Web application testing
Over 50 commercial penetration tests of web applications delivered. OWASP Top 10, SQL Injection, XSS, SSRF, deserialization, business logic and access control flaws.
cybersecurity · pentesting · audits
Penetration Tester & Security Auditor
I help organizations find and fix security gaps before someone else exploits them. I perform web application and infrastructure penetration tests as well as cybersecurity audits.
01
I look at systems through an attacker's eyes — I check where you can really get in, then show how to shut those doors for good. As a result, a test report is not a list of theoretical risks, but confirmed vulnerabilities with concrete recommendations.
Day to day I work with the Galach Consulting team, focusing primarily on web application penetration testing. I also develop practical applications of artificial intelligence in the security testing process.
Over 50 commercial penetration tests of web applications delivered. OWASP Top 10, SQL Injection, XSS, SSRF, deserialization, business logic and access control flaws.
Insider threat / assumed breach testing, red teaming and social engineering. External perimeter analysis, reconnaissance and automated infrastructure scanning. Configuration and hardening audits, privilege escalation, Active Directory attacks.
Internal audits for compliance with ISO 27001, NIS2, DORA, GDPR and Polish national frameworks (KSC, KRI). Security policy analysis and risk documentation.
02
Verified credentials — every certificate is available as a PDF.
Practical Network Penetration Tester
Hands-on certification covering the full network penetration test lifecycle — from reconnaissance to reporting.
Certificate of Completion — 40h, 40 CPE
Completion of an advanced lab simulating a corporate network compromise: enumeration, exploit development, lateral movement, privilege escalation and web application attacks.
Auditing and assessment of information security management systems (ISMS). Certification accredited by PCA (Polish Centre for Accreditation).
Certified Secure Web Application Engineer
Web application security — testing and defense techniques. Recertified in 2026, valid until 2029.
Cybersecurity Identity and Access Solutions using Azure AD
Identity and access management in the Azure environment.
Sekurak Academy Hacker
Comprehensive training in offensive cybersecurity techniques.
Completion diplomas — 180h total, 180 CPE
Semester-long training programs: network and Active Directory security, OSINT, IoT, red teaming, web application and infrastructure security.