About Bulwark Advisory

Senior Product Security judgment, directly from the founder.

Bulwark Advisory is a founder-led Product Security practice for startups, scale-ups, and growing software companies that need credible security depth without building a large in-house function first.

15+ years in cybersecurityTechnical + strategicRemote-first · worldwide
Founder-led by design

One senior expert from scoping to security decisions.

Ivan Piskunov is a cybersecurity and Product Security leader with more than 15 years of experience across technical security, engineering enablement, cloud and platform security, and security leadership.

His background spans Product Security, Application Security, DevSecOps, cloud, and platform environments across regulated and fast-moving organizations, including healthcare, retail, banking, fintech, and digital-asset ecosystems.

He is strongest where security has to become operational: turning architecture and attack paths into practical controls, improving the signal-to-noise ratio of security tooling, structuring Product Security programs, and translating technical risk into priorities leadership and engineering teams can act on.

Earlier offensive and systems-security work provides adversarial context. The commercial focus today is deliberately narrower: securing how software products are designed, built, released, and operated.

The Bulwark approach

Boutique by size. Senior by default.

The value is not a large bench of junior consultants. It is direct access to senior Product Security judgment, supported by focused tooling and specialist expertise when the scope requires it.

01

Founder involvement

Ivan remains directly involved in discovery, technical review, prioritization, workshops, and final recommendations.

02

Deep technical context

Automated tooling can provide breadth. Architecture, attack paths, business context, and engineering tradeoffs determine what actually matters.

03

Engineering-friendly security

Controls are designed around how teams ship software — with practical ownership, useful gates, and less security theater.

04

Right-sized delivery

Start with the smallest scope that can answer the decision. Expand only when additional work creates measurable value.

05

Business-aware risk

Findings are translated into risk, remediation effort, security debt, release confidence, and leadership-ready decisions.

06

Proof in public

Books, open technical work, research, and a public Product Security knowledge base let clients inspect the methodology before engaging.

Background & credentials

Technical foundation. Leadership context.

The profile combines hands-on security depth with program design, economics, and executive communication.

EducationInformation Security

Specialist-level technical education in information security.

Business contextEconomics & Finance

Graduate background in economics and financial accounting, supporting risk and investment decisions.

Executive learningHBS Online

Business coursework and executive education completed through Harvard Business School Online.

Selected credentialsCloud & Security

AWS Security Specialty, Google Cloud Professional Cloud Security Engineer, CEH, CCNA, MCSA, and LPIC-1.

Where Ivan is strongest

Product Security across the software lifecycle.

A focused mix of engineering depth, program structure, and risk translation.

01

Product Security programs

Operating models, ownership, roadmaps, maturity, risk acceptance, metrics, and leadership reporting.

02

AppSec & Secure SDLC

Threat modeling, architecture review, secure development workflows, developer guidance, and practical testing strategy.

03

DevSecOps & delivery

SAST, DAST, SCA, secrets, IaC, container security, CI/CD gates, release evidence, and tooling optimization.

04

Cloud & platform security

AWS, Kubernetes, IAM, containers, infrastructure-as-code, platform controls, and cloud-native attack paths.

05

Risk translation

Security debt, remediation velocity, control adoption, business impact, budget context, and executive decisions.

06

Security culture

Security Champions, engineering partnership, practical ownership, and security programs teams can actually use.

Work directly with the founder

Bring the product, the risk, or the decision.

Bulwark Advisory can start with a focused assessment and expand only when the problem justifies it.

Discuss a project →