Mark Liapustin (clizSec)

clizSec

Mark Liapustin

Securing Email, APIs, Compliance, and the Products Built on Them

I'm Mark Liapustin (clizSec), a cybersecurity architect where email security, Web/API security, and regulatory compliance intersect. As CISO at Trustifi, killing phishing for a living, I set enterprise security strategy, GDPR, HIPAA, ISO 27001 framework programs, and AI/ML anti-phishing through intelligent agents and applied machine learning across the email, Web, and API stack.

United States, Miami · English · Hebrew · Russian

Work Experience

Roles, impact, and skills across my career.

Trustifi logo

Chief Information Security Officer

Trustifi

Miami, Florida, United States · Hybrid

Oct 2021 - Present

As a CISO with experience in email security, Web and API security, and compliance, I develop and implement email security measures to protect against spam, phishing, and malware, lead the cybersecurity team and the Email Managed Detection and Response (EMDR) team, build custom IOCs and threat signatures for email-based attacks, and secure email systems in accordance with GDPR, HIPAA, and ISO 27001. I also set enterprise security strategy and drive AI/ML anti-phishing capabilities through intelligent agents, applied machine learning, and model development across the email, Web, and API stack, while overseeing VIP client relationships and regulatory framework programs.

  • 01Email security
  • 02Anti-spam
  • 03Anti-phishing
  • 04Web & API security
  • 05Security architecture
  • 06AI/ML & intelligent agents
  • 07Compliance & frameworks
  • 08CISO & program leadership
Trustifi logo

Information Security, Compliance and Data Protection Officer

Trustifi

Las Vegas, Nevada · Hybrid

Aug 2018 - Oct 2021

As an Information Security, Compliance and Data Protection Officer, I have developed and implemented email security protections in the product, proprietary metrics and signatures, and managed my company's Information Technology environment while also creating internal Information Security policies to ensure the security and compliance of our systems. Leading, developing and certifying the company for compliance, regulations and standards such as GDPR, HIPAA and ISO 27001.

  • 01Email security
  • 02Anti-spam
  • 03Anti-phishing
  • 04Compliance & frameworks
  • 05Web & API security
  • 06Security architecture
Trustifi logo

Information Security Specialist

Trustifi

Tel Aviv District, Israel · On-site

Aug 2017 - Aug 2018

As an Information Security Specialist, I have gained expertise in researching and analyzing email security threats and conducting vulnerability and penetration testing. My work has allowed me to become a trusted resource for information security within my organization.

  • 01Email security
  • 02Anti-phishing
  • 03Penetration testing
Nation-E logo

Cyber Security Specialist

Nation-E

Herzliya, Tel Aviv District, Israel

Nov 2014 - Aug 2017

Focused on exploiting ICS/SCADA devices and running proof of concept demonstrations for potential clients to showcase product capabilities against zero-day threats. Published a CVE for an exploit I discovered and built experience protecting critical infrastructure systems.

  • 01Cybersecurity research
  • 02Penetration testing
  • 03ICS/SCADA security
  • 04IoT security

Volunteering

Responsible disclosure and bug bounty contributions.

United States Department of Defense

Apr 2017 - Present

Contributing to the U.S. Department of Defense Vulnerability Disclosure Program through HackerOne, responsibly identifying and reporting security vulnerabilities across critical DoD systems and infrastructure.

  • Focus areas include the Pentagon Visa/Passport Program, military websites and servers, and research and development centers.
  • Publicly disclosed findings include information disclosure in US Army Corps of Engineers R&D systems and cross-site scripting in the Pentagon Visa/Passport Program.

Schneider Electric

Mar 2017 - Apr 2017

Discovered and disclosed a denial-of-service vulnerability in Schneider Electric Conext ComBox (model 865-1058), acknowledged by US-CERT and Schneider Electric and documented under advisory ICSA-17-061-02 (CVE-2017-6019).

  • Co-discovered with Arik Kublanov (Nation-E Ltd); helped improve resilience of ICS and SCADA environments.

Instacart

May 2017 - Jun 2017

Identified and reported a path traversal vulnerability in WordPress Core AJAX handlers through HackerOne, contributing to the security of one of the most widely deployed CMS platforms.

FlexiSpy

Jun 2017 - Jul 2017

Discovered and responsibly reported two high-to-critical vulnerabilities in FlexiSPY services. Public disclosure was not approved due to the sensitive nature of the findings.

Publications

Public research and advisory work.

Discovery of a Vulnerability in Schneider Electric SCADA/ICS Devices

May 2017

Cybersecurity and Infrastructure Security Agency (CISA)

CVE-2017-6019. Identified and exploited a denial-of-service vulnerability affecting Schneider Electric Conext ComBox Solar Battery Monitor (model 865-1058) and related integrated devices. The finding was responsibly disclosed and publicly documented under advisory ICSA-17-061-02, contributing to mitigation guidance for industrial infrastructure.

View publication

CVE-2017-6019: Schneider Electric Conext ComBox Denial of Service

Apr 2017

NVD / MITRE

National Vulnerability Database record for the Conext ComBox (model 865-1058) uncontrolled resource consumption flaw, all firmware versions prior to V3.03 BN 830. Credited to Arik Kublanov and Mark Liapustin of Nation-E Ltd; fixed by Schneider Electric in firmware V3.03 BN 830.

View publication

Contact

Get in touch.

Connect on LinkedIn

Best way to reach me for collaboration, security discussions, or professional inquiries - especially around email security, phishing, and enterprise security programs.

Connect on LinkedIn

Elsewhere online