You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Patryk KieszekPK

Patryk Kieszek

Web & API Pentester | eJPT · ICCA · ISO 27001 IA

€450/day
Paris, FR
3-7 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Patryk

Web & API Pentester with an offensive, results-oriented approach.

Certified eJPT, ICCA, and ISO 27001 Internal Auditor, I conduct penetration tests targeting web applications, APIs, and SaaS environments under real-world conditions. I gained my experience as a pentester at NASK, the Polish national cybersecurity research institute, where I performed security assessments in production and contributed to vulnerability research that led to a CVE attribution.

Since then, I operate as a freelancer, undertaking commercial pentest missions and Bug Bounty programs on various platforms including HackerOne, with technical reports aligned with OWASP, ISO 27001, GDPR, and SOC 2 requirements. I am currently preparing for the CPTS (Hack The Box) and OSCP certifications.

Educated in both the humanities and code, I studied sociology at Sorbonne University before diving into ethical hacking. My technical foundations were strengthened by intensive training at 42 School in low-level programming - C, C++, Bash, and Python, enabling me to analyze systems in depth and understand business risk.

My approach is pragmatic and offensive: I seek exploitable vulnerabilities, assess their real business impact, and deliver concrete recommendations, accessible to all stakeholders.

I work in French, English, Spanish, and Polish, remotely or occasionally in person. If you are developing a high-potential solution, I can help make it more secure without unnecessary jargon.
  • Polish

    Native or bilingual

  • French

    Native or bilingual

  • English

    Fluent

  • Spanish

    Conversational

Can work on-site
Paris (up to 50km)

Experience

  • NASK - Institut national de recherche en cybersécurité (Pologne)
    Intern Pentester
    CONSULTING AND AUDITS
    October 2025 - January 2026 (3 months)
    Varsovie, Poland
    - Conducted penetration tests on web applications in internal and production environments, identifying critical vulnerabilities related to authentication, session management, and access control by applying the OWASP Top 10 methodology.

    - Performed security assessments on internal networks as part of structured audits, contributing to the drafting of risk-oriented reports transmitted to stakeholders.

    - Contributed to vulnerability research that led to a CVE attribution, by responsibly identifying and disclosing a flaw discovered during a real-world audit.

    - Participated in security audits aligned with industry compliance frameworks, supporting the documentation and analysis of results across multiple engagements.
    Internal Audit Internal Penetration Test Cybersecurity Audit API Audit
  • MyDataSolutions
    External Cybersecurity Consultant
    CONSULTING AND AUDITS
    May 2025 - September 2025 (4 months)
    Paris, France
    Engaged as a freelancer to support audits, risk assessments, and compliance validations, with a focus on technical analysis, data protection, and the implementation of security controls for public and private clients.
    Cybersecurity Audit Internal Audit API Audit Reporting configuration audit
  • patsecu
    Cybersecurity Consultant / Pentester
    CONSULTING AND AUDITS
    November 2024 - Today (1 year and 7 months)
    Paris, France
    - Conducted a comprehensive commercial penetration test on a SaaS web application, covering OWASP Top 10 attack vectors, by combining manual and automated assessments on authentication, access control, and business logic layers.

    - Produced a risk-oriented technical report with proof-of-concept demonstrations for each finding, enabling the client to prioritize and initiate remediation immediately after delivery.

    - Contributed to vulnerability research that resulted in a CVE attribution during work at NASK, the Polish national cybersecurity institute, by responsibly identifying and disclosing a flaw discovered in a production environment.

    - Developed reusable pentest and audit templates aligned with ISO 27001 and PTES frameworks, standardizing assessment workflows across engagements.

    - Actively identified security vulnerabilities on multiple bug bounty platforms, including HackerOne, targeting authentication flaws, broken access controls, and client-side exposures in real production environments.
    Internal Audit Internal Pentester OWASP Cybersecurity Audit API Audit

Recommendations

Be the first to recommend Patryk

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master's in Cybersecurity
    University of Warsaw
    Master's in Cybersecurity
  • Programming Training
    42 School
    2026
    C, C++, Bash, Python

Certifications

  • eJPT
    INE (INE Security / eLearnSecurity)
    2025
    Burp Suite Cybersecurity Audit Linux System Administration OWASP PenTest OSINT Windows Nmap
  • ICCA
    INE
    2025
    Cloud Computing Google Cloud Platform (GCP) Cloud Azure AWS

Skill set

Categories