For over 8 years, I've helped organisations build resilient, secure IT environments.
I specialise in security analysis and auditing, and currently also work as a Security Manager. I build and run security programs: from SOC operations and Threat Intelligence, through risk analysis and business continuity planning (BCP), to internal and external audits and compliance (incl. NIS2/KSC2, ISO 27001).
Work History
-
Jan 2025 - Jun 2026
Security Manager & Security Consultant
Tenesys Sp. z o.o.
Security Manager / vCISO (dedicated client engagement)
Mar 2025 - Jun 2026
- Acting as virtual CISO for a logistics-tech group - owning the security program end-to-end and reporting directly to the Management Board.
- Developing and maintaining the Business Continuity Plan (BCP), including Business Impact Analysis (BIA) surveys across all group companies.
- Leading the penetration testing programme (web, API, infrastructure) with an external vendor - from scoping, through report review, to remediation tracking with development teams.
- Designing and rolling out the organisation's AI usage policy, including an AI tool register, GDPR/data-residency assessment, and board-level presentations.
- Performing periodic access reviews and driving the remediation process.
- Planning the MDM and EDR rollout and defining device configuration policies.
- Creating the annual and long-term security roadmap with KPIs, and monitoring progress against the group's security objectives.
- Creating a group-wide cybersecurity status matrix (heatmap) mapping implemented security controls across all group companies, giving the board a consolidated view of cyber risk.
- Owning the security budget: cost planning and tracking, plus licensing recommendations (e.g. Microsoft 365).
- Managing vendor selection and procurement for security tooling and services (SOC/SIEM provider, WAF, penetration-testing vendor), including RFQs and offer evaluation.
- Managing a multi-entity VPN consolidation project, including access-matrix design and coordination with infrastructure providers.
- Documenting the scope of work and handing it over to a successor upon transition off the engagement.
Security Consultant – Security Service Line Development & Management
Jan 2025 - May 2026
- Co-building the company's SOC/security service line: designing service offerings (SOC-as-a-Service, Security-Officer-as-a-Service, vulnerability scanning) and delivery methodology.
- Configuring and tuning SIEM platforms (Microsoft Sentinel, Wazuh), including detection rule development and third-party integrations.
- Monitoring and analysing the threat and attack landscape to inform detection engineering and client advisories.
- Evaluating and piloting XDR/EDR and vulnerability-scanning tools, producing technical assessments and cost estimates to support service pricing.
- Delivering internal cybersecurity training and public webinars (e.g. ransomware attack scenarios) for security awareness.
- Developing audit methodology and service scoping frameworks for NIS2, ISO 27001 and DORA compliance offerings.
Pre-sales Security Consultant
Jan 2025 - May 2026
- Providing pre-sales technical support across 50+ prospective clients spanning retail, financial services, logistics, manufacturing, public sector, healthcare and aviation.
- Scoping and quoting SOC, NIS2, ISO 27001, DORA and CISO-as-a-Service engagements in response to client RFQs.
- Preparing commercial proposals and technical write-ups in collaboration with the sales team.
- Conducting initial security assessments and technical discovery calls with prospects to define engagement scope and pricing.
- Creating technical marketing content (service descriptions, articles) supporting the growth of the security practice.
Security Consultant – Client Delivery Projects
Jan 2025 - May 2026
- Implementing Data Loss Prevention (DLP) and Identity/Mobile Device Management (MDM/IAM) solutions for an international premium cigar and luxury brand distribution company - from initial setup and configuration to documentation.
- Deploying and configuring MDM and XDR/EDR solutions for clients in banking and retail (e.g. Microsoft Intune, Bitdefender GravityZone, Microsoft Defender), including endpoint enrolment and remote user support.
- Developing detection rules and use cases in Microsoft Sentinel for a banking-sector client.
- Supporting a bookstore retail chain with a security roadmap, XDR/Defender rollout, and infrastructure security review (backup, VPN, monitoring).
- Supporting incident response and remediation following a ransomware attack for a group of technology companies providing software development, hosting and IT services for business clients.
- Managing project delivery: planning, client meetings, and documentation across multiple parallel engagements.
Security Consultant – Internal
Jan 2025 - May 2026
- Acting as Information Security Coordinator Deputy, supporting internal (first-party) ISO 27001 audits and continuous-improvement actions.
- Analysing internal security incidents and threats, and coordinating remediation actions.
- Conducting internal cybersecurity training and data-protection awareness sessions for new and existing employees.
- Administering the internal MDM/Apple Business Manager environment for company devices and enforcing security-policy compliance on personal devices.
Auditor (second-party audits)
Dec 2025 - May 2026
- Conducting NIS2 "zero audits" and ISO 27001 gap assessments for clients across sectors including aviation, food manufacturing, telecommunications, industrial manufacturing, waste management, and public administration.
- Preparing detailed audit reports with findings, risk ratings and remediation recommendations, and presenting results to client stakeholders.
- Delivering security risk assessments, including kick-off workshops and structured analysis of identified risks.
- Supporting clients with regulatory/compliance documentation, including data-protection incident reporting.
-
Feb 2023 - Jan 2025
SOC Analyst L3 / CTI Analyst
Trecom Spółka Akcyjna sp. k.
SOC Analyst L3
Feb 2023 - Jan 2025
- Real-time monitoring, analysis and prioritisation of security events, and implementing remediation actions based on incident analysis.
- Preparing recommendations related to incident prevention.
- Participating in the Incident Response process and producing security reports.
- Creating incident-response scenarios for staff, plus internal procedures and guidelines.
- Threat hunting in logs using open-source tools.
- Analysis of user reports related to email security.
- Setting up the vulnerability management process framework, participating in vulnerability analysis, defining root cause, and supporting remediation activities.
- Maintaining the knowledge base and proactively sharing information between team members.
- Organising team work and implementing tools such as Jira (task management), Sling (shift scheduling) and BookStack (documentation).
- Onboarding new team members and arranging the team schedule.
- Coordinating SIEM tool implementation in client organisations from the SOC team's perspective.
- Configuring the SIEM tool and troubleshooting issues in client environments.
- Preparing detailed, personalised reports and statistics per client requirements.
CTI Analyst
Sep 2023 - Jan 2025
- Preparing the base framework for tactical and technical threat intelligence.
- Coordinating the CTI process - from data gathering to threat monitoring.
- Gathering data on techniques, tactics and procedures used by attackers, high-impact vulnerabilities, and the latest attacks, and sharing it with the team for threat hunting and SIEM monitoring.
- Gathering client requirements for their future cyber threat intelligence (CTI) process.
- Delivering warnings about the latest cyber threats and vulnerabilities.
- Implementing a threat-feed platform in the organisation (OpenCTI).
-
Jun 2023 - Oct 2023
Teacher & Mentor
iCode Trust Sp. z o.o. (Future Collars)
- Delivering and mentoring the Cybersecurity course program across six modules: security fundamentals, threat intelligence, phishing analysis, post-breach/forensic analysis, monitoring & SIEM, and incident management - including the creation of comprehensive lesson plans and study materials.
- Mentoring course participants individually, tracking progress and supporting their transition into cybersecurity careers.
-
Feb 2022 - Jan 2023
SOC Analyst L2
Sportradar Polska Sp. z o.o.
- Real-time monitoring, analysis and prioritisation of security events, and implementing remediation actions based on incident analysis.
- Analysis of user reports related to email security.
- Participating in the Incident Response process and producing security reports.
- Creating internal procedures and guidelines.
- Setting up the vulnerability management process framework, participating in vulnerability analysis, defining root cause, and supporting remediation activities.
- Supporting vendor assessments from a security perspective.
- Running a Threat Intelligence pilot (POC) at the company:
- gathering requirements from leadership,
- preparing the base framework for tactical and technical threat intelligence,
- gathering data on techniques, tactics and procedures used by attackers, high-impact vulnerabilities (especially zero-day and actively exploited), and the latest attacks (e.g. phishing, malware and ransomware campaigns),
- producing monthly threat-briefing reports with risk-impact and likelihood assessments,
- participating in the future vendor assessment.
-
Jun 2020 - Jan 2022
Junior SOC Analyst → SOC Analyst
Centrum Elektronicznych Usług Płatniczych eService Sp. z o.o.
SOC Analyst
Jul 2021 - Jan 2022
- Real-time monitoring, analysis and prioritisation of security events, and implementing remediation actions based on incident analysis.
- Processing and analysis of DLP incidents.
- Analysis of user reports related to email security.
- Participating in the Incident Response process.
- Creating internal procedures and guidelines.
- Arranging the team schedule (EU and USA).
- Performing and organising user access reviews for internal applications.
- Onboarding new team members.
Junior SOC Analyst
Jun 2020 - Jun 2021
- Real-time monitoring, analysis and prioritisation of security events, and implementing remediation actions based on incident analysis.
- Processing and analysis of DLP incidents.
- Analysis of user reports related to email security.
- Supporting analysts in the Incident Response process.
-
Feb 2019 - May 2020
Junior IT Security Auditor
Roedl Outsourcing Sp. z o.o.
- Supporting the legal team during GDPR audits.
- Vulnerability assessment of the client's environment.
- Physical security assessment.
- Assessment of the client's security policies and related documentation.
- Organising a phishing campaign as part of the security-awareness programme.
-
Jul 2016 - Jan 2019
Junior Software Engineer → Junior IT Security Specialist
Cybercom Poland Sp. z o.o.
Junior IT Security Specialist
Apr 2018 - Jan 2019
- Supporting the legal team during GDPR audits.
- Vulnerability assessment of the client's environment.
- Physical security assessment.
- Assessment of the client's security policies and related documentation.
Junior Software Engineer
Jul 2016 - Mar 2018
- Testing applications based on Bluetooth technology.
- Preparing test scenarios.
- Supporting second-line client support.
Certificates
Industry certifications validating my cybersecurity expertise.
ISO/IEC 27001:2023 Lead Auditor
EC-Council CTIA (Certified Threat Intelligence Analyst)
Splunk Core Certified User
SecurityX
CompTIA CySA+
CompTIA Security+
CompTIA Network+
ISTQB Foundation Level
Skills
An overview of the competencies I use in my daily work.
Security Operations & Analysis
Governance & Compliance
Service Delivery & Deployment
Languages
Tools
Tools I have hands-on experience deploying and operating.
Vulnerability scanners
SIEM / SOAR
NDR & network security
DLP
Cloud & identity
EDR / XDR
MDM / UEM
Threat Intelligence
Collaboration & documentation
Education
Formal education in computer science and cybersecurity.









