> karolkozakowski karol_

security · compliance · infrastructure

Karol Kozakowski

I build secure-by-default infrastructure and treat security as pragmatic risk reduction — not box-checking.

  • CISSP
  • Cloud security
  • SOC 2 Type II
  • ISO 27001
  • GDPR
  • 10 yrs shipping

Based in Gdynia, Poland · open to consulting engagements, senior / staff security roles, and infrastructure engineering (AWS / EKS) with a strong security approach.

01

The short version

I'm a CISSP security and infrastructure engineer who helps startups build security that holds up in the real world: cloud architecture, identity, compliance, automation, and the unglamorous glue between them.

For the last several years, I've often been the one-person security team at fast-growing companies, wearing every hat from compliance owner to AWS infrastructure engineer. I've led SOC 2 Type II and ISO 27001 programs from scratch while staying hands-on with Terraform, EKS, IAM, Okta, and Zero Trust access.

My bias is practical: security should make the safe path easier, not slow the business down. I still come at this as an engineer, which means I'd rather automate a control than write a policy nobody reads, and I care about systems that engineers will actually keep using after the audit is over.

02

What I'm good at, concretely

Compliance from inception to realization

Outcome: audit-ready programs built from zero.

Stood up SOC 2 Type II and ISO 27001 from scratch and drove them to certification — scoping, controls, evidence, and audit. The useful part was wiring evidence collection and controls into everyday infrastructure so they held up across a real audit window, not just on the day.

Secure-by-default cloud on AWS

Outcome: safer defaults for cloud access and workloads.

IAM design, guardrails, and network access (Cloudflare WARP / Zero Trust) built so the right thing is the default. Terraform for everything that can be codified; EKS and Fargate for the workloads. Detection with GuardDuty rather than hope.

GDPR, Cyber Essentials & CE+

Outcome: standards translated into controls engineers keep.

Ran GDPR programs and drove Cyber Essentials / CE+ certifications — and, as my résumé hints, managed to not lose my mind doing so. Translating a standard into clear owners, evidence, and maintainable controls is its own discipline.

Code across the whole stack

Outcome: less manual glue, fewer one-off exceptions.

Comfortable from product code down to infrastructure and the integration glue in between. I lean on good tools instead of reinventing them — no Not-Invented-Here syndrome — but I'll write what's missing.

Identity & access, done properly

Outcome: access that is auditable and revocable by design.

Okta, least-privilege IAM, and Zero Trust network access designed so access is auditable and revocable, and onboarding/offboarding isn't a fire drill.

AI security & governance

Outcome: LLM adoption with practical guardrails.

Bringing threat modeling and monitoring to how teams actually adopt LLMs — the newest place where "move fast" and "don't leak everything" need a referee.

03

Experience

  1. 2026 — presentGdynia

    Senior Staff Security / Infrastructure Engineer

    Equilibrium Energy

    Owning security architecture across cloud and identity, with an emphasis on automation, secure-by-default infrastructure, and pragmatic risk management — working at the intersection of engineering, compliance, and business to prevent problems before they become incidents.

  2. 2024 — 2025Remote

    Staff Infrastructure Engineer

    Equilibrium Energy

    Cloud security and identity management across AWS — secure network access (WARP) and IAM design — plus infrastructure automation from foundational components to operating EKS clusters and production workloads. Owned the SOC 2 Type II program from inception to certification.

  3. 2023 — 2024Remote

    Senior Infrastructure Engineer

    Equilibrium Energy

  4. 2023Gdynia, PL

    DevSecOps Engineer

    Light

    Infrastructure management (AWS, Terraform, EKS, Fargate, GitHub Actions) alongside compliance and security work — SOC 2 Type II reporting, code review, and the risk registry.

  5. 2018 — 2023Warsaw, PL

    DevOps Engineer

    Artificial Labs

    Built and managed AWS environments with Terraform, kept them as secure as possible, and automated whatever could be automated. Helped achieve ISO 27001 certification.

  6. 2017 — 2018Warsaw, PL

    DevOps Engineer

    EXATEL

  7. 2016 — 2017Warsaw, PL

    DevOps Engineer

    Redge Technologies

    Continuous Integration with Puppet; managed staging environments.

  8. 2015 — 2016Warsaw, PL

    Junior Developer / DevOps Specialist

    Centralny Ośrodek Informatyki

04

Skills

# infrastructure

  • AWS
  • Kubernetes / EKS
  • Terraform
  • IAM
  • Lambda
  • Fargate
  • GuardDuty

# security & compliance

  • SOC 2 Type II
  • ISO 27001
  • GDPR
  • Cyber Essentials / CE+
  • Threat Modeling
  • Okta
  • Cloudflare Zero Trust
  • SDLC Security
  • Information Security

# ai

  • AI security & governance
  • LLM monitoring
  • Claude
  • ChatGPT
05

Certifications, education & languages

Certifications

  • CISSP — Certified Information Systems Security Professional, ISC² (2025) verify ↗

Education

  • Inż. (Eng.), Computer Science — Polish-Japanese Academy of Information Technology, Warsaw (2014–2018)

Languages

  • Polish — Native
  • English — Professional
06

Let's talk

I'm open to consulting engagements — secure-by-default cloud architecture, IAM & Zero Trust, and compliance programs (SOC 2, ISO 27001, GDPR, Cyber Essentials / CE+) built from inception to certification. I'm equally happy in a senior / staff security role or as an infrastructure engineer (AWS / EKS) with a strong security approach. If any of that is on your plate, get in touch.