Sławomir Babicz

Experience

Senior Security Engineer with 10+ years of hands-on experience across incident response, detection engineering, and cloud infrastructure security. Very strong fundamentals in how systems operate, able to derive solutions from first principles. Enjoys driving incident response, performing investigations, and securing systems in complex environments — handling incidents end-to-end, from forensic analysis to postmortems and stakeholder presentations. Builder of technically deep SIEM platforms and detection tooling, most recently applying AI agents to phishing classification and SIEM alert triage. Proven track record securing AWS/GCP environments, release pipelines, and blockchain infrastructure for financial services and Web3 organisations.

career

  1. Senior Infrastructure Security Engineer

    2022 – 2026

    DFINITY Foundation · Zürich, Switzerland

    • Responded to security incidents end-to-end, including forensic analysis, postmortems, and stakeholder presentations.
    • Designed and built a technically deep Elastic SIEM platform with custom detection rules covering a wide range of applications and threat vectors.
    • Deployed AI agents for phishing classification and for SIEM alert throttling and triage.
    • Maintained IAM permissions and access control for AWS infrastructure, including Okta (SAML) integrations, and contributed to release-pipeline hardening.
  2. Security Engineer

    2021 – 2022

    Credit Suisse (contractor via iET SA) · Zürich, Switzerland

    • Designed and implemented end-to-end technical solutions for security and business use cases using Splunk and commercial UEBA tools.
    • Built parsers, data models, correlation rules, Splunk searches, and dashboards.
  3. Professional Threat Responder

    2018 – 2021

    ISPIN AG · Bassersdorf, Zürich area, Switzerland

    • Built a threat intelligence platform gathering, processing, and correlating TI data for distribution into SIEM/EDR solutions.
    • Built and maintained high-throughput Elasticsearch clusters (40+ nodes, 50 TB+ bare metal).
    • Developed a phishing framework and ran high-profile phishing campaigns for major Swiss financial organizations.
    • Built the Cyber Defense Center from scratch, recruiting team members and providing mentorship.
  4. Senior SOC Specialist

    2015 – 2018

    Akamai Technologies · Cracow, Poland

    • Lead DDoS mitigation expert and escalation point for the global Security Operations Center.
    • Detected DDoS attack vectors through deep packet analysis and developed mitigation policies for emerging threats.
    • Built the Cracow SOC from scratch: recruiting, training material, and technical documentation.
  5. CMS Network Engineer

    2015

    Cisco Systems · Cracow, Poland

    • Full-cycle configuration and administration of Cisco equipment in mission-critical infrastructures.
    • Advanced troubleshooting and diagnostics on Cisco routers; incident management per ITIL/ISO procedures.
  6. 3rd Line Network Engineer

    2013 – 2015

    Atos IT Solutions and Services · Bydgoszcz, Poland

    • Provided 3rd-line LAN/WLAN support for wireless infrastructure (802.11 a/b/g/n) with Enterasys and Cisco controllers.
    • Configured BGP, OSPF, HSRP, VRRP, ACLs, static routing, and EtherChannels.
  7. Field Engineer

    2011 – 2013

    SpeedNet · Ropczyce, Poland

    • Wireless installations using climbing equipment on buildings and structures.
    • Full-cycle 802.11a/b/g point-to-point implementations in the 2.4 and 5 GHz bands.

education

  1. Bachelor's degree, Technical Information and Education

    2009 – 2013

    University of Rzeszów, Poland

    • Received scientific scholarships.
    • Erasmus exchange at Matej Bel University, Banská Bystrica, Slovakia; MOST exchange at Kazimierz Wielki University, Bydgoszcz, Poland.

skills

Security Engineering

Cloud & Infrastructure

Automation & AI

Languages