Template
Copy this website

Tomasz Kowalski

IT Security Manager at Tech Innovations Corp.

Summary

Highly accomplished IT Security Manager with over 10 years of progressive experience in designing, implementing, and managing comprehensive cybersecurity programs. Proven expertise in risk management, compliance adherence, and incident response, safeguarding critical information assets in dynamic technology environments. Adept at leading cross-functional teams and leveraging advanced security frameworks to achieve organizational resilience and maintain a strong security posture.

Experience

IT Security ManagerTech Innovations Corp.
Austin, TXMar 2020Present
  • Led a team of 5 security analysts, improving incident response time by 30% and reducing critical vulnerabilities by 25% across 500+ endpoints.
  • Developed and implemented a new risk assessment framework, reducing identified high-risk vulnerabilities by 40% in the first year.
Senior Security AnalystGlobal Data Solutions
Dallas, TXJun 2016Feb 2020
  • Conducted over 150 penetration tests and vulnerability assessments, identifying and remediating 200+ high-severity vulnerabilities in core applications.
  • Instrumental in achieving PCI DSS compliance, contributing to a 100% successful annual audit for payment processing systems handling $500M+ transactions.
Security AnalystSecureNet Innovations
Houston, TXJun 2014May 2016
  • Monitored security events and alerts, analyzing over 10,000 logs daily to detect potential security breaches.
  • Assisted in the implementation of an EDR solution, resulting in a 15% improvement in endpoint threat detection.
  • Responded to 200+ security incidents, documenting findings and contributing to post-incident reviews.

Projects

Automated Cloud Security Policy Generator
Jan 2022Present
  • Developed a Python-based tool to automatically generate secure configuration policies for AWS and Azure based on industry best practices.
  • Increased efficiency in policy deployment by 40% and reduced human error in manual configuration.
  • Contributes to open-source community, receiving 50+ stars and forks, demonstrating practical scripting and cloud security expertise.
Home Network Threat Intelligence Feed Aggregator
Sep 2019Mar 2020
  • Built a personal project using Python to aggregate multiple open-source threat intelligence feeds and integrate them with a local firewall.
  • Improved proactive threat detection capabilities for home network by 20%, blocking known malicious IPs and domains.
  • Showcased ability to integrate disparate security data sources and automate defensive actions.
Security Awareness Training Module
Apr 2017Oct 2017
  • Designed and developed an interactive online security awareness training module focused on phishing and social engineering.
  • Utilized engaging content and quizzes, resulting in a 15% increase in employee awareness test scores.
  • Demonstrated pedagogical skills in making complex security concepts accessible to non-technical audiences.

Education

Carnegie Mellon UniversityMaster of Science in Cybersecurity
Pittsburgh, PAAug 2012May 2014
  • Specialized in Enterprise Security and Information Assurance.
  • Awarded Dean's List for academic excellence with a GPA of 3.9/4.0.
University of Texas at AustinBachelor of Science in Computer Science
Austin, TXAug 2008May 2012
  • Graduated Magna Cum Laude with a GPA of 3.8/4.0.
  • Completed honors thesis on 'Advanced Cryptographic Techniques for Secure Data Transmission'.

Skills

Security Frameworks & Standards
NIST CSFISO 27001CIS ControlsSOC 2MITRE ATT&CKOWASP Top 10
Cloud Security
AWS SecurityAzure SecurityGCP SecurityContainer Security (Docker, Kubernetes)Serverless SecurityCloud IAM
Tools & Technologies
SIEM (Splunk, QRadar)EDR (CrowdStrike, SentinelOne)Firewalls (Palo Alto, Fortinet)Vulnerability Scanners (Nessus, Qualys)Identity & Access Management (Okta, Azure AD)DLP Solutions
Compliance & Governance
GDPRHIPAAPCI DSSSOXData PrivacySecurity Audit
Cybersecurity Operations
Incident ResponseRisk ManagementVulnerability ManagementThreat ModelingSecurity ArchitecturePenetration Testing