Skip to content
View damianfedeczko's full-sized avatar

Block or report damianfedeczko

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
damianfedeczko/README.md

Hey, I'm Damian πŸ‘‹

Security Engineer focused on cloud security, detection engineering, and making security actually scale. I spend most of my time in AWS, building things with Terraform, and trying to automate my way out of manual work.


What I do

I've led and contributed to security programs across cloud infrastructure, detection engineering, compliance, and automation. Some highlights:

  • SIEM at scale β€” designed and scaled an Elastic SIEM ingesting ~185M events/day from AWS CloudTrail, Okta, and Cloudflare. Built ML-based anomaly detection and defined long-term detection strategy.
  • Cloud vulnerability management β€” overhauled the vuln management program across 500+ EC2 instances. Implemented auto-patching via AWS Systems Manager, built an Inspector-based reporting pipeline in Looker, and automated AMI updates via Renovate.
  • CNAPP migration β€” led migration from a third-party CNAPP to native AWS services (Inspector + Resource Explorer), saving ~$103k/year while keeping parity on coverage.
  • EDR rollout β€” deployed container and host-level EDR across 6 Kubernetes clusters and 500+ EC2 instances. Refactored Helm charts to support ongoing scalability.
  • Cloudflare security β€” managed configs across 15+ zones, migrated legacy rules, hardened ciphers for PCI DSS, and onboarded Bot Management blocking ~120k malicious requests daily.
  • Compliance β€” supported ISO 27001 and ISO 27701 audits, owning evidence for network, infrastructure, and IAM controls.

Stack & tools

AWS GCP Terraform Elastic Cloudflare Kubernetes

Cloud & infra: AWS (Inspector, Systems Manager, CloudTrail, Resource Explorer), GCP, Cloudflare
Detection & response: Elastic SIEM, EDR (container + host), ML-based anomaly detection
IaC & automation: Terraform, Helm, Renovate, Vanta
Compliance: ISO 27001, ISO 27701, PCI DSS


Currently interested in

  • Cloud-native security tooling and reducing dependency on third-party SaaS where native does the job
  • Detection engineering at scale β€” signal quality over alert volume
  • Security automation that engineers actually want to use

Based in Poland πŸ‡΅πŸ‡± β€” open to connecting on LinkedIn

Popular repositories Loading

  1. bash-tips-and-tricks bash-tips-and-tricks Public

    Bash tips and tricks - useful commands and shortcuts to use within your terminal

    2

  2. terraform-training-examples terraform-training-examples Public archive

    Simple Terraform examples

    HCL 1

  3. tmpsms tmpsms Public

    Forked from sdushantha/tmpsms

    A temporary SMS utility right from your terminal written in POSIX sh

    Shell 1

  4. damianfedeczko damianfedeczko Public

    1

  5. Programmers_guide_to_Python Programmers_guide_to_Python Public

    Forked from Anku5hk/Programmers_guide_to_Python

    Learn almost everything in python fast πŸš€

    1

  6. sre sre Public

    Forked from mxssl/sre-interview-prep-guide

    Site Reliability Engineer Interview Preparation Guide

    1