Valerii Serkin
Senior Manager, Security Engineering · TradingView

Valerii Serkin

Security Operations & Engineering Leader. I build and run SOCs, detection engineering, threat hunting and security automation — from the ground up.

14+
Years in cybersecurity
20+
SOC analysts led
3
SOCs built from zero
6
Languages I code in

I'm a security operations leader who is happiest standing things up where nothing existed before. Across TradingView, Malcrove and Kaspersky, I've established SOCs from scratch — monitoring, detection, response, and the threat-intelligence functions that make them intelligence-led.

I lead teams, but I never stopped being an engineer. I architect SOAR automation, tune EDR for real detection coverage, and write internal tooling and microservices in Python, Go, Rust and .NET Core to take the manual work off analysts' plates.

Most recently I've focused on a new frontier: detecting and governing shadow AI — the unsanctioned AI usage that quietly creates data-exposure and compliance risk inside modern organizations.

Based inMálaga, Spain
CurrentTradingView
FocusSecOps · Detection · DFIR
EducationMEPhI — Information Security
LanguagesRussian · English · Spanish
StatusOpen to conversations
Sep 2025 — Present
TradingView
Senior Manager, Security Engineering
Málaga, Spain
  • Lead the internal SOC — continuous, org-wide monitoring, incident response and proactive threat hunting.
  • Established the SOC from the ground up and embedded a Threat Intelligence function for intelligence-led ops.
  • Architected and deployed SOAR automation, unifying the security stack and cutting mean time to detect & respond.
  • Pioneered methods and tooling to detect and prevent unsanctioned shadow-AI usage.
Sep 2021 — Sep 2025
Malcrove
3 roles · 4 years — progressive leadership
Dubai, UAE
Jan 2024 — Sep 2025
Head of Cyber Defense Center
  • Led 20+ SOC analysts across daily operations, incident response and threat detection in diverse environments.
  • Directed DFIR across client environments — swift containment, investigation and remediation.
  • Ran compromise assessments and optimized SIEM (Elasticsearch, Splunk, QRadar), IDS/IPS and TI tooling.
Oct 2022 — Jan 2024
Head of Detection Engineering & Threat Hunting
  • Built and optimized detection engineering and threat hunting across multiple clients.
  • Designed customized detection rules with the SIGMA framework.
  • Spearheaded threat hunting across on-premise, AWS and Azure; automated workflows with custom Python.
Sep 2021 — Oct 2022
Senior Cyber Security Consultant
  • Led Threat Hunting and Incident Response engagements for multiple clients.
  • Built Python microservices to automate enrichment, triage and response.
  • Conducted malware analysis and reverse engineering to produce actionable threat intelligence.
Sep 2016 — Sep 2021
Kaspersky
Senior SOC Analyst — R&D
Moscow, Russia
  • Helped build the SOC's core processes and tools from scratch (Elasticsearch, TheHive, Cortex).
  • Developed microservices in Python, Go and .NET Core to automate SOC workflows.
Jun 2015 — Sep 2016
Credit Bank of Moscow
Leading Information Security Specialist
Moscow, Russia
  • Built and implemented information security policies; ran assessments and audits for compliance.
  • Oversaw firewalls, IDS and endpoint protection; led incident response and forensics.
Mar 2014 — Jun 2015
Transaero Airlines
Leading Information Security Engineer
Moscow, Russia
  • Led key-carrier generation for the client-bank clearing center (eToken / RuToken).
  • Ran internal penetration tests and end-to-end security projects.
Dec 2011 — Sep 2012
Microtest
IT Security Engineer
Moscow, Russia
  • Pre-sale security consulting; implemented channel and personal-data protection systems for enterprise clients.
Programming
PythonGoRust.NET CoreC / C++JavaScript
SIEM
Elastic SIEMSplunkAzure SentinelSecurity OnionWazuhLogRhythmSumo LogicRapid7 IDR
Detection & Response
SIGMATheHiveVelociraptorMISPZeekSuricataCortex / SOAR
EDR & Threat Hunting
CrowdStrikeCarbon BlackDefender 365ELK StackOSQueryQRadar
Cloud
AWSAzureGCPCloudTrail / GuardDutyAzure AD / SentinelCloud Armor
Threat Intel & Offensive
MITRE ATT&CKSTIX / TAXIIOpenCTICalderaCobalt StrikeAtomic Red TeamBurp SuiteNessus
001

TradingView SOC, from zero

Established a full Security Operations Center for a global trading platform — monitoring, detection, response and an embedded threat-intel function.

002

Shadow-AI detection

Pioneered methods and internal tooling to detect and prevent unsanctioned AI usage, cutting data-exposure and compliance risk.

003

SOAR automation at scale

Unified a fragmented security stack into a single automated workflow, significantly reducing mean time to detect and respond.

004

20+ analyst defense center

Ran daily operations, DFIR and threat detection for a managed-security provider across diverse client environments.

005

Detection engineering with SIGMA

Designed customized detection rules and automated hunting workflows across on-premise, AWS and Azure infrastructures.

006

Kaspersky SOC tooling

Built core SOC processes and tooling from scratch with open-source stacks and custom microservices in Python, Go and .NET Core.

This profile is published in machine-readable form so AI agents and tools can fetch and parse it directly — a curated llms.txt index, clean Markdown for every section, and JSON-LD Person schema, all served alongside this page.