Dark personal security engineering workspace at night

About → Flappedear

Arkadiusz
Kozuch.

Security engineering leader with deep technical roots, focused on SOC operations, incident response, detection capability, and building teams that work well in practice.

SOC Operations CISSP CASP+ IT Leadership Kraków

Background

8+ years in information security

I started in IT infrastructure — Windows Server, Linux, virtualisation, backup and disaster recovery. That foundation matters more than it sounds: understanding how systems actually work at the metal level is what separates security engineers who reason from first principles from those who just follow playbooks. Over eight years, I moved from keeping systems running to understanding how they fail — and how attackers exploit that.

The bulk of my career has been in Security Operations. I built a global 24/7 SOC from the ground up — not just staffed it, but designed the operating model, developed the detection logic, wrote the playbooks, and wired up the automation. SIEM, SOAR, EDR, IAM: I've operated most of the major platforms (Sentinel, Splunk, SentinelOne, CrowdStrike, Rapid7, Okta) and know where they help and where they get in the way. When major incidents happened, I was the Incident Commander — the person accountable for getting it contained and communicating clearly under pressure.

Now I run a cybersecurity operations function at the leadership level. That means setting direction, reporting to senior stakeholders, and developing the people on the team — including building an internship programme to bring new security talent through the door. The MBA I'm finishing adds a layer of business context to everything: security only works if it fits how the organisation actually operates. I hold CISSP and CASP+ as the professional anchors, with a stack of Microsoft and ITIL certifications underneath.

Certifications

Verify on Credly →

ISC² / CompTIA

  • CISSP
  • CASP+
  • CompTIA Security+
  • ISC² Certified in Cybersecurity (CC)

Microsoft

  • Cybersecurity Architect Expert
  • Security Operations Analyst
  • Azure Security Engineer Associate
  • Identity and Access Administrator Associate
  • Microsoft 365 Enterprise Administrator Expert
  • Microsoft 365 Security Administrator Associate
  • MCSE: Cloud Platform and Operations
  • MCSA: Windows Server 2012

ITIL

  • ITIL® 4 Specialist: Drive Stakeholders Value
  • ITIL® 4 Specialist: Create, Deliver and Support
  • ITIL® Foundation V4
  • ITIL® Intermediate V3 (PPO)
  • ITIL® Foundation V3

Other

  • VMware Certified Professional – Security
  • Rapid7 InsightVM Certified Administrator

Education

2024 – 2025

Master of Business Administration

Business strategy, leadership, and organisational management

2018 – 2020

Master degree in Management

Project management, team coordination, and process improvement

2014 – 2018

Engineer degree in Information Technology

Computer networks, systems engineering, software development fundamentals

Technology Stack

Microsoft Platform

Azure SentinelEntra IDActive DirectoryDefenderIntuneAzureExchangeTeamsATP / AIPSystem Center

Security Tools

SentinelOneCrowdStrike EDRCarbon BlackOkta IAMRapid7 InsightVMSplunkFireEye HelixAxoniusInvictiBitSight

Virtualisation

Microsoft Hyper-VVMware vSphereOracle VirtualBox

One corgi. Many rabbit holes.

Security · Leadership · Garage projects