I build secure and governable IT environments - strategically led, technically verified.
Grigory Sipachev - IT Director · CISO · Vienna
25 years of experience in IT infrastructure, information security and international IT/OT environments - from strategy, governance and budget to technical acceptance in live operations.
Open to permanent leadership roles and to fixed-term mandates in Austria and Europe - on-site, hybrid or remote.
SIPACHEV.COM
EXECUTIVE ACCESS
Grigory
Sipachev
IT-DIREKTOR · CISO
WIEN · ATSEIT 2001DE · EN · RU
- 25
- years in IT & engineering
- 7+
- countries under responsibility - infrastructure & security
- 24/7
- support organisation built from zero
- 300+
- users supported internationally
Employers & mandates - selectionT&F Agriculture · GroupDF International · MIPT CET · RWGG · Transkor-K · GMAC CIS · Auto3P · M-Skou IT · Digisky · Astern Energy · Rhinestone · Greenfield
§ 01
Engagement
IT Director / CISO / Head of IT & Security
Permanent
For industry, energy and international groups: building and leading the IT organisation, budget and vendor accountability, security governance, board reporting. Open to long-term commitment - including equity and board-track perspectives.
- IT strategy, operating model and organisation
- Information security as a leadership duty (NIS2 context)
- Crisis resilience: proven in geopolitically unstable environments
Get in touch
Leadership on a temporary basis - fixed-term or seconded
Interim & project leadership
For companies that need leadership for a defined period: bridging a vacancy, transformation phases, building an IT organisation - with a clearly scoped remit and a defined outcome.
- NIS2: assessment and implementation roadmap
- IT/OT security assessment for production environments
- Building risk and board reporting
- Interim leadership of an IT function or programme
Get in touch
§ 02
Competence areas
Governance & leadership
IT strategy, operating models, building and leading IT organisations, reporting lines up to executive management.
Risk & compliance
Information security as a risk discipline: access control, incident analysis, data-protection and export-compliance practice.
IT/OT security
Separation and interplay of IT and control systems in production environments; security and backup architecture from day one.
Infrastructure & operations
Windows Server, virtualisation, Citrix/VDI, networks, migrations - built from scratch or modernised in place, always operable.
Vendor steering & procurement
Tenders, TCO evaluation, negotiation, acceptance and the transition from contractors to internal teams.
Transformation & products
Digital products with full ownership: web platforms, native clients, subscription operations - architecture to support.
§ 03
Selected mandates
GroupDF International, Vienna - IT & security across 7+ countries
Situation: fragmented IT landscape across several countries, geopolitically unstable environment, strict regulatory and export-compliance requirements.
Approach: unified infrastructure and security strategy, reorganisation with zero downtime, consistent vendor governance, secured communications for the leadership level.
Result: uninterrupted operations through several crisis years; consolidation of the telephony and communications landscape; governance that holds up in front of auditors and partners.
Oil & gas project (international) - IT operating model and IT/OT separation
Situation: multi-site project (city office, engineering base, production sites) without a defined IT organisation, operated by external contractors.
Approach: design of the IT operating model, clear separation of IT vs. OT/control-systems responsibility, definition of the specialist structure, plan for the transition from contractors to an internal team.
Result: a sustainable operating model with defined interfaces to international technology partners; security and backup architecture planned in from the start.
Austrian energy company - secure remote workspace
Situation: outdated local infrastructure, distributed team, no internal IT.
Approach: hardened Windows Server domain with remote desktops and file services on European cloud infrastructure, controlled data migration, corporate telephony and company website.
Result: ongoing, managed operations as an external IT partner - delivery, documentation and accountability from a single source.
MIPT research centre - infrastructure from six desks to a campus
Situation: start-up phase of a research organisation: six employees, one office, no infrastructure.
Approach: built virtualisation, private cloud, compute clusters and a helpdesk; IT planning for a new R&D facility; growing the IT function alongside the organisation - from IT manager to CIO.
Result: uninterrupted research operations through years of growth and several relocations.
Retail network (AT + CZ) - management platform for 22 stores
Situation: a growing store network with POS, warehouse, logistics and staff processes and no unified system.
Approach: concept and full-stack delivery of one platform: point of sale, warehouse with scanning, logistics, HR and role-based dashboards for management and accounting.
Result: a working end-to-end system across all roles - proof that concept, delivery and operations can come from a single source.
Own product - zero-trust remote-access platform
Situation: the need for trustworthy, secured remote access with the standards of a commercial service - not a hobby project.
Approach: as a founder: distributed European server infrastructure, own Android and Windows clients, subscription management, monitoring and support - product ownership from architecture to operations.
Result: a live service with real users; P&L, product and operational responsibility in one person.
Further mandates are covered by non-disclosure agreements and are not shown here. Specifics can be discussed in person, within what those agreements allow. References on request (after an initial conversation).
§ 04
Further projects & products
Work outside permanent employment - as an external IT partner and as a product owner.
Infrastructure renewal, trading company
Replaced two hypervisor hosts with a single Dell R640, migrated the domain including directory services and terminal server, deployed SQL Server 2025 for the ERP - without interrupting operations.
Export company, Bahrain
Domain, web server with the corporate site, a separate SFTP file server and expense tracking; dashboard covering server health and accounting.
Cross-border corporate telephony
Two coupled phone systems in two countries: calls from the CRM are routed by destination number, and the customer sees a local number in each market.
IP telephony for an Austrian company
Self-hosted PBX on a dedicated server, Austrian phone number, calls from the app and straight from the browser (WebRTC); optional transcription and call summaries.
Digital health twin (MVP in production)
Own product: training, nutrition and sleep data drive a digital twin - tracking, sober projections, progress compared over time.
Architecture graph of a codebase
Interactive graph built straight from source: 2,441 nodes, 197 clusters, function and database relationships - a tool for reviews, handovers and onboarding.
§ 05
Governance & trust
Regulatory focus
Security as a governance duty: access and vendor control, incident analysis, reporting lines to leadership - lived practice in international environments with data-protection and export-compliance requirements. Not a list of tools, but accountability.
Legal background
Legal education complementing the technical career: contracts, liability, compliance and vendor control are handled with a legal eye - a working advantage in regulated environments.
Verifiability
Raised in Austria, based in Vienna; German as a native language. References on request; ready for background screening. Work strictly within the legal framework - including environments with sanctions and export-compliance requirements.
Way of working
The real problem first. Build systems that stay operable. Total cost, not purchase price. Verify results personally - responsibility does not end with the presentation.
§ 06
Career
- 2025 - today
IT Security Manager - T&F Agriculture GmbH, Vienna
Responsible for IT operations and information security; continuation of international infrastructure and security programmes.
- 2019 - 2024
CISO - GroupDF International, Vienna
IT security and infrastructure strategy across 7+ countries; operational continuity and secured communications in a geopolitically demanding environment.
- 2014 - 2017
CIO - MIPT Center for Engineering & Technology (research campus)
Full infrastructure from scratch; IT design for a new R&D facility; building the IT organisation.
- 2013
Head of IT Helpdesk / ITSM - RWGG (international legal services)
Global 24/7 support function built from zero, aligned with ITIL.
- 2011 - 2013
CIO - Transkor-K (industrial monitoring, oil & gas)
Recovery and modernisation of a deteriorated IT landscape; AD, communications, security.
- 2001 - 2011
Systems engineering & early leadership
Banking-grade processing environments, Solaris/Oracle, AV and digital-signage systems (Digisky), international vendors - including interim IT director roles.
Full CV with company names available to recruiters; references on request after an initial conversation.
Legal notice
Media owner and responsible for the content: Grigory Sipachev, Vienna, Austria. Contact: grigory@sipachev.com.
Purpose of this site: presenting my professional record and my availability for work. Disclosure under § 25 of the Austrian Media Act (small website). This site does not offer paid services and is not a means of concluding contracts.
Privacy policy
Controller: Grigory Sipachev, Vienna, Austria, grigory@sipachev.com.
No cookies, no tracking. This site sets no cookies, uses no analytics or marketing tools and embeds no third-party content. Fonts are served locally - opening the page creates no connections to external servers.
Server log files. The hosting provider stores technically necessary access data (IP address, timestamp, file requested, browser type). The legal basis is Art. 6(1)(f) GDPR - legitimate interest in secure and reliable operation. The provider is bound as a processor under Art. 28 GDPR. This data is not combined with other sources.
Contacting me. If you write to me by e-mail, your details are used solely to handle your enquiry (Art. 6(1)(b) and (f) GDPR) and are deleted once no longer needed and no statutory retention period applies.
Your rights. Access, rectification, erasure, restriction of processing, data portability and objection - informally by e-mail. You may lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dsb.gv.at.