CST-360: Protecting what matters

The people you actually get

Practitioners across methodology, cloud architecture, security engineering and GRC. No pyramid staffing: whoever scopes your work is who does it.

CST-360: Protecting what matters

The team

Architecture, engineering, governance & GRC

Oren Hadar

Oren Hadar

Founder & CEO · Cyber Security Methodologist

President of ISACA Israel, cyber security methodology expert and cyber risk policy maker with more than 25 years' experience. Previously a senior member of the Israeli Defense Forces cyber-defense doctrine development teams, where his work shaped security processes across the IDF, government bodies and commercial entities. Works with Fortune 500 companies, global enterprises, SMBs and stealth-mode startups.

MethodologyCyber risk policyGovernanceBoard advisory
Shlomi Halif

Shlomi Halif

CTO · Head of Architecture & Engineering

Cyber security architect and cloud solution expert with more than 10 years across IT, networking and cyber security. Managed projects in the IDF Mamram unit for four years, including end-to-end data migration from on-premise servers to Azure. Today he leads CST-360's technology services team.

Cloud architectureAzureSecurity engineeringMigrations
Uriel Zion

Uriel Zion

Cloud & Security Architect · AI & Automation

Cloud and security architect with more than a decade across infrastructure, DevOps and security, and a graduate of IDF Unit 81. In recent years he built and ran AI agents and local language models inside classified, air-gapped environments: precisely the settings where no data may leave and every control has to work locally. Before that he ran infrastructure and DevOps for technology and healthcare companies, including on-premise to cloud migrations and local test environments that cut roughly half a million shekels a year from cloud spend. At CST-360 he owns cloud and security architecture for clients, and the AI risk practice: mapping what is actually running inside an organisation, and how to govern it without stopping the work.

Cloud architectureDevOpsAI riskAutomation
Nissim Cohen

Nissim Cohen

Cloud Security Engineer

Cloud security engineer across Azure and AWS. Spent two years as a cloud engineer in the IDF's J6 & Cyber Defense Directorate, working on cloud infrastructure and networking (VNet, VPN, DNS and firewalls), identity management in Entra ID, and automation with Terraform and Azure DevOps. Holds three current Microsoft certifications: Azure Administrator, Endpoint Administrator and Information Security Administrator.

At CST-360 he covers two layers that work together. On the data layer: classification and labelling, DLP, permissions and identity, and insider risk controls — the controls that actually determine what an embedded AI tool such as Copilot can see and retrieve. On the endpoint layer, through Intune: compliance policy, device hardening, and detecting unapproved tools installed on the machine itself, including local models that generate no network traffic at all.

Cloud securityAzure & AWSIntune & endpointData protection & DLP
Ariel Halif

Ariel Halif

Cyber Security Engineer

Security engineering

Join the team

Open to strong practitioners

We hire for judgement, not certifications alone. If you work on cyber or AI risk in regulated environments, talk to us.

How we work

Security as a business process

Our mission is to leverage your business with cyber security: implementing security that enables business services and products rather than obstructing them. Two words guide the delivery: simplicity and professionalism.

Set a business-aligned security strategyThe strategy follows the business objectives, not the tooling catalogue.
Mitigate the risks that hit the financesWe prioritise by business consequence, so spend lands where exposure actually is.
Manage cyber security as a business processOwned, measured and reviewed like any other process: not a one-off project.