Kosta Koutros

CEO

Melbourne, Victoria, Australia12 yrs experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Led major incident response efforts effectively.
  • Achieved ISO 27001 certification for the organization.
  • Advised top-tier clients on cybersecurity strategies.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in risk management and compliance.

Contact

Skills

Core Skills

Information Security ManagementCybersecurityPenetration Testing

Other Skills

Security AssuranceSecurity PolicyVulnerability AssessmentOT SecurityIdentity and Access Management (IAM)CommunicationLeadershipSecurity OperationsIncident ManagementISO 27001Security AwarenessNetwork SecurityDisaster RecoveryLinux System AdministrationSystem Administration

Experience

Ctrl:cyber

5 roles

Head of (Cyber Security) Risk Operations Centre

Promoted

Jul 2025Present · 8 mos

  • Deliver regular executive-level briefings to different C-suite and SLT’s on cyber security maturity, risk posture, and strategic priorities.
  • Contribute to ISO/IEC 27001 audits, coordinating control evidence with external auditors and internal stakeholders to maintain continuous compliance and strengthen the organisation’s security posture.
  • Oversee IT risk management, contributing to the Cyber Risk Committee and driving risk treatment through stakeholder alignment and coordinated remediation across business units and system owners.
  • Design and implement DLP controls to safeguard confidential data from exposure through generative AI platforms (ChatGPT, Claude, Copilot), significantly reducing data exfiltration risk.
  • Lead, manage, and mentor a security team, driving operational excellence and capability uplift.
  • Lead major incident response efforts as the primary escalation point for Level 3 investigations, ensuring swift resolution and minimised business impact.
Security AssuranceSecurity PolicyVulnerability AssessmentOT SecurityIdentity and Access Management (IAM)Communication+20

Principal Cybersecurity Advisor

Mar 2023Jul 2025 · 2 yrs 4 mos

  • Serving as a Cybersecurity Consultant for top-tier clientele, tasked with:
  • Advising on cybersecurity strategies, processes, and technologies to align with client's strategic objectives.
  • Tailored consultation on the business impact of emerging zero-day threats to client organisations.
  • Optimizing cybersecurity expenditure by recommending priority investments that deliver greatest risk mitigation.
  • Leading initiatives to establish and uphold a resilient cybersecurity foundation spanning our company's network, systems, hardware, software, and cloud computing operations, fortifying defenses against emerging cyber threats.
  • Implement internal compliance in-line with ISO 27001, ISM, Essential 8, NIST & CIS Benchmarks
Security AssuranceSecurity PolicyVulnerability AssessmentOT SecurityIdentity and Access Management (IAM)Communication+20

Head of Cybersecurity

Promoted

Jan 2021Feb 2023 · 2 yrs 1 mo

  • Championed enterprise-wide governance and risk alignment by implementing compliance programs in line with ISO 27001, ISM, Essential 8, NIST, and CIS Benchmarks, culminating in the organisation achieving ISO 27001 certification and strengthening executive and board-level assurance.
  • Established and directed both the organisation’s internal Security Operations Centre and the customer-facing Managed SOC service, including Breach Support; designed and operationalised SOC & SIEM capabilities that safeguarded the enterprise and over 20 client organisations.
  • Coordinated major incident response efforts, serving as escalation point and strategic lead for Level 3 investigations.
Security AssuranceSecurity PolicyVulnerability AssessmentOT SecurityIdentity and Access Management (IAM)Communication+20

Head of Penetration Testing

Promoted

Oct 2019Dec 2020 · 1 yr 2 mos

  • Delivered risk remediation consultation directly to client C-Suite and senior technical leadership, translating complex technical findings into business-aligned recommendations.
  • Led a high-performing Penetration Testing team, providing executive-level consultation on the implications of bypassed controls and layered attack paths.
  • Maintained profitability and scalability of cybersecurity services while ensuring delivery quality met client board and regulator expectations.
  • Establishing the foundational architecture, processes and personnel requirements an efficient and scalable Security Operations Centre business unit
Security AssuranceSecurity PolicyVulnerability AssessmentOT SecurityIdentity and Access Management (IAM)Communication+20

Security Specialist & Penetration Tester

Oct 2018Sep 2019 · 11 mos

  • Initiated the organisation’s ISO 27001 alignment journey by developing core security policies and leading the first wave of technical control implementations, establishing the foundation for future certification.
  • Served as the organisation’s primary Cybersecurity Lead, acting as the central point of contact for all security matters; strengthened both operational defences and governance practices to enhance overall resilience.
  • Led offensive security exercises across both client environments and the organisation’s own infrastructure, uncovering systemic risks and strengthening resilience, those including:
  • Internal Network & External Perimeter Penetration Testing
  • Physical Onsite Breach Simulations to assess physical security posture
  • Social Engineering campaigns (Vishing, Phishing simulations) to evaluate human risk factors
Security AssuranceSecurity PolicyVulnerability AssessmentOT SecurityIdentity and Access Management (IAM)Communication+20

Barry nilsson

Independent Member - Cyber Security Committee

Nov 2023Present · 2 yrs 4 mos

  • Providing expert oversight and independent advice on cybersecurity.

Australian regional and remote community services ltd

Independent Member - Cyber Security & Risk Committee

Aug 2022Present · 3 yrs 7 mos

  • Providing expert oversight and independent advice on cybersecurity and risk management.

Dimension data

Network & Security Engineer (Contract)

Jun 2018Oct 2018 · 4 mos

  • A valued security and network resource to meet Dimension Data’s billion dollar transportation client's project requirements. Typical duties included:
  • Mount Palo Alto 3050 Series Firewalls, configure IPs, activate Threat Prevention and URL Filtering subscriptions.
  • Configure & stack 47 CISCO Catalyst 9300 Access switches and their corresponding switchports.
  • Build secure OOB management network and implement into production to meet availability business requirements.

Australian financial complaints authority

IT Security Officer (Contract)

Dec 2017Feb 2018 · 2 mos

  • Achievements:
  • Security Uplift Project: Build hardened SOE Kiosk machines with strict patching and removable USB policies.
  • Other duties included:
  • Identity and Access Management administration of IT access systems and user accounts.
  • Mentor the service desk team to provide quality customer service.

Eurofins

2 roles

Lead IT Systems Engineer

Oct 2014Nov 2015 · 1 yr 1 mo

  • Achievements include:
  • Physical security project, deploying of biometric security system to SCADA locations.
  • Test, implement, and deploy Mobile Sandbox security solution (VMware Airwatch) nationwide on mobile devices and train staff.
  • Datacenter Migration Project Lead, including development of BCP Business Continuity Plan and DR Disaster Recovery Plan
  • Implement Security Investigation & Remediation workflow for team to respond to attacks against company VPN Gateway.
  • Other responsibilities: Identity Access Management for VPN Gateway.

IT Administrator

Sep 2012Oct 2014 · 2 yrs 1 mo

  • Achievements include:
  • Building hardened SCADA & non-SCADA SOE and replace 250+ systems.
  • Migrate security systems from Trend Micro Security to Symantec Endpoint Protection to align with business security and management requirements.
  • Migration of 200+ Workstations from Windows XP to Windows 7.
  • Other responsibilities included and not limited to:
  • Bi-Monthly security patching and reporting on systems via Labtech Control Centre RMM.

Festo australia

Information Systems Support

Jan 2011Aug 2012 · 1 yr 7 mos

  • Achievements included:
  • Improve business data security via removing server and client EFS encryption and implement BitLocker drive security.
  • Migration of 150 Local and remote users from Windows XP to Windows 7 via SCCM.
  • Other responsibilities included and not limited to:
  • Administration and maintenance of AU & NZ Active Directory environment.
  • Availability Management, via maintaining healthy server RAID Arrays as well as the Offsite Backup Storage operations.
  • Installation and upgrading hardware / software of desktops and laptops to meet changing business requirements.

Stackforce found 100+ more professionals with Information Security Management & Cybersecurity

Explore similar profiles based on matching skills and experience