identity & Access Management

Microsoft Entra ID, MFA, Conditional Access, OAuth/SSO and group-based authorization.

05

Endpoint Security

Endpoint policy, device control, threat prevention, Intune and security tooling.

06

Infrastructure & Cloud Security

Secure administration across Linux, virtualization, Microsoft 365, Azure, GCP and AWS.

07

Security Awareness & Training

Tailor-made employee training, condensed briefings and practical awareness material.

08

Policies & Documentation

Security policies, procedures, risk records, technical guides and control documentation.

Selected security initiatives

Security work in practice

Sanitized case studies focused on responsibility, approach and control outcomes.

01

Endpoint security

Endpoint Security Modernisation

Challenge
Improve endpoint consistency, visibility and protection across managed devices.
My responsibility
Administration, policy configuration, deployment support and operational maintenance.
Approach / solution
Standardized endpoint controls and device management through centrally administered platforms.
Security controls
Device compliance, endpoint policy, threat prevention and controlled application execution.
Technologies used
Microsoft Intune, Defender, ThreatLocker, Trend Micro.
Outcome
A more centralized endpoint-security operating model with clearer control ownership.
02

Identity security

Identity & Access Security

Challenge
Manage access consistently across cloud services and the user lifecycle.
My responsibility
Identity administration and implementation of access controls.
Approach / solution
Centralized identities, strengthened authentication and aligned access with business groups.
Security controls
MFA, Conditional Access, group-based authorization and access review processes.
Technologies used
Microsoft Entra ID, Microsoft 365, Google Workspace.
Outcome
Stronger identity-based access control and clearer administration paths.
03

Secure access

Entra OAuth Remote Access

Challenge
Provide remote connectivity governed by centralized organizational identity.
My responsibility
Design and implementation of the identity-controlled remote-access solution.
Approach / solution
Integrated VPN authentication with Microsoft Entra ID through OAuth2 and mapped access to authorized groups.
Security controls
Centralized authentication, group authorization, encrypted remote access and controlled provisioning.
Technologies used
OpenVPN, Microsoft Entra ID, OAuth2, Ubuntu, GCP.
Outcome
Remote access tied to centrally managed identities and authorization groups.
04

Human risk

Security Awareness Programme

Challenge
Replace generic online material with relevant, understandable security education.
My responsibility
Programme design, material preparation and training delivery.
Approach / solution
Built tailored modules covering common threats, safe behavior and response actions.
Security controls
Awareness training, role-relevant guidance and repeatable learning material.
Technologies used
In-house web content and presentation material.
Outcome
A reusable security-awareness programme aligned with the working environment.
05

Risk

Risk Management & Assessments

Challenge
Translate security threats into documented, reviewable business risks.
My responsibility
Risk identification, assessment, treatment planning and ongoing review.
Approach / solution
Evaluated likelihood and impact, recorded controls and tracked residual risk.
Security controls
Risk register, ownership, treatment actions and scheduled review.
Technologies used
Structured risk documentation and supporting technical evidence.
Outcome
A consistent basis for risk decisions and governance follow-up.
06

Assurance

Documentation & Audit Readiness

Challenge
Maintain practical security documentation that also supports audit and regulatory review.
My responsibility
Define, maintain and organize policies, procedures and control evidence.
Approach / solution
Created structured documentation mapped to operational responsibilities and review needs.
Security controls
Policies, procedures, access guidance, continuity material and audit evidence.
Technologies used
Google Workspace, Microsoft 365, GLPI and internal knowledge systems.
Outcome
More accessible control documentation and a clearer audit-preparation process.

Risk & governance

From threat to accountable treatment

Security governance turns technical observations into decisions, ownership and review.

  • Risk identification and assessment
  • Risk treatment and control selection
  • Risk monitoring and periodic review
  • Policies, procedures and control ownership
  • Audit preparation and regulatory responsibilities

Sanitized example

ThreatCredential phishingAssetCloud accountInitial riskHighControlsMFA · CA · trainingResidual riskReduced / monitored

Likelihood and impact are evaluated before treatment; residual risk is documented and reviewed. This example contains no company data.

Policies, procedures & security documentation

Documentation that supports operations and assurance

Security PoliciesRisk AssessmentsIncident Response ProceduresAccess Control ProceduresBusiness Continuity / Disaster RecoverySecurity Awareness MaterialTechnical Security GuidesAudit / Control Documentation

Technical environment

Platforms supporting the security programme

Security / Identity

Microsoft Entra ID · Conditional Access · MFA · OAuth/SSO · OpenVPN

Endpoint Security

Microsoft Defender · ThreatLocker · Trend Micro · Intune

Infrastructure

Linux · Proxmox · VMware · Docker · Dell servers

Cloud / Productivity

Microsoft 365 · Google Workspace · Azure · GCP · AWS

Automation

PowerShell scripting · troubleshooting · controlled deployment

Career

Progression into information security

Technical Support / NetworkingQuality & Process EngineeringIT OfficerInformation Security Officer

2023–Present

Information Security Officer

Energy Casino / LV Bet · Gzira, Malta

  • MGA Key Function Holder
  • Risk assessments and management
  • Policies, documentation and audit preparation
  • Security awareness training
  • Small-scale penetration testing

2019–2023

IT Officer

Energy Casino / LV Bet · Gzira, Malta

  • Identity, endpoint, cloud and infrastructure administration
  • Microsoft 365, Entra, Intune and Google Workspace
  • Servers, virtualization, Docker and PowerShell
  • Security tooling and operational controls

Earlier career

Quality Engineering, QA & Networking

Experience in risk mitigation, audits, structured problem solving, process documentation and continuous improvement created a natural foundation for information security.

Contact

Let’s discuss security, governance and resilient infrastructure.