Author Image

[UPDATE IN PROGRESS] Hi, I am Iason Somarakis

Iason Somarakis

Security Engineer at RHEA Group

I am Iason Somarakis, I work as a senior security engineer, focusing on research, development and application of security solutions. With hands-on experience in penetration testing methodologies, tools and techniques; virtualization and containerization frameworks; and machine learning algorithms for enhanced proactive and reactive security mechanisms. Furthermore, I have a diverse toolkit of programming languages, developing and infrastructure as a code frameworks. My research interests focus on two types of security assessments, cyber range training and penetration testing; specifically, asset and threat emulation technologies for cyber range training and offensive technologies for penetration testing. Last but not least, I enjoy capture the flag activities, privacy related topics, cryptocurrencies, and reading novels.

Problem Solving
Team Work
Hard Working
Leadership
Keen to Learn
Project Management

Skills

Experiences

1
Security Engineer
RHEA Group

August 2022 - Present, Hybrid

Space and systems engineering and cybersecurity solutions.

Responsibilities:
  • Designing and developing cybersecurity training scenarios in the domain of IT, Critical Infrastructure (e.g., OT) and Space
  • Researching and implementing approaches of exploitation in the domain of IT, OT and Space
  • Delivering cybersecurity training in physical location, or remotely
  • Designing and developing asset and threat emulation/simulation solutions in manufacturing supply chain
  • Contributing on the quality assurance of documentation and training content

CEO, Solution and Security Architect
RAVEN CYBERSECURITY IKE

January 2023 - Present, Hybrid

Cybersecurity and Technology Solutions and Services

Responsibilities:
  • Management
  • Designing the software architecture for software solutions
  • Designing the security of software solutions and systems
  • Performing risk analysis and threat modelling based on well known stanrdards (e.g., STRIDE, ATT&CK MITRE)
  • Performing technical security assessments (e.g., penetrationg testing, bughunting)
2

3
Senior Security Engineer
SPHYNX Technology Solutions

August 2021 - Dec 2022, Cyprus

SPHYNX offers products and solutions, and consulting services, in the areas of cyber intelligence, analytics, incident response, assurance, and certification.

Responsibilities:
  • Managing and Designing SPHYNX’s Cyber Range capabilities
  • Developing the emulation (i.e., asset and threat emulation) and infrastructure orchestration mechanisms of SPHYNX’s Cyber Range
  • Developing training content for SPHYNX’s Cyber Range
  • Managing, Designing and Developing SPHYNX’s Penetration Testing capabilities
  • SPHYNX’s designated penetration tester
  • Managing, Contributing and Developing on RESIST EU Project
  • Managing, Contributing and Developing on HOLOBALANCE EU Project
  • Managing and Contributing on AERAS EU Project

Security Engineer
SPHYNX Technology Solutions

January 2020 - August 2021, Cyprus

SPHYNX offers products and solutions, and consulting services, in the areas of cyber intelligence, analytics, incident response, assurance, and certification.

Responsibilities:
  • Designing SPHYNX’s Cyber Range capabilities
  • Developing the emulation (i.e., asset and threat) and infrastructure orchestration mechanisms of SPHYNX’s Cyber Range
  • Managing, Designing and Developing SPHYNX’s Penetration Testing capabilities
  • SPHYNX’s designated penetration tester
  • Managing, Contributing and Developing on RESIST EU Project
  • Managing, Contributing and Developing on HOLOBALANCE EU Project
  • Contributing and Developing on Threat Arrest EU Project
4

5
Software Engineer
SPHYNX Technology Solutions

April 2018 - January 2020, Cyprus

SPHYNX offers products and solutions, and consulting services, in the areas of cyber intelligence, analytics, incident response, assurance, and certification.

Responsibilities:
  • Managing, Designing and Developing SPHYNX’s Penetration Testing capabilities
  • SPHYNX’s designated penetration tester
  • Managing, Contributing and Developing on RESIST EU Project
  • Managing, Contributing and Developing on HOLOBALANCE EU Project
  • Contributing and Developing on THREAT ARREST EU Project
  • Contributing and Developing on SEMIOTICS EU Project

IT Support Technician
Curvature

April 2016 - December 2016, Netherlands

Sales of new and refubrished IT hardware

Responsibilities:
  • Activities require interaction with application software and operating systems to diagnose and resolve problems.
  • Assist staff with the installation, configuration, and ongoing usability of desktop computers, peripheral equipment and software within established standards and guidelines.
  • Assist in the design and deployment of a standard OS and Software images
  • Works with vendor support contacts to resolve technical problems with desktop computing equipment and software.
  • Manages Help Desk request queue (Ticketing System, Knowledgebase, and Asset Management).
  • Trains and orients staff on use of hardware and software.
  • Performs upgrades on systems to ensure longevity.
  • Assists in maintaining Voice related services
  • Uphold all aspects of Curvature’s Information Security Management systems.
6

7
IT Support/Network Administrator Trainee
Curvature

October 2015 - April 2016, Netherlands

Sales of new and refubrished IT hardware

Responsibilities:
  • Activities require interaction with application software and operating systems to diagnose and resolve problems.
  • Assist staff with the installation, configuration, and ongoing usability of desktop computers, peripheral equipment and software within established standards and guidelines.
  • Assist in the design and deployment of a standard OS and Software images
  • Works with vendor support contacts to resolve technical problems with desktop computing equipment and software.
  • Manages Help Desk request queue (Ticketing System, Knowledgebase, and Asset Management).
  • Trains and orients staff on use of hardware and software.
  • Performs upgrades on systems to ensure longevity.
  • Assists in maintaining Voice related services
  • Uphold all aspects of Curvature’s Information Security Management systems.

Technician's assistant/IT Support
IPEKAT IKE

June 2013 - June 2015, Greece

Construction Services

Responsibilities:
  • Responsible for management and maintenance of IT equipment
8

Education

Ph.D student in Asset and Threat Emulation for Cybersecurity Training at School of Mathematics, Computer Sciences & Engineering
B.Sc. in Computer Software Engineering

Projects

RHEA Internal Scenario Engineering
Developer, Contributor August 2022 - Present"

Protect and Allow Exchange of Manufacturing Data (PAEMD)
Developer, Contributor August 2022 - Present"

Security Cyber Center of Excellence (SCCoE)
Training Content Engineer, Contributor August 2022 - Present"

HOLOBALANCE
Developer, Penetration Tester, Project Manager March 2018 - December 2021

HOLOgrams for personalised virtual coaching and motivation in an ageing population with BALANCE disorders. Primarily worked on an educational android game and on the security assurance (i.e., Penetration Testing) of HOLOBALANCE platform, involving the assessment of backend infrastructure, web front facing applications, REST APIs, android applications, python applications and bluetooth devices.

RESIST
RESIST
Developer, Penetration Tester, Project Manager Jun 2018 - August 2022

Resilient Transport Infrastructure to Extreme Event. Primarily worked on the integration of SPHYNX’s solution in RESIST platform and the security assurance (i.e., Penetration Testing, project wide security recommendations) of the RESIST platform, involving the assessment of backend infrastructure (e.g., ProxMox virtual machines), front-facing web applications, REST APIs, and drones.

SEMIOTICS
Developer, Contributor Jun 2018 - August 2021

Smart End-to-end Massive IoT Interoperability, Connectivity and Security. Primarily worked on SPHYNX’s contribution for multiple deliverables required by the project.

THREAT ARREST
Developer, Penetration Tester, Contributor Jun 2018 - August 2021

THREAT-ARREST aims to develop an advanced training platform incorporating emulation, simulation, serious gaming and visualization capabilities to adequately prepare stakeholders with different types of responsibility and levels of expertise in defending high-risk cyber systems and organizations to counter advanced, known and new cyber-attacks. Primarily worked on the security assurance (i.e., Penetration testing) of THREAT ARREST’s Pilot organizations, involving the assessment of backend infrastructure (i.e., containers and physical machines) and web applications. Also, worked on the development of the models for the cyber range training scenarios and programmes, and on the development of the scenario/programme adaptation mechanisms.

SMART BEAR
Penetration Tester Jun 2018 - August 2022

Smart Big Data Platform to Offer Evidence-based Personalised Support for Healthy and Independent Living at Home. Primarily worked on the security assurance of (i.e., Penetration testing) of SMART BEAR platform, involving the assessment of front-facing web applications and REST APIs.

Model-Driven Cyber Range Training: A Cyber Security Assurance Perspective
Lead Contributor, Developer Jan 2017 - Nov 2017

Publication for our novel approach in specificing cyber range training scenarios and the interworkings wih SPHYNX’s security assurance model. Focused on the developement of the models and the mechanisms that managed them.

CYRA: A Model-Driven CYber Range Assurance Platform
Contributor, Developer Oct 2019 - Dec 2019

Publication with advances in our model-driven approach of specifying cyber range training scenarios and adaptation mechanisms that allow the scenarios to adapt based on the organizations security & privacy posture. Focused on the development of the adaptation mechanisms based on vulnerabilities.

RNN-LSTM-Network-Intrusion
Lead author and developer Jun 2018 - July 2018

A Deep Learning based anomaly network instrusion solution that was developed to supplement signature-based IDS such as snort. Developed in Python with well known frameworks, such as Keras, Numpy, SciLearn and trained using well-known dataset NSL-KDD99.

Accomplishments

Offensive PenTesting Learning Path
Tryhackme August 2021 - December 2021

Course that prepares inspiring security proffesionals for offensive security operations.

Advent of Cyber 2021
Tryhackme August 2021 - December 2021

Themed event with 25 challenges offering hands-on experiece on various cyber security concepts.

NIS2019
ENISA & FORTH September 2019

Summer school with theme ‘Challenges of Emerging Technologies’, focusing on AI, 5G, IoT, Machine Learning etc.

NIS2018
ENISA & FORTH September 2018

Summer school with theme ‘The Challenge of the Changing Risk Landscape’ with hands-on workshop on incident handling.

Penetration Testing and Ethical Hacking
Cybrary October 2018

Course that teaches the basic to advanced topics of ethnical hacking, from methodology to common tools and techniques.

Python for Security Profesionals
Cybrary October 2018

Course that teaches the fundamentals of Python, focusing on libaries for data and packet-level manipulation.

The Ultimate Ethical Hacking Course 2017
Udemy October 2017

Course that teaches from fundamentals to advanced concepts of ethnical hacking with ephasis on real world applications.

Neural Networks and Deep Learning
Udemy September 2017

Course by DeepLearning.AI that teaches the inner workings of Neural Networks and introduces the core building blocks on developing one in Python.

EU Scholarship - Android Development for Beginners
Udacity January 2017

This course focuses on the basics of android developing, with hands-on experience towards building your first applications.