Henryk Hellebrand

Next‑Gen Security Architect SIEM • AI/ML • Vector DB • DevSecOps Security Architect | SIEM (Splunk, QRadar, ELK) • AI/ML • OT Security • DevSecOps SIEM & AI Security Architect Future‑Proof Cybersecurity Architectures

Wrocław, Dolnośląskie, Poland

About

I design scalable, intelligent security systems that blend enterprise SIEM (Splunk, QRadar, Sentinel) with AI/ML anomaly detection and vector databases. My focus: future‑proof architectures that unify OT security, EDR, and automated DevSecOps pipelines. Hands‑on expertise: Enterprise SIEM deployments for 5000+ endpoints AI/ML agents for anomaly detection + vector DB integration DevSecOps pipelines (Jenkins, Docker, Kubernetes) OT Security & incident response Mission: Reduce false positives, accelerate incident detection, and empower SOC teams with smarter, automated workflows. I’m looking for projects where I can combine hands‑on implementation with innovation — proving that Next‑Gen SIEM is the future of cybersecurity.

Experience

  • Security Operations Engineer at Unit4
    Oct 2025 - Present · 10 mos

  • Cybersecurity systems and SIEM Engineer at thyssenkrupp Group Services Gdańsk Sp. z o.o.
    Jun 2023 - Sep 2025 · 2 yrs 4 mos

    - Led SIEM onboarding for 5000+ endpoints, integrating EDR and OT Security log sources. - Developed correlation rules that reduced false positives by 30% and accelerated incident detection. - Designed dashboards and reports for SOC teams, improving visibility across firewalls, servers, and applications. - Integrated SIEM with IDS/IPS and endpoint security, enabling unified threat detection. - Conducted training sessions for analysts, ensuring effective use of SIEM and faster response times.

  • B2B Freelance SIEM Engineer at Agmil Henryk Hellebrand
    Sep 2022 - Jan 2024 · 1 yr 5 mos

    - Delivered SIEM deployments for enterprise clients (5000+ endpoints), integrating EDR and OT Security log sources. - Designed and implemented correlation rules that reduced false positives by 30% and accelerated incident detection. - Built DevSecOps pipelines (Jenkins, Docker, Kubernetes) to automate rule deployment and ML model updates. - Developed onboarding documentation and training for SOC teams, ensuring smooth adoption of SIEM platforms. - Provided tailored freelance B2B solutions, adapting Splunk, QRadar, and Sentinel to diverse client environments.

  • Siem Engineer / Project Manager at British American Tabacco
    Sep 2022 - Apr 2023 · 8 mos

    - Led SIEM onboarding for enterprise clients (5000+ endpoints), integrating critical log sources across IT and OT. - Developed correlation rules and detection strategies that reduced false positives by 30% and accelerated incident response. - Implemented EDR and OT Security integration, ensuring unified visibility across industrial and corporate networks. - Designed dashboards and compliance reports tailored to SOC teams and regulatory requirements. - Delivered tailored freelance B2B solutions, adapting Splunk, QRadar, and Sentinel to diverse client infrastructures.

  • Test Automation Engineer at Merapar
    Sep 2022 - Dec 2022 · 4 mos

    * Developed and executed automated test scripts for DOCSIS CPE devices, network elements, and end-to-end scenarios. * Utilized [testing frameworks] to create efficient and maintainable test suites. * Collaborated with development teams to identify and resolve defects. * Contributed to improving product quality and reducing time-to-market.