Founder involvement
Ivan remains directly involved in discovery, technical review, prioritization, workshops, and final recommendations.
Bulwark Advisory is a founder-led Product Security practice for startups, scale-ups, and growing software companies that need credible security depth without building a large in-house function first.
Ivan Piskunov is a cybersecurity and Product Security leader with more than 15 years of experience across technical security, engineering enablement, cloud and platform security, and security leadership.
His background spans Product Security, Application Security, DevSecOps, cloud, and platform environments across regulated and fast-moving organizations, including healthcare, retail, banking, fintech, and digital-asset ecosystems.
He is strongest where security has to become operational: turning architecture and attack paths into practical controls, improving the signal-to-noise ratio of security tooling, structuring Product Security programs, and translating technical risk into priorities leadership and engineering teams can act on.
Earlier offensive and systems-security work provides adversarial context. The commercial focus today is deliberately narrower: securing how software products are designed, built, released, and operated.
The value is not a large bench of junior consultants. It is direct access to senior Product Security judgment, supported by focused tooling and specialist expertise when the scope requires it.
Ivan remains directly involved in discovery, technical review, prioritization, workshops, and final recommendations.
Automated tooling can provide breadth. Architecture, attack paths, business context, and engineering tradeoffs determine what actually matters.
Controls are designed around how teams ship software — with practical ownership, useful gates, and less security theater.
Start with the smallest scope that can answer the decision. Expand only when additional work creates measurable value.
Findings are translated into risk, remediation effort, security debt, release confidence, and leadership-ready decisions.
Books, open technical work, research, and a public Product Security knowledge base let clients inspect the methodology before engaging.
The profile combines hands-on security depth with program design, economics, and executive communication.
Specialist-level technical education in information security.
Graduate background in economics and financial accounting, supporting risk and investment decisions.
Business coursework and executive education completed through Harvard Business School Online.
AWS Security Specialty, Google Cloud Professional Cloud Security Engineer, CEH, CCNA, MCSA, and LPIC-1.
A focused mix of engineering depth, program structure, and risk translation.
Operating models, ownership, roadmaps, maturity, risk acceptance, metrics, and leadership reporting.
Threat modeling, architecture review, secure development workflows, developer guidance, and practical testing strategy.
SAST, DAST, SCA, secrets, IaC, container security, CI/CD gates, release evidence, and tooling optimization.
AWS, Kubernetes, IAM, containers, infrastructure-as-code, platform controls, and cloud-native attack paths.
Security debt, remediation velocity, control adoption, business impact, budget context, and executive decisions.
Security Champions, engineering partnership, practical ownership, and security programs teams can actually use.
Public artifacts show how the work is framed before a private engagement begins.
Operating models, Secure SDLC, architecture, DevSecOps, cloud, Kubernetes, supply chain, metrics, and leadership.
Explore ↗ Published bookTechnical security guidance spanning attack surface, controls, hardening, and practical scenarios.
View publication ↗ Applied researchProduct Security for EVSE and software-defined mobility across cloud, APIs, identity, firmware, OTA, and operations.
Preview ↗Bulwark Advisory can start with a focused assessment and expand only when the problem justifies it.