cybersecurity · pentesting · audits

Bartosz Wiszniewski

Penetration Tester & Security Auditor

I help organizations find and fix security gaps before someone else exploits them. I perform web application and infrastructure penetration tests as well as cybersecurity audits.

01

About me

I look at systems through an attacker's eyes — I check where you can really get in, then show how to shut those doors for good. As a result, a test report is not a list of theoretical risks, but confirmed vulnerabilities with concrete recommendations.

Day to day I work with the Galach Consulting team, focusing primarily on web application penetration testing. I also develop practical applications of artificial intelligence in the security testing process.

  • Web application penetration testing
  • Infrastructure and network penetration testing
  • Cybersecurity and compliance audits
  • Threat modeling and risk analysis

Web application testing

Over 50 commercial penetration tests of web applications delivered. OWASP Top 10, SQL Injection, XSS, SSRF, deserialization, business logic and access control flaws.

Infrastructure testing

Insider threat / assumed breach testing, red teaming and social engineering. External perimeter analysis, reconnaissance and automated infrastructure scanning. Configuration and hardening audits, privilege escalation, Active Directory attacks.

Security audits

Internal audits for compliance with ISO 27001, NIS2, DORA, GDPR and Polish national frameworks (KSC, KRI). Security policy analysis and risk documentation.

02

Certifications

Verified credentials — every certificate is available as a PDF.

TCM Security

PNPT

Practical Network Penetration Tester

Hands-on certification covering the full network penetration test lifecycle — from reconnaissance to reporting.

View certificate (PDF)
Hack The Box

Pro Labs: Dante

Certificate of Completion — 40h, 40 CPE

Completion of an advanced lab simulating a corporate network compromise: enumeration, exploit development, lateral movement, privilege escalation and web application attacks.

View certificate (PDF)
DEKRA

ISO/IEC 27001 Lead Auditor

Auditing and assessment of information security management systems (ISMS). Certification accredited by PCA (Polish Centre for Accreditation).

View certificate (PDF)
Mile2

CSWAE

Certified Secure Web Application Engineer

Web application security — testing and defense techniques. Recertified in 2026, valid until 2029.

View certificate (PDF)
Microsoft / Coursera

Cybersecurity: Identity & Access

Cybersecurity Identity and Access Solutions using Azure AD

Identity and access management in the Azure environment.

View certificate (PDF)
Sekurak

Sekurak Academy 2023–2025

Completion diplomas — 180h total, 180 CPE

Semester-long training programs: network and Active Directory security, OSINT, IoT, red teaming, web application and infrastructure security.