Cybersecurity · Ljubljana, Slovenia

Erik Cvetek

Senior Cybersecurity Consultant

From threat detection & response to ISMS, ISO 27001, NIS2 and GRC - I defend business-critical assets and guide organizations to certification.

  • EDR / XDR
  • SIEM / SOC
  • ISO 27001
  • NIS2
  • GRC
Erik Cvetek, Senior Cybersecurity Consultant in Ljubljana, Slovenia
15+ years Experience across IT and cyber security
ISO 27001 Implementation & auditing
NIS2 · TISAX Compliance & certification
24/7 Detection & response mindset
erikcvetek@security - ~ %
  • $ whoami
  • Erik Cvetek · Senior Cybersecurity Consultant
  • $ cat focus.txt
  • Cyber Defense · Security Operations · GRC
  • $ ls ~/stack
  • EDR  XDR  SIEM  Email-Security
  • $ cat governance.txt
  • ISMS · ISO 27001 · TISAX · NIS2 · Internal Audit
  • $ status
15+ years Experience across IT and cyber security

// about me

Defense in depth - from the SOC to the boardroom.

I'm a cybersecurity professional who works across the full spectrum of defense. On the technical side I manage and tune EDR / XDR, SIEM, and email and endpoint security, run threat detection and hunting, and lead incident response. On the strategic side I design and operate ISMS frameworks and prepare organizations for ISO 27001, TISAX and NIS2 certification - driving implementation and conducting internal audits.

That blend lets me connect day-to-day security operations with governance, risk and compliance - turning controls into measurable outcomes and aligning security with real business objectives. My focus stays the same end to end: minimize risk, strengthen resilience and enable secure innovation across the enterprise.

Cyber Defense · EDR / XDR · SIEM / SOC · Identity Protection
ISMS · ISO 27001 · TISAX · NIS2 · GRC
Incident Response · Threat Hunting · Certification Support

// what I do

Expertise

Hands-on technical defense and strategic governance - the full security lifecycle.

  • Threat Detection & Response

    EDR / XDR across endpoints and identities - detection engineering, alert tuning and threat containment.

  • Security Operations & SIEM

    SOC monitoring, log correlation and alerting that surface real threats fast.

  • Email, Endpoint & Identity Security

    Hardening the three primary attack vectors - anti-phishing, endpoint protection and identity security.

  • Incident Response & Threat Hunting

    Prepared playbooks, proactive hunting and calm execution when it matters most.

  • ISMS, ISO 27001 & NIS2

    Implementation, certification support and internal auditing of ISO 27001, TISAX and NIS2 - frameworks that actually stick.

  • Governance, Risk & Compliance

    GRC programs, NIS2 compliance, internal auditing and risk management that tie controls to real outcomes.

  • Cybersecurity Strategy

    Security roadmaps, target operating models and program planning that align cybersecurity with business strategy and risk appetite.

  • Security Architecture

    Secure-by-design architecture and reference models - from network and cloud to identity and Zero Trust - that scale with the organization.

// career

Experience

A track record of building and leading security programs.

  1. May 2025 - Present

    Senior Cybersecurity Consultant

    KP Consulting · Ljubljana, Slovenia

    Advising organizations on information security strategy, ISMS, GRC and certification pathways - helping SMEs and enterprises strengthen their security posture and achieve ISO 27001, TISAX and NIS2 compliance.

  2. Sep 2022 - May 2025

    Information Security Manager

    Led information security end to end - heading both technical cybersecurity (threat detection & response, vulnerability management, endpoint and email security) and the ISMS & GRC program (governance, risk, compliance and security awareness) across the organization.

  3. Jul 2019 - Sep 2022

    System Security Specialist

    Hardened systems and infrastructure, ran vulnerability assessments and implemented security controls across Windows Server environments.

  4. Jul 2015 - Jul 2019

    IT Business System Analyst & Support

    Bridged business and IT - analyzing requirements, supporting core systems and Office 365, and keeping operations running smoothly.

  5. Oct 2013 - Jul 2015

    IT Support

    Delivered front-line IT support and administration, building the technical foundation that underpins a security-first career.

  6. Oct 2010 - Apr 2014

    Sales & IT Support

    Combined customer-facing sales with hands-on IT support - where it all started.

// credentials

Certifications & education

Credentials and a working toolkit spanning cyber defense, governance and compliance.

Certifications

  • Certified SME Cyber Security Officer
  • Certified Ransomware Protection Officer
  • ITIL® Foundation Certificate in IT Service Management
  • More certifications currently in the works

Education

  • University of Ljubljana
    Faculty of Computer and Information Science
    BSc, Computer Science & Informatics · 2008-2014

Languages

  • Slovene - Native
  • English - Professional

Cyber Defense & Operations

  • EDR / XDR
  • SIEM / SOC
  • Threat Detection & Response
  • Threat Hunting
  • Incident Response
  • Security Architecture

Governance, Risk & Compliance

  • ISMS
  • ISO 27001
  • NIS2
  • TISAX
  • Risk Management
  • Internal Auditing

Security Platforms

  • Microsoft Defender
  • Microsoft Sentinel
  • CrowdStrike
  • SentinelOne
  • Proofpoint
  • Microsoft 365

// get in touch

Let's secure what matters.

Need cybersecurity, information security, GRC or certification support for your organization? Reach out and I'll connect you with the right consulting engagement through KP Consulting.

Based in Ljubljana, Slovenia · Consulting inquiries welcome via KP Consulting.