New website versionCurrent website
← Back to the materials

About Vitaliy Pikov

Engineering, research and teaching.

Vitaliy Pikov, secure software development expert and lecturer

Secure development, engineering practice, teaching and research — from requirements and architecture through to verifiable artefacts and working tools.

I work in secure software development, DevSecOps and AppSec, turning the requirements of standards into architectural decisions, working processes, automated checks and verifiable results. At the centre of that practice are security by design, threat modeling, and protection across the whole software lifecycle.

  • Secure C/C++
  • SAST & DAST
  • Fuzzing
  • SCA & SBOM
  • Software Supply Chain
  • DevSecOps
  • AppSec

Professional background

For more than 25 years I have worked at the intersection of information technology, information security, research and education: developing trusted computing systems, defining security requirements, reviewing architecture and source code, testing security products, and leading engineering teams.

My last position in public service was at a specialised state-sector research institute. There I progressed from software engineer to head of a research laboratory for information protection and of a testing laboratory. Since then I have worked on trusted computing platforms, on developing continuing-education programmes, and on the practical rollout of secure software development processes.

Engineering practice

I build a secure development lifecycle as a working engineering loop, not merely a set of documents. I designed and rolled out an in-house SCA/SBOM service for component analysis, vulnerability tracking and licence-compliance review of third-party components.

I work with CycloneDX, SPDX, VEX/OpenVEX and CSAF, enriching data from NVD, OSV, EPSS and CISA KEV. I embed role-based access, immutable audit, containerisation and security gates into CI/CD. For C/C++ the emphasis is on memory safety, safe APIs, compiler hardening, sanitizers, SAST, DAST and fuzzing.

Standards and methodologies

I connect Russian regulatory requirements with international engineering practice, so that requirements, architecture, threat model, code, testing, component inventory and release form one verifiable chain.

  • GOST R 56939-2024
  • GOST R 71207-2024
  • NIST SSDF
  • OWASP SAMM
  • OWASP ASVS
  • CWE
  • ISO/IEC 27001
  • ISO/IEC 27034
  • CERT C/C++
  • MISRA C/C++

Teaching

  • More than 10 years of teaching in higher education and in continuing professional education.
  • Supervised more than 130 students to a successful defence at bachelor's, specialist (the five-year Russian first degree) and master's level, with final qualification theses on information security and information systems.
  • Authored 10 original courses on secure software development, static and dynamic analysis, fuzzing and penetration testing.
  • Trained more than 100 practitioners and delivered more than 40 webinars on secure development, including an extensive joint series with PVS-Studio.

Research and expert engagement

  • Author of more than 40 research publications on information security, secure development, hardware vulnerabilities and trusted information systems; indexed in Scopus and Web of Science.
  • Invited expert on the secure-development round table at MiTSOBI 2026.
  • Speaker at Positive Hack Days, Infoforum, InfoSecurity Russia and international academic conferences; judge at information-security competitions.

Education and qualifications

A foundation in engineering, extended by systematic professional retraining and regular continuing education in information security, secure development, pedagogy and artificial intelligence.

Primary degree

  • Engineering degree in Automated Information Processing and Control Systems.

Professional retraining

  • Information Security — Bauman Moscow State Technical University.
  • Countering foreign technical intelligence collection.
  • Pedagogy for vocational and continuing professional education.
  • Technical protection of information.
  • Applied psychology.
  • Artificial intelligence in education.

Continuing education and additional training

  • Application security.
  • Contemporary information security: approaches, tooling and teaching practice.
  • Secure Software Development Process Specialist, 200 hours; architecture analysis and source-code review; Python, radar signal processing, neural networks, AI ethics and quality in IT teaching.
  • 2022–2023KasperskyOS, industrial control system security and the current threat landscape.
  • Astra Linux Special Edition administration.
  • 2009–2010Systems administration, Windows Server, Active Directory and Windows deployment.

Titles and professional standing

  • Honoured Associate Professor of RosNOU — an honorary title conferred by the Russian New University, not an academic rank or degree. Higher-education lecturer.
  • Authorised instructor for Astra Linux Special Edition 1.7/1.8.
  • Microsoft Certified: MCT, MCITP, MCPS, MCSA, MCTS — including Microsoft Certified Trainer (MCT).

Let’s work on the next step.

For lectures, team training and consulting on secure software development and information security.