# Mark Liapustin (clizSec) > CISO at Trustifi, killing phishing for a living. Email security, Web/API security, AI/ML anti-phishing, and compliance across GDPR, HIPAA, ISO 27001, and related frameworks. ## About Portfolio site for Mark Liapustin (clizSec): Chief Information Security Officer and cybersecurity architect at Trustifi (since Oct 2021), based in Miami, Florida. Focused on email security, Web and API security, AI/ML-driven anti-phishing, intelligent agents, custom IOCs and threat signatures, and regulatory compliance including GDPR, HIPAA, and ISO 27001. Leads Trustifi's cybersecurity team and its Email Managed Detection and Response (EMDR) team. ## Name variants - Mark Liapustin (canonical English spelling) - Mark Lyapustin (alternate transliteration) - clizSec / clizsec (handle on GitHub, LinkedIn, HackerOne) - Марк Ляпустин (Russian) - מרק ליאפוסטין (Hebrew) ## Employer - Trustifi: https://trustifi.com (AI-powered cloud email security) - Role: Chief Information Security Officer, Oct 2021 to present - Earlier Trustifi roles: Information Security, Compliance and Data Protection Officer (2018 to 2021); Information Security Specialist (2017 to 2018) - Earlier: Cyber Security Specialist at Nation-E (2014 to 2017), ICS/SCADA and IoT security research ## Research and disclosures - CVE-2017-6019: Schneider Electric Conext ComBox (model 865-1058) denial of service, co-discovered with Arik Kublanov (Nation-E Ltd) - CISA advisory ICSA-17-061-02: https://www.cisa.gov/news-events/ics-advisories/icsa-17-061-02 - NVD: https://nvd.nist.gov/vuln/detail/CVE-2017-6019 - Exploit-DB: https://www.exploit-db.com/exploits/41537 - HackerOne (https://hackerone.com/clizsec): U.S. Department of Defense Vulnerability Disclosure Program (information disclosure in US Army Corps of Engineers R&D systems, cross-site scripting in the Pentagon Visa/Passport Program), Instacart (WordPress Core AJAX path traversal), FlexiSPY (two high-to-critical findings, not publicly disclosed) ## Projects - [ScaMatrix](https://scamatrix.com): AI-powered threat intelligence lookup (beta). Scan indicators of compromise - URLs, IPs, domains, emails, and file hashes. Owned and built by Mark Liapustin (clizSec). ## Primary content - [English](https://www.clizsec.com/en): Professional portfolio with work experience (including role-specific skills), volunteering, publications, and contact information. - [Hebrew](https://www.clizsec.com/he): Hebrew version of the portfolio. - [Russian](https://www.clizsec.com/ru): Russian version of the portfolio. ## Contact - LinkedIn: https://www.linkedin.com/in/clizsec - GitHub: https://github.com/clizsec - HackerOne: https://hackerone.com/clizsec ## Optional - [humans.txt](https://www.clizsec.com/humans.txt) - [security.txt](https://www.clizsec.com/.well-known/security.txt) - [sitemap](https://www.clizsec.com/sitemap.xml) Last updated: 2026-09-04