RYSZARD BIALACH
PUBLIC VIEW

CYBERSECURITY ENGINEER · DETECTION ENGINEERING · PYTHON · CLOUD SECURITY · INFRASTRUCTURE

Step inside a security engineering mind.

I am a cybersecurity engineer focused on detection engineering, Python security automation, cloud security, SOC operations, and secure infrastructure. I build systems, secure them, instrument them, and study what their behavior reveals.

Behavioral analytics Security automation Cloud security Detection engineering Secure AI infrastructure
OPERATING PRINCIPLE
“An anomaly is a question worth asking, not an incident verdict.”

Good security work is not about producing the loudest alert. It is about producing the most defensible next action.

PROFESSIONAL PROFILE

Cybersecurity engineering built around evidence, automation, and operations.

My strongest areas include detection engineering, security automation with Python, cloud security monitoring, SOC and incident-response operations, network security, Linux infrastructure, SIEM workflows, and behavioral security analytics.

Cybersecurity EngineerDetection EngineerSecurity Automation EngineerSecurity Platform EngineerSOC EngineerCloud Security EngineerSecurity AnalystInfrastructure Security Engineer

CAPABILITY MAP

Explore the systems behind the résumé.

Select a node. Each one opens the professional evidence behind the skill, without exposing unnecessary operational or personal detail.

EVIDENCE DECK

Work that can be inspected.

Public case files emphasize methodology, architecture, and outcomes. Sensitive topology, secrets, private identifiers, and live control details are intentionally withheld.

CASE // NF-03 RESEARCH

Behavioral NetFlow Analytics & Anomaly Triage

Rebuilt an earlier flow-analysis project into a research-grade behavioral investigation: data validation, robust statistics, host concentration, normalized entropy, Isolation Forest triage, model sensitivity testing, and analyst-facing explanations.

PythonPandasscikit-learnNetFlowDetection
Read full case study →
QUESTION

How do we separate malformed telemetry, unusual behavior, and evidence of actual security risk?

METHOD

Schema validation → feature engineering → baseline characterization → anomaly ranking → sensitivity analysis.

LESSON

An impossible port is first a data-quality problem; an anomaly is first an investigation candidate.

CASE // INF-04 LAB

Segmented Security & AI Infrastructure

Built a segmented lab to study firewall policy, virtualization, telemetry, governed local AI workers, observability, and controlled service communication.

OPNsenseProxmoxLinuxVLANsObservability
Read full case study →
DESIGN

Network segmentation separates management, workstations, servers, and governed AI workloads.

CONTROL

AI workers operate without direct public Internet access; approved paths are benchmarked and validated.

PUBLIC VIEW

Architecture is intentionally sanitized; operational addresses and control-plane details are not published.

CASE // APP-02 ENGINEERING

Secure Application & Automation Patterns

Applied secure software patterns around identity, least privilege, controlled automation, logging, testing, CRUD workflows, and PostgreSQL-backed governance.

DjangoPythonPostgreSQLRBACTesting
Read full case study →
FOCUS

Separate human, service, manager, and worker identities with attributable actions and explicit permissions.

METHOD

Desired-state architecture plus as-built reconciliation, deterministic tests, evidence capture, and review.

EXPERIMENTAL SECURITY LAB

Artifact. Device. Human.

Cybersecurity does not stop at the network boundary. These public-safe experiments examine three different layers of trust: what is hidden inside a digital artifact, what changes when a connected endpoint can affect the physical world, and how people can strengthen one another through cooperative security habits.

LAB // 02

CYBER-PHYSICAL THREAT MODELING

MORPH//NODE

Rotate a fictional autonomous IoT field node and explore how connectivity, sensing, actuation, autonomy, and fail-safe controls change its trust boundary. The model demonstrates risk concepts—not construction instructions.

IoT SecurityAutonomyTrust BoundariesSafety
Enter MORPH//NODE →
LAB // 03

COOPERATIVE HUMAN SECURITY

SafeCircle

Practice positive social engineering: trusted-channel verification, supportive reporting, shared safety habits, and community cooperation for home, life, and work.

Human SecuritySecurity AwarenessCommunityTrust
Enter SafeCircle →

CREDENTIAL SIGNALS

Validated foundations.

Credential IDs and unnecessary verification metadata are not exposed in the public page.

C+

CERTIFICATION

CompTIA CySA+

Cybersecurity analytics, threat detection, vulnerability management, incident response, and security operations.

CC

CERTIFICATION

CSA Certificate of Cloud Security Knowledge

Cloud security architecture, governance, risk, controls, and shared-responsibility concepts.

BS

EDUCATION

B.S. Computer Networking & Security

Networking and security foundation with digital-forensics emphasis.

SELECTED EXPERIENCE

The work behind the capability map.

The public site presents role themes and technical scope rather than a scrape-ready employment ledger. A complete résumé can be provided through the professional contact path.

CLOUD SECURITY Professional experience

Cloud Security Specialist

Security monitoring and administration across cloud, SIEM, endpoint, and Zero Trust workflows. Experience included AWS security telemetry, centralized logging, endpoint tooling, and operational follow-through.

AWSGuardDutyCloudTrailSumo LogicRapid7CrowdStrike
SECURITY OPERATIONS Leadership + incident operations

SOC Coordination & Supervision

Oversight of monitoring, incident response, team coordination, multi-site security operations, reporting, and escalation in operational environments.

Incident ResponseMonitoringOperationsTeam Leadership
CURRENT BUILD Independent engineering

Security Engineering, Python & Governed AI Systems

Building repeatable analysis pipelines, secure infrastructure, local AI governance patterns, benchmark-driven controls, and analyst-friendly evidence workflows.

PythonLinuxDjangoPostgreSQLAutomationAI Governance

SECURITY BY PRESENTATION

Some details are missing on purpose.

This public portfolio is designed to demonstrate professional capability without publishing credential identifiers, phone numbers, private infrastructure addresses, complete internal topology, secrets, personal location data, or a full machine-readable employment history.

Public visibility is useful. Unnecessary exposure is not.

PROFESSIONAL CONTACT

If the work is relevant, continue the conversation.

Security engineering · detection engineering · security automation · infrastructure · Python.

GitHub profile