
CISSP, CCSE Plus NG, RSA/CSE - SecurID
Warsaw Area, Poland

CISSP, CCSE Plus NG, RSA/CSE - SecurID
Warsaw Area, Poland
Expert in IT security organization and technology
The author of stunnel encrypting proxy
Security Management: ISO 27001 Lead Auditor qualification
Cryptography: protocols (SSL/TLS, IPsec, SSH, PGP) and algorithms (DES, AES, RSA, DH, EC)
Networking: expert knowledge of TCP/IP internals, firewalls (FireWall-1, IOS Firewall, iptables), routing (OSPF, EIGRP), GSM-related protocols (GTP, UCP)
Administration: HP-UX, Solaris, MacOS X, Linux, Cisco IOS
Network servers: Apache, Squid, Postfix, Sendmail, Qmail, Bind, FreeRADIUS, INN
Programming: C/C++, Assembler, Perl, PHP, Python, Shell
(Public Company; 10,001 or more employees; ABN; Banking industry)
January 2008 — Present (5 months)
Penetration testing of online banking systems worldwide: web applications, client-server applications, operating systems.
Reverse engineering: machine code, J2EE, Flash ActionScript.
Source code review: PHP, JavaScript.
(Public Company; 10,001 or more employees; ABN; Banking industry)
November 2006 — December 2007 (1 year 2 months)
Performed Technology Risk Analyst tasks in Technology Risk Accreditation Process: defined the scope of risk assessments, identified technology risks, and designed cost-effective changes to mitigate identified risks to an acceptable level.
Performed Operational Risk Assessment of FX/MM applications worldwide including EBS, Reuters and Bloomberg interfaces.
Co-authored global ABN AMRO IT security strategy: Public Key Infrastructure, Enterprise Identity and Access Management.
(Privately Held; 5001-10,000 employees; Telecommunications industry)
November 1998 — October 2006 (8 years)
Developed IT Security Policy based on ISO 17799 standard.
Designed identity management system, user accountability system and strong authentication solution based on SecurID tokens.
Designed and implemented a FreeRADIUS module for SMS-based strong authentication.
Designed security architecture for new systems including GPRS, WAP, Prepaid, Voicemail, SMSC, Lawful Interception (had Top Secret security clearance), Billing, CRM and Self-Care.
Worked on IT security audit (including penetration testing), incident management and forensics.
(Privately Held; 51-200 employees; Information Technology and Services industry)
June 1996 — October 1998 (2 years 5 months)
Supervised deployment and operations of LAN/WAN for Daewoo car sales in Poland (WAN based on Cisco routers, Frame Relay and VSAT/X.25 links).
Managed 10 HP-UX/PA-RISC and Solaris/SPARC servers, Informix databases.
Designed and implemented network perimeter security architecture for the whole Daewoo Corporation in Poland.
PhD, Cryptography, 2007 — 2011 (expected)
MSc, Computer Science, 2004 — 2005
Winner of Enigma competition for best thesis in cryptography and information security, 2005
BSc, Information Systems and Decision Support, 1992 — 2004
Free Software, Go, photography, Bible
PKN KT182 (national equivalent of ISO/IEC JTC1/SC27)
IEEE
(ISC)2 Certified Information System Security Professional (CISSP), 2007
ISO 27001 Lead Auditor qualification, 2007
Check Point Certified Security Expert Plus NG (CCSE Plus NG), 2003
RSA Certified Systems Engineer - SecurID (RSA/CSE - SecurID), 2000
Winner of Enigma competition for best thesis in cryptography and information security, 2005
Finalist of Trophées du Libre, 2005