Krzysztof Swidrak

Krzysztof Swidrak

Cyber Security Consulting

Helping enterprises build resilient security programs across cloud, identity, and DevSecOps.

Governance Risk and Compliance Services

Comprehensive security advisory in governance, risk management, and compliance (GRC) for enterprise environments based on ISO27001, SOC2 and NIS2.

Cloud Security Architecture

Expert security architecture design and implementation for Microsoft Azure, AWS, and hybrid cloud solutions.

DevSecOps Architecture Solutions

Secure development pipeline implementation for GitHub, GitLab, and Atlassian suite.

Security Assessment Services

Comprehensive security testing and auditing for cloud platforms, Active Directory, and IoT systems.

Achievements

OSCP
Issuer: OffSec
Certified Red Team Lead
Issuer: ZeropointSecurity
Certified Red Team Operator
Issuer: ZeropointSecurity
Certified Ethical Hacker (Master)
Issuer: EC-Council
Microsoft Certified: Security Architect Expert
Issuer: Microsoft
AWS Certified Security
Issuer: Amazon Web Services
GitHub Advanced Security
Issuer: GitHub
HashiCorp Certified: Terraform
Issuer: HashiCorp
ISO/IEC 27001:2022 Foundation
Issuer: PECB
Microsoft Certified: Security Operations Analyst
Issuer: Microsoft
Microsoft Certified: Azure Security Engineer Associate
Issuer: Microsoft
Certified Security Professional
Issuer: CQURE
Drone Security Operations
Issuer: Credly
Certified Azure Red Team Professional
Issuer: AlteredSecurity
Cooperated with
Avon
Architected and delivered SSO integrations across a broad suite of enterprise security platforms — including CrowdStrike, TrendMicro, Rubrik, and Qualys — centralising identity governance and reducing access sprawl at scale. Led penetration testing engagements against e-commerce environments and drove cloud security engineering across AWS and Azure, covering CSPM configuration, triage, and remediation workflows. Extended detection coverage to AKS and EKS workloads, and developed custom integrations to strengthen SOC and Threat Hunting capabilities. Identified Shadow IT through proper cloud workload coverage, directly reducing unnecessary cloud spend and improving organisation-wide risk visibility.
Cassia
Conducted in-depth penetration testing of Cassia Networks' products as part of security due diligence for the Dodge OPTIFY platform. Uncovered multiple vulnerabilities, including CVE-level findings that had previously gone undetected. Coordinated responsible disclosure with the vendor, resulting in measurable improvements to the security quality of Cassia's product line.
Dodge Industrial
Provided security input bridging technical risk and business decision-making for the team responsible for the OPTIFY platform. Supported IT in establishing due diligence frameworks and executing SSO migrations. During vendor negotiations, applied precise audit scoping to eliminate redundant coverage — reducing the cost of external audits without compromising compliance integrity.
Japan Tobacco International
Delivered Azure security consultancy for a large-scale Digital Eco System platform, focused on advancing Zero-Trust posture: enforcing policy-driven access controls, transitioning role management toward IaC-deployed RBAC with Managed Identities, and hardening GitLab and Cloudflare WAF configurations to reduce attack surface and improve auditability.
Natura&Co
Established a NIST SP 800-115-aligned penetration testing process as the operational backbone of a group-wide Vulnerability Management programme. Defined and supervised internal, external, and Bug Bounty streams across the capital group — from scoping through remediation tracking — eliminating redundant testing and reducing programme costs while maintaining consistent assurance quality.
Dodge Optify
Built the cybersecurity programme for the OPTIFY industrial IoT platform: authored a tailored policy suite aligned to ISO 27001 and SOC 2, designed security controls across Azure cloud workloads, edge sensors, and IoT gateways, and initiated DevOps security practices using Bicep-based IaC to establish a repeatable, auditable deployment model. Also worked with RBC Bearings IT to strengthen Entra ID integrations and EDR capabilities to meet enterprise compliance requirements.
Bank Pekao S.A.
Conducted penetration testing engagements across a broad range of internal enterprise applications and critical infrastructure components, including Privileged Access Management (PAM) systems, SAP environments, and FortiNet network appliances. Assessments covered both application-layer and infrastructure-level attack surfaces, providing the organisation with actionable findings and remediation guidance across high-value, high-risk targets.
Avon Products International
Architected and delivered SSO integrations across a broad suite of enterprise security platforms — including CrowdStrike, TrendMicro, Rubrik, and Qualys — centralising identity governance and reducing access sprawl at scale. Led penetration testing engagements against e-commerce environments and drove cloud security engineering across AWS and Azure, covering CSPM configuration, triage, and remediation workflows. Extended detection coverage to AKS and EKS workloads, and developed custom integrations to strengthen SOC and Threat Hunting capabilities. Identified Shadow IT through proper cloud workload coverage, directly reducing unnecessary cloud spend and improving organisation-wide risk visibility.
Cassia Networks
Conducted in-depth penetration testing of Cassia Networks' products as part of security due diligence for the Dodge OPTIFY platform. Uncovered multiple vulnerabilities, including CVE-level findings that had previously gone undetected. Coordinated responsible disclosure with the vendor, resulting in measurable improvements to the security quality of Cassia's product line.
Dodge Industrial
Provided security input bridging technical risk and business decision-making for the team responsible for the OPTIFY platform. Supported IT in establishing due diligence frameworks and executing SSO migrations. During vendor negotiations, applied precise audit scoping to eliminate redundant coverage — reducing the cost of external audits without compromising compliance integrity.
Japan Tobacco International
Delivered Azure security consultancy for a large-scale Digital Eco System platform, focused on advancing Zero-Trust posture: enforcing policy-driven access controls, transitioning role management toward IaC-deployed RBAC with Managed Identities, and hardening GitLab and Cloudflare WAF configurations to reduce attack surface and improve auditability.
Natura&Co
Established a NIST SP 800-115-aligned penetration testing process as the operational backbone of a group-wide Vulnerability Management programme. Defined and supervised internal, external, and Bug Bounty streams across the capital group — from scoping through remediation tracking — eliminating redundant testing and reducing programme costs while maintaining consistent assurance quality.
Dodge Optify
Built the cybersecurity programme for the OPTIFY industrial IoT platform: authored a tailored policy suite aligned to ISO 27001 and SOC 2, designed security controls across Azure cloud workloads, edge sensors, and IoT gateways, and initiated DevOps security practices using Bicep-based IaC to establish a repeatable, auditable deployment model. Also worked with RBC Bearings IT to strengthen Entra ID integrations and EDR capabilities to meet enterprise compliance requirements.
Bank Pekao S.A.
Conducted penetration testing engagements across a broad range of internal enterprise applications and critical infrastructure components, including Privileged Access Management (PAM) systems, SAP environments, and FortiNet network appliances. Assessments covered both application-layer and infrastructure-level attack surfaces, providing the organisation with actionable findings and remediation guidance across high-value, high-risk targets.