
IT Security Consultant and Auditor
Wrocław Area, Poland

IT Security Consultant and Auditor
Wrocław Area, Poland
I am a Security Consultant with wide computer science knowledge and experience in security audits, risk management, creation of Business Continuity and Disaster Recovery Plans, policies and "best practice" documents.
Do not hesitate to contact me: marcin *at* engelmann.pl
My skills and knowledge include:
- detailed knowledge of security threats, vulnerabilities and methods of exploitation
- information risk management, creation of Business Continuity and Disaster Recovery Plans, policies and best practice documents
- theoretical and practical acquaintance with security problems of computer systems and networks (firewall, cryptography, deployment of Intrusion Detection and Prevention System software, designing secure LAN and WAN networks)
- knowledge of modern, TCP/IP based dynamic routing protocols (BGP, OSPF), IPv6 (new generation IP protocol) and network protocols design with an ability to provide the most suitable network architecture for a particular task
- understanding of challenges associated with securing electronic communication in distributed environments (cryptography, VPN, PKI)
- very good knowledge of Unix (Solaris, FreeBSD) and GNU/Linux (mostly Debian, Ubuntu, RedHat Enterprise Linux, CentOS) systems - configuration and advanced administration
- good knowledge of Microsoft Windows 2003 Server
- knowledge of advantages and disadvantages of free and commercial products
- ability to approach technology- and resource-related problems creatively, with a solid grasp on reality (and budget constraints)
Certificates:
- Certified Information Systems Auditor (CISA)
- preparing to CISSP (Certified Information Systems Security Professional) exam
Securing Computer Systems and Networks, Information Risk Management (ISO17799, BS7799-2), creation of Business Continuity and Disaster Recovery Plans, designing secure solutions, security testing, penetration testing, technology solutions consulting
(Non-Profit; 1-10 employees; Computer & Network Security industry)
September 2005 — Present (3 years 11 months)
Co-developing the Securityinfo portal – an IT security portal presenting available technologies and commenting on what is going on in the security world. Publishing articles in Polish.
(Self-Employed; 1-10 employees; Computer & Network Security industry)
January 2003 — Present (6 years 7 months)
- security penetration testing, security audits, consultations and reports
- creation of Business Continuity and Disaster Recovery Plans, policies and best practice documents, information risk management (according to ISO17799 and BS7799-2)
- creation of network scheme, conforming to security standards
- consultations related to processing personal data in accordance with the Personal Data Protection Act, conforming to the rules of Inspector General for the Protection of Personal Data (GIODO)
- customers:
* Wspolny Rynek Medyczny Sp. z o.o. http://rynekmedyczny.pl/ - design of hardware and software systems, security analysis
* General Consulting Sp. z o.o. http://generalconsulting.pl/ - encrypted repository for documents and classified files
* Bestgroup Sp. z o.o. http://bestgroup.com.pl/ - information security advisory
* Vpol.pl http://vpol.pl/ - web application security, infrastructure consultations, operating system virtualization software
(Partnership; 11-50 employees; Internet industry)
February 2005 — March 2007 (2 years 2 months)
- design of hardware (servers, network, SAN storage) and software infrastructure for Microsoft Solution for Hosted Messaging and Collaboration (Microsoft Exchange 2003 for 5000 mailboxes and SharePoint Services) and PEM (managing and billing system from SWsoft); acting as a Project Manager - coordination of all aspects of the projects
- design of a high performance, reliable hardware and software platform for a mass hosting services using Virtuozzo (OS virtualization solution form SWsoft) and based on self developed high availability grid/cluster of Linux servers
- elaboration and implementation of security policy for Internet Service Provider
- response to current security threats, investigation and resolving external and internal incidents
(Privately Held; 11-50 employees; Internet industry)
June 2004 — January 2007 (2 years 8 months)
- security advisory and consultations related to Livechat Contact Center communicator and server infrastructure
- installation and configuration of servers for customers of the company: Inteligo Financial Services S.A., PZU Zycie S.A., Commercial Union Powszechne Towarzystwo Emerytalne BPH CU WBK S.A. with fulfilment of all security constraints of these financial companies
(Privately Held; 1-10 employees; Internet industry)
September 2002 — July 2003 (11 months)
- installation, configuration and administration of servers, working under Linux and FreeBSD
- software analysis with regard to security - threatening errors
- multi-user groupware suite implementation (phpGroupWare, Tutos)
- using modern Internet technologies (jsp, xml, xslt) and software optimisation to best efficiency (Tomcat, Cocoon)
(Privately Held; 11-50 employees; Internet industry)
May 2000 — October 2001 (1 year 6 months)
- creation of portal's network scheme, conforming security standards using Cisco, Intel, 3Com hardware
- administration of Sun servers (Sparc, Solaris), database cluster Compaq Alphaserver (Alpha, Tru64 UNIX) and Compaq Proliant servers (Intel, GNU/Linux)
- installation, configuration, optimisation and administration of Oracle products (Oracle 8i Database, Oracle 9i Database, Internet Application Server 8i - jsp technology)
- advanced configuration and implementation of firewalls and Internet Detection System software
(Privately Held; 1-10 employees; Internet industry)
May 1999 — April 2000 (1 year)
- configuration of network services for customers of the company including making indispensable improvements
- elaboration and implementation of security policy for Internet Service Provider
- software development - control panel for managing customer services
Software Engineering 2006 — 2006
- Socrates-Erasmus student exchange programme
M.Sc. , Computer Science , 2001 — 2006
- Course "Software Integration" organized by Siemens Communications Software Development Center; lecture and practical; concentraded on software's testing methods, testing environment, quality verification, effort estimation and resources planning; grade: very good;
- Master's Thesis subject: "The Idea of Distributed Intrusion Prevention System in Corporate Networks"; grade: very good
artificial intelligence, stock market, science-fiction, RPG
ISSA, ISACA