Aleksander Nowak
Senior Security Engineer
a.nowak@example.com · +48 512 000 142 · Warsaw, Poland · linkedin.com/in/example-profile · example.com/security
Skills
Penetration testing · Incident response · Threat hunting · Digital forensics
Splunk · Burp Suite · Metasploit · Wireshark
Crisis communication · Risk explanation · Training delivery
Six years of security operations and penetration testing in enterprise environments. I have worked across incident response, threat hunting and secure software lifecycle. I follow a finding through to remediation rather than leaving it in a report.
Work Experience
Senior Security Engineer
January 2022 – PresentEnterprise software company · Warsaw
- Rewrote the SIEM rule set; false positives fell from 71% to 18% and true incident detection rose 2.3×.
- Established a monthly threat hunting cycle mapped to MITRE ATT&CK; three persistence attempts found in the first year.
- Ran threat modelling on 14 critical applications, closing 63 high-risk findings before release.
Penetration Tester
June 2019 – December 2021Security consultancy · Kraków
- Carried out web and network penetration tests for 31 organisations and reported 12 critical findings.
- Built an automated asset discovery tool that cut test preparation from three days to four hours.
- Delivered secure coding training to client development teams, reaching 180 participants.
Security Operations Analyst
February 2018 – May 2019Telecoms operator · Kraków
- Triaged an average of 400 alerts a day on a 24/7 SOC rota.
- Built an automated quarantine flow for phishing campaigns; click-through fell from 9% to 2%.
- Institutionalised incident response exercises; mean time to detect fell from 41 minutes to 9.
Education
Warsaw University of Technology
MSc, Information Security · 4.5/5
Jagiellonian University
BSc, Computer Science · 4.2/5
Projects
Zero Trust Network Migration
Moved a 1,900-user environment to an identity-based access model. The lateral movement surface narrowed measurably and the VPN dependency was removed entirely.
Secure Software Pipeline
Integrated static analysis, dependency scanning and secret detection into CI so that findings reach developers rather than a quarterly report.
Certifications
- Offensive Security Certified Professional (OSCP)Offensive Security · 2023-03
- GIAC Certified Incident Handler (GCIH)GIAC · 2022-06
Languages
- Polish · Native
- English · Advanced
- German · Intermediate