Profil zawodowy
Podsumowanie
Doświadczenie
Umiejętności
Certyfikacja
Dodatkowe informacje
Oś czasu
Generic

Adrian Karolak

City: Katowice

Profil zawodowy

I am Security oriented and eager to learn new things. Along with technical abilities I possess other necessary traits such as strong communication skills.

I like security in general. Besides over 10 years of professional experience I enjoy tinkering with software privately. I was participating in "CTF" platforms such as "ringzeroteamCTF" or "Hitcon CTF". I was testing Hitcon CTF challenges locally from repository files hosted by Orange Tsai researcher and analyzed the code with the purpose of finding security issues.

I have identified vulnerabilities in products like Mozilla Firefox, McAfee DLP or Google Chrome. There is no CVE assigned for Google Chrome however due to duplicate report but it proves that I am able to spot risks even in very popular software.

Currently I am focused to help integragrate security in entire SDLC process. I work closely with developers to give suggestions regarding security controls. I work with popular frameworks ranging from Angular for client-side to Express.js or .NET Core for backend among many others.

I have experience working with dynamic security tools like Burp-Suite for example. I am experienced on cloud based applications as well and have identified issues related to cloud-based solutions.

Currently my focus is on hands-on highly technical Security Engineering Path. Experience from Offensive side of cybersecurity can be very helpful when dealing with configurations of security tools, or generally security technology. I can run and configure scanners, verify vulnerabilities found and help provide easy to understand guidance.

I have strong application security fundamentals and I am sure I could bring value to your company.

Podsumowanie

1
1
Certification
5
5
years of professional experience

Doświadczenie

Senior Security Product Engineer

ABB
Kraków
2026.08 - obecnie
  • Conducting Attack Surface Analysis
  • Conducting Threat Modeling
  • Analyzing CI/CD pipelines for security misconfigurations
  • Secure Code Review
  • Veryfing Vulnerabilities for false positives signals
  • Running Vulnerability Scans in tools Like BlackDuck, Blackduck Binary Analysis
  • Taking sessions with developers for secure coding guidance

Senior Ethical Hacker

Rockwell Automation
Katowice
2021.11 - obecnie
  • Conducting Application Penetration Tests
  • Making Penetration Test reports
  • Providing client support regarding test preparation and execution
  • Providing client support regarding fix implementations
  • Reviewing Azure Cloud Services
  • Source Code Review
  • Writing custom tools to help automate repetive tasks

Senior Penetration Tester

ING Tech Poland
Katowice
2017.04 - 2021.11

I started as Penetration Tester in 2017.04

In 2019.06 I got a promotion to Senior Penetration Tester

  • Conducting Application Penetration Tests
  • Conducting Network Scans with nmap
  • Making Penetration Test reports
  • Providing client support regarding test preparation and execution
  • Trainings preparation and execution

Umiejętności

  • Adapt and learn new technologies quickly
  • Interpreted languages programming(Python, Bash, PHP)
  • Compiled language programming(C,C, Java)
  • Basic Assembly Language Programming
  • Dynamic Application Security Testing
  • Code Review
  • Advanced BurpSuite Professional
  • Understanding TCP/IP Network Stack
  • Easily establishing contacts
  • Good time management

Certyfikacja

eWPT- eLearnSecurity Web application Penetration Tester

Dodatkowe informacje

  • Mozilla Firefox

CVE-2020-12412: Address bar spoofing using history navigation and blocked ports

  • McAfee DLP

CVE-2022-2330: XXE leading to local file disclosure

  • Google Chrome

CVE-2021-37999: XSS in new tab. CVE assigned to someone else. Google VRP policy states that credit goes to first reporter and I was bit late but the point is that I am able to spot issues in popular software.

  • Gitlab

CVE-2023-2015: Reflected XSS In Report Abuse

  • Gitlab

CVE-2023-0483: Leaking Datadog API Key

  • Gitlab

CVE-2023-3909: Denial of Service

  • Gitlab

CVE-2023-1279: Incorrect "../" Parsing

Oś czasu

Senior Security Product Engineer

ABB
2026.08 - obecnie

Senior Ethical Hacker

Rockwell Automation
2021.11 - obecnie

Senior Penetration Tester

ING Tech Poland
2017.04 - 2021.11
Adrian Karolak