Wojtek Palczynski CISSP, CRISC, CISA, CGEIT, CISM
Cyber Security Consultant - Governance, Risk Management, Compliance
Toronto, Canada Area
Computer & Network Security
Current
Safe IT Inc.,
Independent
Previous
Sentry Metrics,
ERE Information Security
Education
ISACA
Recommendations 5 people have recommended Wojtek Palczynski
Websites
isc2
ISACA
Summary
I have over 12 years of experience and proven success in Enterprise Threat and Risk Management, Audit, Gap Analysis, Project Management, IT Security Governance and Compliance Reporting. I currently hold the CISSP, CRISC, CGEIT and CISA designations.
With over 12 years of experience in diverse environments such as mining and metals, telecom, capital markets, banking, government and high technology development I have worked in roles ranging from Risk Adviser, managing global SIEM deployments, operations and business management to systems and network architecture design as well as auditing, IT governance and compliance reporting.
I focus on delivering IT security solutions in the realms of SIEM (Security Information and Event Management), Governance, Compliance and Auditing for a diverse range of clients and industries. I have a track record of success in delivering projects on time and budget working on both domestic and international enterprise-class projects.
Specialties: Governance, Risk Management and Compliance Reporting, eDiscovery, Gap Analysis, Penetration Testing and Vulnerability Assessments.
Forensic and IT Control Audits measuring control effectiveness and compliance against the ISO 27001, 27002 and NERC CIP standards, COBIT framework and industry best practices.
Mergers and Acquisitions.
Experience
Cyber Security Consultant - Governance, Risk Management, Compliance Reporting
Safe IT Inc.
January 2003 – Present (13 years 1 month)
Recent Achievements
• Developed a Information Security Merger and Acquisition (M&A) Handbook for one of Canada`s leading Banks. Deliverables included a framework for the initial Due Diligence assessment of potential targets as well as Deep Dive examination of the targets Information Security governance program.
• Performed all Threat Risk Assessments in support of a $300 million acquisition of a large American wealth management institution by one of Canada's leading Banks.
• Global deployment of Log Logic Log Management System (LMS) and integration with Security Information and Event Management System (SIEM) for one of Canada's leading Banks.
• Conducted Maturity Assessments of Key Technology Controls at a major Canadian Banking Institution.
• Managed a global SIEM deployment project which helped implement Governance on a $1.2 Billion contract for a world’s leading Mining Corporation.
• Performed Enterprise Information Security compliance assessments against industry standards such as ISO 27001, ISO 27002, NERC CIP and COBIT, provided recommendations to mitigate the identified control gaps.
• Conducted vulnerability assessments of IT systems using a broad range of tools and technologies, created comprehensive reports based on the results for clients which included recommendations to remediate the vulnerabilities, resulting in proactive improvement of clients network security posture.
Blockchain / Cryptocurrency Technology Consultant
Independent
October 2013 – Present (2 years 4 months)
• Blockchain technology strategy consulting.
• Architectural advice for Blockchain projects.
• Merchant cryptocurrency payment system integration.
• Secure Offline cryptocurrency storage solutions including multi-signature ‘deep freeze’ storage.
• Custom, scalable cryptocurrency mining solutions (SHA-256, Scrypt, Scrypt-N).
• Security / Risk assessments and audits.
• Blockchain investigations.
• Non-technical "Bitcoin 101" style talks to various industries including legal, accounting, financial.
Sentry Metrics
Senior Security Auditor
Sentry Metrics
2005 – 2007 (2 years)
Senior Security Auditor
ERE Information Security
2005 – 2007 (2 years)
Organizations
ISACA - Information Systems Audit and Control Association
Certifications
CISSP Certification (Certified Information System Security Professional)
ISC2
CRISC Certification (Certified in Risk and Information Systems Control)
Information Systems Audit and Control Association (ISACA)
CISA Certification (Certified Information Systems Auditor)
Information Systems Audit and Control Association (ISACA)
CGEIT Certification (Certified in the Governance of Enterprise IT)
Information Systems Audit and Control Association (ISACA)
CISM Certification (Certified Information Security Manager)
Information Systems Audit and Control Association (ISACA)
October 2014 – Present
Education
ISACA
CGEIT
2011 – 2012
ISACA
CRISC
2011 – 2011
ISACA
CISA
2011 – 2011
ISC2
CISSP
2005 – 2005
Mohawk College
Mohawk College
Advanced Network Security and Connectivity, Information Technology
2001 – 2003
Languages
English
Native or bilingual proficiency
Polish
Native or bilingual proficiency