For over 8 years, I've helped organisations build resilient, secure IT environments.

I specialise in security analysis and auditing, and currently also work as a Security Manager. I build and run security programs: from SOC operations and Threat Intelligence, through risk analysis and business continuity planning (BCP), to internal and external audits and compliance (incl. NIS2/KSC2, ISO 27001).

Work History

Present
  1. Jan 2025 - Jun 2026

    Security Manager & Security Consultant

    Tenesys Sp. z o.o.

    Security Manager / vCISO (dedicated client engagement)

    Mar 2025 - Jun 2026

    • Acting as virtual CISO for a logistics-tech group - owning the security program end-to-end and reporting directly to the Management Board.
    • Developing and maintaining the Business Continuity Plan (BCP), including Business Impact Analysis (BIA) surveys across all group companies.
    • Leading the penetration testing programme (web, API, infrastructure) with an external vendor - from scoping, through report review, to remediation tracking with development teams.
    • Designing and rolling out the organisation's AI usage policy, including an AI tool register, GDPR/data-residency assessment, and board-level presentations.
    • Performing periodic access reviews and driving the remediation process.
    • Planning the MDM and EDR rollout and defining device configuration policies.
    • Creating the annual and long-term security roadmap with KPIs, and monitoring progress against the group's security objectives.
    • Creating a group-wide cybersecurity status matrix (heatmap) mapping implemented security controls across all group companies, giving the board a consolidated view of cyber risk.
    • Owning the security budget: cost planning and tracking, plus licensing recommendations (e.g. Microsoft 365).
    • Managing vendor selection and procurement for security tooling and services (SOC/SIEM provider, WAF, penetration-testing vendor), including RFQs and offer evaluation.
    • Managing a multi-entity VPN consolidation project, including access-matrix design and coordination with infrastructure providers.
    • Documenting the scope of work and handing it over to a successor upon transition off the engagement.

    Security Consultant – Security Service Line Development & Management

    Jan 2025 - May 2026

    • Co-building the company's SOC/security service line: designing service offerings (SOC-as-a-Service, Security-Officer-as-a-Service, vulnerability scanning) and delivery methodology.
    • Configuring and tuning SIEM platforms (Microsoft Sentinel, Wazuh), including detection rule development and third-party integrations.
    • Monitoring and analysing the threat and attack landscape to inform detection engineering and client advisories.
    • Evaluating and piloting XDR/EDR and vulnerability-scanning tools, producing technical assessments and cost estimates to support service pricing.
    • Delivering internal cybersecurity training and public webinars (e.g. ransomware attack scenarios) for security awareness.
    • Developing audit methodology and service scoping frameworks for NIS2, ISO 27001 and DORA compliance offerings.

    Pre-sales Security Consultant

    Jan 2025 - May 2026

    • Providing pre-sales technical support across 50+ prospective clients spanning retail, financial services, logistics, manufacturing, public sector, healthcare and aviation.
    • Scoping and quoting SOC, NIS2, ISO 27001, DORA and CISO-as-a-Service engagements in response to client RFQs.
    • Preparing commercial proposals and technical write-ups in collaboration with the sales team.
    • Conducting initial security assessments and technical discovery calls with prospects to define engagement scope and pricing.
    • Creating technical marketing content (service descriptions, articles) supporting the growth of the security practice.

    Security Consultant – Client Delivery Projects

    Jan 2025 - May 2026

    • Implementing Data Loss Prevention (DLP) and Identity/Mobile Device Management (MDM/IAM) solutions for an international premium cigar and luxury brand distribution company - from initial setup and configuration to documentation.
    • Deploying and configuring MDM and XDR/EDR solutions for clients in banking and retail (e.g. Microsoft Intune, Bitdefender GravityZone, Microsoft Defender), including endpoint enrolment and remote user support.
    • Developing detection rules and use cases in Microsoft Sentinel for a banking-sector client.
    • Supporting a bookstore retail chain with a security roadmap, XDR/Defender rollout, and infrastructure security review (backup, VPN, monitoring).
    • Supporting incident response and remediation following a ransomware attack for a group of technology companies providing software development, hosting and IT services for business clients.
    • Managing project delivery: planning, client meetings, and documentation across multiple parallel engagements.

    Security Consultant – Internal

    Jan 2025 - May 2026

    • Acting as Information Security Coordinator Deputy, supporting internal (first-party) ISO 27001 audits and continuous-improvement actions.
    • Analysing internal security incidents and threats, and coordinating remediation actions.
    • Conducting internal cybersecurity training and data-protection awareness sessions for new and existing employees.
    • Administering the internal MDM/Apple Business Manager environment for company devices and enforcing security-policy compliance on personal devices.

    Auditor (second-party audits)

    Dec 2025 - May 2026

    • Conducting NIS2 "zero audits" and ISO 27001 gap assessments for clients across sectors including aviation, food manufacturing, telecommunications, industrial manufacturing, waste management, and public administration.
    • Preparing detailed audit reports with findings, risk ratings and remediation recommendations, and presenting results to client stakeholders.
    • Delivering security risk assessments, including kick-off workshops and structured analysis of identified risks.
    • Supporting clients with regulatory/compliance documentation, including data-protection incident reporting.
  2. Feb 2023 - Jan 2025

    SOC Analyst L3 / CTI Analyst

    Trecom Spółka Akcyjna sp. k.

    SOC Analyst L3

    Feb 2023 - Jan 2025

    • Real-time monitoring, analysis and prioritisation of security events, and implementing remediation actions based on incident analysis.
    • Preparing recommendations related to incident prevention.
    • Participating in the Incident Response process and producing security reports.
    • Creating incident-response scenarios for staff, plus internal procedures and guidelines.
    • Threat hunting in logs using open-source tools.
    • Analysis of user reports related to email security.
    • Setting up the vulnerability management process framework, participating in vulnerability analysis, defining root cause, and supporting remediation activities.
    • Maintaining the knowledge base and proactively sharing information between team members.
    • Organising team work and implementing tools such as Jira (task management), Sling (shift scheduling) and BookStack (documentation).
    • Onboarding new team members and arranging the team schedule.
    • Coordinating SIEM tool implementation in client organisations from the SOC team's perspective.
    • Configuring the SIEM tool and troubleshooting issues in client environments.
    • Preparing detailed, personalised reports and statistics per client requirements.

    CTI Analyst

    Sep 2023 - Jan 2025

    • Preparing the base framework for tactical and technical threat intelligence.
    • Coordinating the CTI process - from data gathering to threat monitoring.
    • Gathering data on techniques, tactics and procedures used by attackers, high-impact vulnerabilities, and the latest attacks, and sharing it with the team for threat hunting and SIEM monitoring.
    • Gathering client requirements for their future cyber threat intelligence (CTI) process.
    • Delivering warnings about the latest cyber threats and vulnerabilities.
    • Implementing a threat-feed platform in the organisation (OpenCTI).
  3. Jun 2023 - Oct 2023

    Teacher & Mentor

    iCode Trust Sp. z o.o. (Future Collars)

    • Delivering and mentoring the Cybersecurity course program across six modules: security fundamentals, threat intelligence, phishing analysis, post-breach/forensic analysis, monitoring & SIEM, and incident management - including the creation of comprehensive lesson plans and study materials.
    • Mentoring course participants individually, tracking progress and supporting their transition into cybersecurity careers.
  4. Feb 2022 - Jan 2023

    SOC Analyst L2

    Sportradar Polska Sp. z o.o.

    • Real-time monitoring, analysis and prioritisation of security events, and implementing remediation actions based on incident analysis.
    • Analysis of user reports related to email security.
    • Participating in the Incident Response process and producing security reports.
    • Creating internal procedures and guidelines.
    • Setting up the vulnerability management process framework, participating in vulnerability analysis, defining root cause, and supporting remediation activities.
    • Supporting vendor assessments from a security perspective.
    • Running a Threat Intelligence pilot (POC) at the company:
      • gathering requirements from leadership,
      • preparing the base framework for tactical and technical threat intelligence,
      • gathering data on techniques, tactics and procedures used by attackers, high-impact vulnerabilities (especially zero-day and actively exploited), and the latest attacks (e.g. phishing, malware and ransomware campaigns),
      • producing monthly threat-briefing reports with risk-impact and likelihood assessments,
      • participating in the future vendor assessment.
  5. Jun 2020 - Jan 2022

    Junior SOC Analyst → SOC Analyst

    Centrum Elektronicznych Usług Płatniczych eService Sp. z o.o.

    SOC Analyst

    Jul 2021 - Jan 2022

    • Real-time monitoring, analysis and prioritisation of security events, and implementing remediation actions based on incident analysis.
    • Processing and analysis of DLP incidents.
    • Analysis of user reports related to email security.
    • Participating in the Incident Response process.
    • Creating internal procedures and guidelines.
    • Arranging the team schedule (EU and USA).
    • Performing and organising user access reviews for internal applications.
    • Onboarding new team members.

    Junior SOC Analyst

    Jun 2020 - Jun 2021

    • Real-time monitoring, analysis and prioritisation of security events, and implementing remediation actions based on incident analysis.
    • Processing and analysis of DLP incidents.
    • Analysis of user reports related to email security.
    • Supporting analysts in the Incident Response process.
  6. Feb 2019 - May 2020

    Junior IT Security Auditor

    Roedl Outsourcing Sp. z o.o.

    • Supporting the legal team during GDPR audits.
    • Vulnerability assessment of the client's environment.
    • Physical security assessment.
    • Assessment of the client's security policies and related documentation.
    • Organising a phishing campaign as part of the security-awareness programme.
  7. Jul 2016 - Jan 2019

    Junior Software Engineer → Junior IT Security Specialist

    Cybercom Poland Sp. z o.o.

    Junior IT Security Specialist

    Apr 2018 - Jan 2019

    • Supporting the legal team during GDPR audits.
    • Vulnerability assessment of the client's environment.
    • Physical security assessment.
    • Assessment of the client's security policies and related documentation.

    Junior Software Engineer

    Jul 2016 - Mar 2018

    • Testing applications based on Bluetooth technology.
    • Preparing test scenarios.
    • Supporting second-line client support.
...

Certificates

Industry certifications validating my cybersecurity expertise.

ISO/IEC 27001

ISO/IEC 27001:2023 Lead Auditor

EC-Council CTIA

EC-Council CTIA (Certified Threat Intelligence Analyst)

Splunk

Splunk Core Certified User

CompTIA SecurityX

SecurityX

formerly CASP+ (CompTIA Advanced Security Practitioner)

CompTIA CySA+

CompTIA CySA+

CompTIA Security+

CompTIA Security+

CompTIA Network+

CompTIA Network+

ISTQB

ISTQB Foundation Level

Skills

An overview of the competencies I use in my daily work.

Security Operations & Analysis

  • Information Security
  • Security audit
  • Security analysis
  • Email security analysis
  • Vulnerability assessment
  • Incident Response
  • Risk assessment
  • Threat Intelligence

Governance & Compliance

  • Business Continuity Planning (BCP)
  • Business Impact Analysis (BIA)
  • NIS2 / DORA / ISO 27001 Compliance
  • AI Governance & AI Usage Policy
  • Board-level Reporting
  • Vendor & Budget Management
  • Cybersecurity Due Diligence

Service Delivery & Deployment

  • MDM/XDR Deployment
  • Documentation creation
  • Pre-sales & solution scoping

Languages

  • Polish - Native
  • English - B2

Tools

Tools I have hands-on experience deploying and operating.

Vulnerability scanners

  • Tenable Nessus
  • Greenbone OpenVAS

SIEM / SOAR

  • Splunk
  • ArcSight
  • Microsoft Sentinel
  • KQL
  • Wazuh
  • Swimlane

NDR & network security

  • Vectra AI Platform
  • Cisco Secure Network Analytics (Stealthwatch)

DLP

  • Forcepoint DLP
  • Symantec DLP

Cloud & identity

  • AWS GuardDuty
  • Microsoft Entra ID

EDR / XDR

  • Microsoft Defender
  • Bitdefender GravityZone
  • Cisco Secure Endpoint (AMP)
  • ESET Inspect

MDM / UEM

  • Microsoft Intune
  • Apple Business Manager
  • Mosyle

Threat Intelligence

  • OpenCTI
  • MISP
  • Group-IB (Attack Surface Management)

Collaboration & documentation

  • Microsoft 365
  • Proofpoint (TAP, TRAP)
  • Confluence & Jira
  • BookStack
  • ServiceNow
  • Outkept

Education

Formal education in computer science and cybersecurity.

Lazarski University

Cybersecurity and Computer Forensics

Postgraduate studies
Lazarski University · 2020–2021

University of Lodz

Computer Science

Bachelor's degree
University of Lodz · 2014–2017

Specialization: Computer networks and data processing

Let's talk about working together

I'll only use your details to reply to your message.

Privacy notice (GDPR)

The controller of the personal data you enter in this form (name, email address, message) is Kamila Pańczuk — you can reach me at the email address shown next to the form. I process this data only to reply to your message and continue the correspondence, based on my legitimate interest (Art. 6(1)(f) GDPR), and — if your message concerns working together — to take steps prior to entering into a contract (Art. 6(1)(b) GDPR). Messages are stored in the Google Workspace email service; the website is hosted by LH.pl. I keep the data for the duration of our correspondence and no longer than 12 months afterwards, unless we start working together. You have the right to access, rectify and erase your data, to restrict processing, to object, and to lodge a complaint with the Polish supervisory authority (Prezes UODO). Providing the data is voluntary, but I cannot reply without it.