Maciej M.

Lead Analyst | Cybersecurity Incident Response | CSAP | CCSK | Azure

Warsaw, Mazowieckie, Poland

About

Cybersecurity analyst & Incident Response (DFIR) team lead with background in engineering and architecture. Currently involved in: • 🛡️ Live Cyber Defense • 🦾 Incident Response & Remediation • 🔍 Incident management • 🔐 Information Security and Compliance analysis and enforcement • 🌥️ Microsoft Azure & Amazon AWS cloud environments Current day-to-day responsibilities: • Oversee end-to-end incident response operations, including detection, triage, containment, eradication, and recovery for security events across the enterprise • Lead and participate in investigations involving advanced threats, lateral movement, data exfiltration, and malware, ensuring accurate root-cause analysis and evidence preservation • Coordinate cross-functional response efforts with SOC, forensics, cloud, network, IT operations, legal, and compliance teams during major incidents • Develop, maintain, and continuously improve incident response plans, playbooks and standard operating procedures • Conduct proactive threat hunting when needed, to uncover hidden threats, identify attacker behaviors, and strengthen the organization's defensive posture • Provide leadership and mentorship to junior analysts, guiding investigations, reviewing analysis, and fostering a high-performance incident response culture • Perform post-incident reviews and executive reporting, translating technical findings into clear business impacts and actionable recommendations • Drive automation and efficiency through SOAR workflows, scripted investigations, and continuous integration of new tools and processes • Ensure regulatory compliance and audit readiness, supporting documentation, evidence management, and communication for internal and external stakeholders Industry certified: • CompTIA Security Analytics Professional (CSAP) • CompTIA CySA+ (CS0-003) • CompTIA Security+ (SY0-701) • CompTIA Network+ (N10-009) • Microsoft Certified: Security Operations Analyst Associate (SC-200) • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) • Microsoft Certified: Azure Administrator Associate (AZ-104) • Microsoft Certified: Azure Fundamentals (AZ-900) • AWS Certified Cloud Practitioner (CLF-C02) • Certificate of Cloud Security Knowledge (CCSK) • Varonis Data Defense Certification 𝗚𝗮𝗹𝗹𝘂𝗽'𝘀 𝗖𝗹𝗶𝗳𝘁𝗼𝗻𝗦𝘁𝗿𝗲𝗻𝗴𝘁𝗵𝘀 𝗮𝘀𝘀𝗲𝘀𝘀𝗺𝗲𝗻𝘁: Learner | Achiever | Relator | Analytical | Individualization

Experience

  • Stryker (Hybrid)
    • Lead Cybersecurity Analyst — Incident Response
      Sep 2025 - Present · 10 mos

      • Manage full incident response lifecycle: detection, triage, containment, eradication, and recovery • Investigate advanced threats with strong root-cause and evidence handling • Coordinate cross-functional response across SOC, forensics, cloud, network, IT, legal, and compliance • Maintain and improve IR plans, playbooks, and SOPs • Conduct targeted threat hunting to identify hidden risks and attacker behavior • Mentor analysts and support high-quality investigation standards • Deliver post-incident reviews and translate findings into business impact and actions • Enhance efficiency through SOAR, automation, and tooling improvements • Support compliance, audits, and stakeholder reporting

    • Senior Cybersecurity Analyst — Security Operations Center
      Apr 2025 - Sep 2025 · 6 mos

      • Incident Triage and Investigation • Management & correlation in SIEM, SOAR, EDR/XDR platforms • Network analysis using NGFW & NAC products • Endpoint management using AEM/XEM & ticketing systems • Cloud assets & vulnerabilities analysis in CIEM & Data Protection solutions • Help with company playbooks & workbooks development for SOC scope • Company-wide team collaboration • Tabletop Exercises

    • Cybersecurity Analyst — Security Operations Center
      Jan 2024 - Mar 2025 · 1 yr 3 mos

      • Daily management & analysis in SIEM, SOAR, EDR/XDR platforms • Network security analysis using NGFW & NAC products • Endpoint management using AEM/XEM & ticketing systems • Cloud assets & vulnerabilities analysis in CIEM & Data Protection solutions • Cross-cyber team collaboration • KQL spells in Azure

  • Architect at Freelance
    Jan 2014 - Dec 2023 · 10 yrs

    • Conceptual design • Architectural Design • 2D CAD drafting • 3D Modelling and visualisations • Design process coordination • Supervision and management of project documentation

  • Architect at Jasiński Kruszewski Architekci Sp. z o.o.
    Sep 2022 - Aug 2023 · 1 yr

    • Architectural Design: concept, building and executive designs • Multi-disciplinary design team coordination • Urban planning and detail design • CAD drafting & 3D Modelling • Supervision and management of project documentation • Multi-family housing and Single family luxury housing design

  • Architect at Kwadratura Sp. z o.o.
    Mar 2021 - Aug 2022 · 1 yr 6 mos

    • Architectural Design: concept, building and executive designs • Multi-disciplinary design team coordination • Urban planning and detail design • CAD drafting • Supervision and management of project documentation • 3D Modelling and visualisations rendering • Single family luxury housing, Multi-family housing, School design, interiors

  • Architect at DWAA Architekci
    Nov 2020 - Jan 2021 · 3 mos

    • Architectural Design: concept, building and executive designs • 2D CAD drafting • Supervision and management of project documentation • Railways and railway station design