Resume

Slobodan "Bob" Horvat

Principal Cybersecurity Engineer — Security · Cloud · SecDevOps
Malahide, Co. Dublin, Ireland

Experience

Work History

2020 – Present Workday Ltd
Principal Cybersecurity Engineer

Architect and enforce security across Private Cloud (bare-metal, OpenStack) and AWS, with Kubernetes as the primary workload platform. Lead infrastructure security reviews and threat-model new product designs. Deployed Zero Trust micro-segmentation using Illumio in Private Cloud. Engineered ModSecurity WAF as a Kubernetes sidecar. Operate and tune endpoint and cloud security tooling: Palo Alto Cortex XDR, CrowdStrike Falcon, Wiz Sensor, and Wiz Advanced.

Spearheading security for agentic LLM deployments across the enterprise AI platform. Define guardrails and evaluation harnesses to assess LLM models for security compliance, prompt injection resistance, and data leakage. Apply the OWASP LLM Top 10 framework to AI workload threat modelling and red-team exercises.

AWS Kubernetes OpenStack Illumio Zero Trust ModSecurity WAF Palo Alto Cortex XDR CrowdStrike Falcon Wiz LLM Security AI Guardrails OWASP LLM Top 10
2019 – 2020 Workday Ltd
Senior Cybersecurity Engineer

Expanded Zero Trust coverage across Private and Public Cloud. Drove the infrastructure security review programme and developed security design patterns adopted platform-wide.

AWS OpenStack Kubernetes Zero Trust Infrastructure Security
2018 – 2019 Workday Ltd
Cybersecurity Engineer

Joined Workday Security Engineering. Hardened Private Cloud (bare-metal, OpenStack) and AWS infrastructure. Conducted security assessments and contributed to the team's design-review methodology.

AWS OpenStack Infrastructure Security Security Reviews
Feb 2010 – 2017 Tokić d.o.o.
Senior Network & Security Engineer, Team Lead

Led network and security engineering for an automotive aftermarket distributor with 100+ branch locations. Architected and operated the full server estate (Windows, Linux, VMware). Designed private cloud on VMware 5/6 and orchestrated phased migration to AWS S3/EC2, Azure, and Digital Ocean. Administered MS SQL 2008/2012 with AlwaysOn HA cluster backing Navision ERP. Developed a C# DLL integrating EFT POS terminals directly with the ERP system.

VMWare AWS Azure MS SQL Server Cisco SSLVPN Active Directory C#
Apr 2004 – Feb 2010 Sberbank d.d.
Senior Network & Security Engineer

Engineered and maintained network connectivity for a retail bank spanning 30+ branches, 2 NOCs, and 100+ servers. Designed corporate LAN segmentation (VLANs, routing). Deployed and managed UTM platforms (Fortigate, Palo Alto). Operated ATM/Frame Relay WAN links on Cisco 800–3600 series. Administered Swift infrastructure.

Cisco Fortigate Palo Alto ATM/Frame Relay VLAN Swift
Apr 2002 – Apr 2004 AlterBox d.o.o.
Senior Network & System Engineer

Built the company NOC from the ground up for a telecom service integrator. Deployed and hardened Linux servers (Debian, RedHat, Suse) with iptables, VPN, and IDS. Instrumented network monitoring via SNMP/MRTG. Administered Oracle 8i/9i RAC. Automated operations with Bash, Python, and Perl.

Linux iptables SNMP Oracle RAC bash python
Mar 2000 – Apr 2002 GlobalNET d.d.
Junior Network Engineer

Part of the core ISP team operating a multi-technology network (Frame Relay, ATM, DSL) across Cisco, RAD, and Zyxel platforms. Implemented MPLS and VPN services. Supervised NOC equipment health via SNMP. Delivered a Call Center solution on Intel Dialogic and Cisco Call Manager.

Cisco MPLS Frame Relay DSL SNMP
Feb 1999 – Apr 2000 Leggett & Platt (LPT) d.d.
System & Software Engineer

Administered Novell Netware servers and IPX/SPX network for a manufacturing plant. Designed TCP/IP transition to replace legacy IPX/SPX. Produced design guides and documentation for Scala ERP rollout. Developed a G-Code application for a 5-axis CNC mill producing industrial feed screws.

Novell Netware TCP/IP Scala ERP G-Code CNC
Jan 1997 – Feb 1998 Edeka Zentrale AG & Co KG
Intern — POS System Integration

Ported a CA-Clipper DOS POS system to CA-Visual Object (Windows) for a major supermarket chain in Hamburg. Integrated a CTI application with an Oracle database.

CA-Clipper CA-Visual Object Oracle CTI
Aug 1994 – Aug 1997 Revoc d.o.o.
Software & Hardware Engineer

Delivered Novell Netware (IPX/SPX) network solutions for SMB clients. Built CA-Clipper financial software for accounting and banking. Designed Oracle databases and wrote PL/SQL for core banking software. Implemented the company's first CTI system with IVR and ACD on Intel Dialogic.

Novell Netware CA-Clipper Oracle PL/SQL Intel Dialogic IVR/ACD

Education

Academic Background

Oct 1989 – Apr 1994 TSC — Technical School for Computer Science and Technology
High School — Computer Science & Technology

Čakovec, Croatia. Specialised technical high school with computer labs and programming courses. Foundation in computer science, electronics, and networking.


Languages

Communication

Croatian — Native (C2)
English — Fluent (C1)
German — Basic (A1)

Extracurricular

Side Projects & Interests

Mobile Development 2D & 3D

2012 – Present

Android and iOS game development using Unity3D and UnrealEngine 4. 2D/3D games and prototypes, shader optimization, Unity3D C# Mono programming. Prototyping in UnrealEngine Blueprint and C++.

Unity3D UnrealEngine 4 C# C++ Android iOS
Embedded Development

2014 – Present

Raspberry Pi, Arduino, and SmarTEK platform projects. OpenCV with Python and C++. Custom Raspbian (Debian) builds. IoT home-automation controller on Arduino. Windows app for GigE Vision SmarTek high-speed cameras. MicroPython firmware development on ESP32 microcontrollers — sensor nodes, MQTT telemetry, Wi-Fi mesh automation, and low-power IoT prototypes.

Raspberry Pi Arduino ESP32 MicroPython MQTT OpenCV Python IoT GigE Vision

Skills

Technical Expertise

Networking — Expert

TCP/IP OSPF BGP VLAN/STP 802.1x VXLAN Cisco

Network Security — Expert

Cisco IOS ACL Cisco ASA VPN iptables OpenVPN Cisco FirePower Meraki MX IKE/IPSEC

Cloud Security — Expert

Illumio Zero Trust Palo Alto Cortex XDR CrowdStrike Falcon Wiz ModSecurity WAF AWS Security K8s Security

AI / LLM Security

LLM Security AI Guardrails OWASP LLM Top 10 Prompt Injection Agentic AI Security

Cloud Infrastructure

VMWare OpenStack AWS S3/EC2 Azure Digital Ocean

Linux / Unix

Debian/Ubuntu CentOS/RedHat Suse Apache nginx BIND Postfix LDAP

Containers & DevOps

Kubernetes Docker Helm Terraform Ansible Puppet Chef

Windows Infrastructure — Expert

Domain Controller Active Directory GPO MS Exchange MS SQL Server NAC/Radius Veritas Backup

Databases

MySQL/MariaDB PostgreSQL MS SQL Server Oracle

Storage

SAN/NAS Pure Storage m10 HP 3Par EMC Brocade FC iSCSI

Monitoring — Expert

Nagios Zabbix SNMP Syslog LogStash fluentd

Programming / Scripting

Bash Python Perl PHP NodeJS C# C++ Rust