Twenty years, two worlds, one throughline
Where compliance rules meet what the business actually needs
Identity architecture · Cloud security · Enterprise governance
I design identity systems that work in the real world — not just on paper. With 20+ years across SMBs, public institutions, and large enterprises serving hundreds of thousands of users, I've learned that identity architecture is never purely technical. It's about understanding what a business actually needs, what its risks really are, and building something that holds up when the complexity scales.
My edge is translation: I move fast between executive strategy and engineering detail, between compliance requirements and Conditional Access policy, between a CISO's concern and a developer's ticket.
Where it started
I came to technology before it had a proper name for me — first on punched tape, then on an 8-bit Amstrad CPC 6128, then an IBM x86 clone where I spent evenings writing Basic and Pascal. Not because anyone told me to, but because taking things apart and making them work differently felt natural.
That instinct has never left. It just found larger, more consequential systems to work on.
Two worlds at once
Two worlds, one decade. I ran my own IT consultancy across Szczecin — a world that rewarded improvisation and ownership. At the same time, I held a parallel role inside a military institution, one of the most hierarchically structured environments there is. That one demanded precision, documentation, and alignment to rules I didn't write.
The lesson stuck. Most identity problems aren't purely technical — they live at the boundary between what the business wants and what the rules require. I learned to work that boundary from both sides.
Why IAM specifically
Identity kept finding me. Every infrastructure project, every cloud migration, every security engagement eventually came back to the same core questions: who should have access, to what, under what conditions, and for how long? JML flows, RBAC design, AAA models, SoD, PIM — these aren't separate concerns. They're the same problem at different scales.
At some point I stopped treating identity as a component of larger projects and started treating it as the foundation everything else is built on. That's still how I approach it.
"Digital identity is no longer an IT problem — it's a business one."
That framing reflects where the field is heading. AI-driven impersonation, synthetic identities, agentic "mini-me" access — organisations are being forced to rethink verification and governance at machine speed. Zero Trust is no longer a maturity model. It's operational survival.
That's still the lens I bring to every engagement — the business/rules boundary, worked from both sides. Here's what it looks like in practice:
How I work
I embed long-term when the complexity demands it — designing JML processes, building Entra ID architecture, owning an identity programme end-to-end. I also come in to solve specific problems fast: an SSO integration, a Conditional Access redesign, an access certification process that needs to actually work before an audit.
Current focus
Master Cybersecurity Systems Engineer at Erste Bank Polska (formerly Santander Bank Polska), focused on IAM process design across a hybrid enterprise environment.
Alongside that, select advisory and B2B consulting work — Active Directory, Entra ID, and identity architecture — evenings, 15:00–23:00 CET/CEST.
-
Roundtable participant — Identity in the AI Era, CEE Leaders Forum
Clateway Media · 2026
Expertise
Identity & governance
- Microsoft Entra ID
- Microsoft Active Directory
- JML lifecycle
- IGA & access governance
Zero Trust & access control
- Conditional Access
- Zero Trust
- SAML · OIDC · SCIM
Tooling & certification
- PowerShell
- Python
Still learning, actively
I compete in cloud security championships and CTF challenges — not as a hobby separate from work, but because understanding how environments are attacked makes me a better architect of their defences. Wiz Ultimate Cloud Security Championship (12/12 challenges completed), hackArcana Kubernetes security track (ended), and more on the way.
Full certifications and competition results are on the Portfolio page. If you want to see what I'm working through day to day, the blog is the place.