Professional Summary

I audit organizations against NIS2 requirements and architect the Zero Trust roadmaps that close the gaps. GIAC-certified across eight domains, including Defensible Security Architecture (GDSA, Zero Trust) and Cloud Security Automation (GCSA, earned with honors). GIAC Advisory Board member, an invitation reserved for exam scores of 90 or above. 10+ years of security work spanning U.S. federal agencies, financial services, and EU environments.

If your organization falls under NIS2 and you want a gap assessment or a Zero Trust architecture review, email me directly. No intake forms, no sales layer. You talk to the auditor.

Przeprowadzam audyty organizacji pod kątem wymagań NIS2 i architektury Zero Trust zamykające luki bezpieczeństwa. Certyfikowany GIAC w ośmiu domenach, w tym Defensible Security Architecture (GDSA, Zero Trust) i Cloud Security Automation (GCSA, uzyskany z wyróżnieniem). Członek GIAC Advisory Board, do którego zaproszenie otrzymują wyłącznie osoby z wynikiem egzaminu 90+. Ponad 10-letnie doświadczenie w bezpieczeństwie w agencjach federalnych USA, usługach finansowych i środowiskach europejskich.

Jeśli Twoja organizacja podlega NIS2 i chcesz oceny luk lub przeglądu architektury Zero Trust, napisz do mnie bezpośrednio. Żadnych formularzy wstępnych, brak warstwy sprzedaży. Rozmawiam z audytorem.

Why NIS2, Why Now

The law is already in force. Poland’s amended National Cybersecurity System Act (the KSC Act), which implements NIS2, took effect on April 3, 2026. It covers roughly 42,000 companies across 18 sectors: energy, transport, banking, healthcare, digital infrastructure, manufacturing, public administration, and more.

The deadlines are close.

  • October 3, 2026: covered entities must self-identify and register with the authorities.
  • April 2027: risk-management measures, security controls, and incident-reporting processes must be fully in place.
  • April 2028: first mandatory security audits.

The penalties are real. Fines reach 10 million EUR or 2% of global turnover for essential entities, and management can be held personally liable for compliance failures.

If you have not yet confirmed whether your organization is covered, that is the first conversation to have. It costs you one email.

Prawo jest już w mocy. Nowelizowana polska Ustawa o Krajowym Systemie Cyberbezpieczeństwa (Ustawa KSC), która wdraża NIS2, weszła w życie 3 kwietnia 2026 r. Obejmuje około 42 000 firm w 18 sektorach: energetyka, transport, bankowość, opieka zdrowotna, infrastruktura cyfrowa, produkcja, administracja publiczna i inne.

Terminy są bliskie.

  • 3 października 2026 r.: podmioty objęte muszą się zidentyfikować i zarejestrować u władz.
  • Kwiecień 2027: środki zarządzania ryzykiem, kontrole bezpieczeństwa i procesy raportowania incydentów muszą być w pełni wdrożone.
  • Kwiecień 2028: pierwsze obowiązkowe audyty bezpieczeństwa.

Kary są rzeczywiste. Grzywny sięgają 10 milionów EUR lub 2% światowego obrotu dla podmiotów istotnych, a kierownictwo może być osobiście odpowiedzialne za niepowodzenie w zakresie zgodności.

Jeśli nie potwierdzono jeszcze, czy Twoja organizacja jest objęta, to jest pierwsza rozmowa do przeprowadzenia. Kosztuje cię jedną wiadomość e-mail.

How I Can Help Your Organization

NIS2 gap assessment. I map your current controls against the directive’s risk-management measures and incident-reporting duties, then deliver a prioritized, evidence-based findings report your leadership can act on.

Zero Trust architecture review and roadmap. Target architectures grounded in NIST SP 800-207 and defensible security architecture principles: identity, network segmentation, least-privilege access, and monitoring, sequenced so each step reduces real risk.

Penetration testing and full-access audits. GWAPT-certified (with honors) web application testing with OWASP Top Ten coverage, plus full-access (white-box) audits that show what a malicious insider or compromised account could actually reach: identity permissions, lateral movement paths, and sensitive data exposure. Clear remediation reports your teams can act on, with findings that map back to your compliance evidence, not a theatrical red-team exercise.

Audit readiness. Documentation, evidence collection, POA&M management, and incident-response tabletop exercises, so the real assessment holds no surprises.

Cloud and identity security. Hands-on reviews of Azure, AWS, and Microsoft Entra ID environments, from account audits to vulnerability management programs.

Frameworks I work in: NIS2, DORA, GDPR (Article 32 security measures), the EU Cyber Resilience Act, ISO/IEC 27001, NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-207 (Zero Trust), CIS Critical Security Controls, and the OWASP Top Ten.

Ocena luk NIS2. Mapuję Twoje obecne kontrole w stosunku do miar zarządzania ryzykiem dyrektywy i obowiązków raportowania incydentów, a następnie dostarczam priorytetowy, oparty na dowodach raport z ustaleniami, na które Twoje kierownictwo może działać.

Przegląd architektury Zero Trust i mapa drogowa. Architektura docelowa oparta na NIST SP 800-207 i zasadach defensywnej architektury bezpieczeństwa: tożsamość, segmentacja sieci, dostęp z najmniejszymi uprawnieniami i monitorowanie, zaplanowane tak, aby każdy krok zmniejszał rzeczywiste ryzyko.

Testowanie penetracyjne i audyty z pełnym dostępem. Testowanie aplikacji internetowych certyfikowane GWAPT (z wyróżnieniem) z pokryciem OWASP Top Ten, plus audyty z pełnym dostępem (white-box) pokazujące, co rzeczywiście mogą osiągnąć złośliwy insider lub skompromitowane konto: uprawnienia tożsamości, ścieżki ruchu bocznego i ekspozycja czułych danych. Jasne raporty o środkach naprawczych, na które Twoje zespoły mogą działać, z ustaleniami odwzorowanymi na dowodach zgodności, a nie na ćwiczeniu red-team.

Gotowość do audytu. Dokumentacja, zbieranie dowodów, zarządzanie POA&M i ćwiczenia symulujące reagowanie na incydenty, aby rzeczywista ocena nie niosła żadnych niespodzianek.

Bezpieczeństwo chmury i tożsamości. Praktyczne przeglądy środowisk Azure, AWS i Microsoft Entra ID, od audytów kont do programów zarządzania lukami w zabezpieczeniach.

Ramy, w których pracuję: NIS2, DORA, GDPR (artykuł 32 – środki bezpieczeństwa), Ustawa UE o odporności cybernetycznej, ISO/IEC 27001, Framework Cyberbezpieczeństwa NIST, NIST SP 800-53, NIST SP 800-207 (Zero Trust), CIS Critical Security Controls i OWASP Top Ten.

Results From Real Engagements

No invented testimonials here. These are anonymized, verifiable outcomes from my security and audit work in U.S. federal and financial-services environments.

Tutaj nie ma wymyślonych rekomendacji. To są zanonimizowane, weryfikowalne wyniki mojej pracy w zakresie bezpieczeństwa i audytu w agencjach federalnych USA i środowiskach usług finansowych.

7 systems

Continuous federal compliance

Kept seven U.S. federal systems audit-ready in XACTA, closed 15+ POA&Ms, and maintained ~90% security-documentation compliance.

500+ accounts

Identity audit that caught intruders

Audited 500+ Microsoft Entra ID accounts, uncovering 10+ unauthorized users and driving immediate corrective action.

20+ controls

Financial-services insider-threat audit

Evaluated 20+ internal-threat controls at a major U.S. financial institution and surfaced weak controls for targeted refinement.

3 gaps

Tabletop that changed priorities

Ran an incident-response exercise with 15+ participants that exposed three critical security gaps and triggered focused remediation.

Get Your NIS2 Compliance Checklist

Free 1-page checklist: 23 essential NIS2 controls mapped to your organization type (essential vs. important entity). No signup required, just your email.

No spam. One email per month with audit insights.

Frequently Asked Questions

What's the cost of a NIS2 gap assessment?

Cost depends on your organization size, sector classification (essential vs. important), and systems in scope. I provide a transparent fixed quote after a free 30-minute scoping call. No obligation, no sales layer.

How long does a NIS2 audit take?

A typical gap assessment runs 4–6 weeks: Weeks 1–2 (scoping & evidence), Weeks 3–4 (assessment & testing), Weeks 5–6 (findings & remediation roadmap). Larger organizations or multi-site deployments may run 8–10 weeks.

Do you work with SMEs or only large enterprises?

Both. NIS2's "important entity" tier is built around mid-sized companies, and the engagement scales to your size: a 50-person company gets a tightly scoped assessment, not an enterprise-shaped process.

What if we're not sure if NIS2 applies to us?

That's a free conversation. Email me your organization's size, sector, and main services. I'll tell you if NIS2 covers you, by what date, and what your first step should be. No obligation.

Can you help with incident response training?

Yes. I run incident-response tabletop exercises tailored to your sector and threat model, and I can help build or review your incident-response plan to meet NIS2 requirements.

Experiences

DevSecOps Engineer

Aug 2025 - Present
Decyda SRLS

• Engineered cloud security governance by deploying Cloud Custodian on AWS, writing custom Python-based policies to enforce compliance and auto-remediate risks.

• Executed penetration testing on web applications, identifying critical vulnerabilities and partnering with developers to patch code before production deployment.

• Deployed AI-based security guardrails within CI/CD pipelines, automatically blocking risky code changes and reducing manual code review time.

IT Cybersecurity Specialist

Jul 2024 - Jul 2025
Department of the Interior

• Audited 500+ Microsoft Entra ID accounts, uncovering 10+ unauthorized users and driving immediate corrective action.

• Kept seven federal systems continuously audit-ready in XACTA and closed 15+ POA&Ms to maintain regulatory alignment.

• Provided weekly Zero Trust architecture guidance (GDSA-certified) for transitioning cloud systems toward a Zero Trust maturity model.

• Led an incident-response tabletop exercise with 15+ participants that surfaced three critical security gaps.

IT/Cyber Security Auditor

May 2023 - July 2023
United Services Automobile Association (USAA)

• Evaluated 20+ security controls and recommended architectural changes that strengthened risk detection and incident response.

• Audited mobile application source code against the OWASP Top Ten, verifying secure coding practices and strengthening compliance review policies.

Technical Skills & Proficiencies

Compliance & Audit

NIS2 Readiness Assessment, Security Auditing, Compliance Frameworks (NIST, ISO 27001), XACTA, POA&M Management, Risk Assessment, Security Controls Assessment, Incident Response Tabletop Exercises, OWASP Top Ten

Zero Trust & Security Architecture

Zero Trust Maturity Models, Defensible Security Architecture (GDSA), Identity Security (Microsoft Entra ID), Least-Privilege Firewall Design, Vulnerability Management (Tenable, BigFix, Defender for Cloud), Splunk Threat Detection, Penetration Testing

Cloud & Infrastructure

Microsoft Azure, AWS, Cloud Security, Infrastructure Management, Virtual Machines, Network Security, Azure Active Directory, Microsoft Entra ID, Cloud Backup Solutions, Disaster Recovery

Latest Blog Posts

Sharing insights on cybersecurity, technology trends, and professional development.

View All Posts →

Site Security

This site is scanned weekly for secrets, vulnerabilities, and code security issues using open-source tools. View scan history on GitHub

Gitleaks
Secret Scanning
-
Exposed credentials, API keys, tokens
Trivy
Vulnerability Scan
-
HIGH & CRITICAL CVEs in dependencies
Semgrep
Static Analysis
-
Security issues in source code