Aleksander Nowak
Senior Security Engineer
a.nowak@example.com | +48 512 000 142 | Warsaw, Poland | linkedin.com/in/example-profile | example.com/security
Summary
Six years of security operations and penetration testing in enterprise environments. I have worked across incident response, threat hunting and secure software lifecycle. I follow a finding through to remediation rather than leaving it in a report.
Work Experience
Senior Security Engineer
January 2022 – PresentEnterprise software company · Warsaw
- Rewrote the SIEM rule set; false positives fell from 71% to 18% and true incident detection rose 2.3×.
- Established a monthly threat hunting cycle mapped to MITRE ATT&CK; three persistence attempts found in the first year.
- Ran threat modelling on 14 critical applications, closing 63 high-risk findings before release.
Penetration Tester
June 2019 – December 2021Security consultancy · Kraków
- Carried out web and network penetration tests for 31 organisations and reported 12 critical findings.
- Built an automated asset discovery tool that cut test preparation from three days to four hours.
- Delivered secure coding training to client development teams, reaching 180 participants.
Security Operations Analyst
February 2018 – May 2019Telecoms operator · Kraków
- Triaged an average of 400 alerts a day on a 24/7 SOC rota.
- Built an automated quarantine flow for phishing campaigns; click-through fell from 9% to 2%.
- Institutionalised incident response exercises; mean time to detect fell from 41 minutes to 9.
Education
Warsaw University of Technology
October 2016 – January 2018MSc, Information Security · 4.5/5
Jagiellonian University
October 2012 – June 2016BSc, Computer Science · 4.2/5
Skills
Penetration testing · Incident response · Threat hunting · Digital forensics · Splunk · Burp Suite · Metasploit · Wireshark · Crisis communication · Risk explanation · Training delivery
Projects
Zero Trust Network Migration
Moved a 1,900-user environment to an identity-based access model. The lateral movement surface narrowed measurably and the VPN dependency was removed entirely.
Secure Software Pipeline
Integrated static analysis, dependency scanning and secret detection into CI so that findings reach developers rather than a quarterly report.
Certifications
- Offensive Security Certified Professional (OSCP)Offensive Security · 2023-03
Languages
- Polish · Native
- English · Advanced
- German · Intermediate