Tomasz Kowalczyk, ai security engineer

Tomasz Kowalczyk

Senior AI Security Engineer

Warsaw, Poland · Europe/Warsaw (UTC+2) · 12 years of experience

Tomasz focuses on securing AI applications, data paths, model supply chains, and agent permissions.

Request a shortlist

Why this profile fits

AI-specific threat modeling

Covers prompt injection, sensitive-data exposure, unsafe tool use, model supply chains, and excessive agency.

Least-privilege architecture

Scopes identities, tools, data access, secrets, and network paths to the minimum required for each workload.

Adversarial validation

Turns abuse cases and incidents into repeatable tests, monitoring signals, and response playbooks.

Relevant toolkit

Threat ModelingIAMKubernetes SecurityLLM Red TeamingSIEM

Delivery evidence

Selected work

Model Supply-Chain Controls

enterprise software

Designed and delivered a AI security programme focused on model supply-chain security; introduced signed artifacts and provenance controls across 60 model and container releases. The release included threat models, least-privilege controls, adversarial tests, logging, and incident playbooks mapped to OWASP guidance.

Threat ModelingPython

AI Artifact Provenance Registry

enterprise software operations

Built the supporting control and measurement layer for the primary system, covering review queues, regression checks, operational visibility, and a documented handoff to the owning team.

Threat ModelingKubernetes Security
View more profile detail →

Relevant experience

Career timeline

Senior AI Security Engineer

2022–Present

Devlyn client assignments · Remote

  • Led model supply-chain security delivery for a enterprise software team and introduced signed artifacts and provenance controls across 60 model and container releases.

AI Security Engineer

2013–2021

enterprise software product company (confidential) · Warsaw, Poland

  • Built production systems in enterprise software, with increasing ownership of reliability, testing, and stakeholder delivery.

Skill depth

Show experience in context.

VerbalCommunicationDomainUnderstandingProblemSolvingCodeQualitySystemDesignDeliverySpeed
Competency shapeAssessment across the same six dimensions used for every profile.

Relevant experience by skill

Threat Modeling12 years
Python11 years
IAM10 years
Kubernetes Security9 years
LLM Red Teaming12 years
SIEM11 years
See the complete skill index

Languages

PythonTypeScriptSQLBash

Frameworks

PythonIAMKubernetes SecurityOPAVaultSemgrep

Tools

Burp SuiteFalcoTerraformGitHub ActionsDocker

Platforms

AWSGoogle CloudAzureKubernetes

Storage

VaultS3PostgreSQLSecurity Lake

Paradigms

Secure-by-design AIZero trustAdversarial testingSupply-chain security

Credentials

Certifications

AWS Certified Security – Specialty

Amazon Web Services · 2025 · Certified

Certified Kubernetes Security Specialist

Cloud Native Computing Foundation · 2024 · Certified

Communication

Languages

English

Fluent

More examples

Similar AI Security Engineer profiles.