Cybersecurity · Ljubljana, Slovenia
Erik Cvetek
Senior Cybersecurity Consultant
From threat detection & response to ISMS, ISO 27001, NIS2 and GRC - I defend business-critical assets and guide organizations to certification.
- $ whoami
- Erik Cvetek · Senior Cybersecurity Consultant
- $ cat focus.txt
- Cyber Defense · Security Operations · GRC
- $ ls ~/stack
- EDR XDR SIEM Email-Security
- $ cat governance.txt
- ISMS · ISO 27001 · TISAX · NIS2 · Internal Audit
- $ status
- ●▋
// about me
Defense in depth - from the SOC to the boardroom.
I'm a cybersecurity professional who works across the full spectrum of defense. On the technical side I manage and tune EDR / XDR, SIEM, and email and endpoint security, run threat detection and hunting, and lead incident response. On the strategic side I design and operate ISMS frameworks and prepare organizations for ISO 27001, TISAX and NIS2 certification - driving implementation and conducting internal audits.
That blend lets me connect day-to-day security operations with governance, risk and compliance - turning controls into measurable outcomes and aligning security with real business objectives. My focus stays the same end to end: minimize risk, strengthen resilience and enable secure innovation across the enterprise.
Cyber Defense · EDR / XDR · SIEM / SOC · Identity Protection
ISMS · ISO 27001 · TISAX · NIS2 · GRC
Incident Response · Threat Hunting · Certification Support
// what I do
Expertise
Hands-on technical defense and strategic governance - the full security lifecycle.
-
Threat Detection & Response
EDR / XDR across endpoints and identities - detection engineering, alert tuning and threat containment.
-
Security Operations & SIEM
SOC monitoring, log correlation and alerting that surface real threats fast.
-
Email, Endpoint & Identity Security
Hardening the three primary attack vectors - anti-phishing, endpoint protection and identity security.
-
Incident Response & Threat Hunting
Prepared playbooks, proactive hunting and calm execution when it matters most.
-
ISMS, ISO 27001 & NIS2
Implementation, certification support and internal auditing of ISO 27001, TISAX and NIS2 - frameworks that actually stick.
-
Governance, Risk & Compliance
GRC programs, NIS2 compliance, internal auditing and risk management that tie controls to real outcomes.
-
Cybersecurity Strategy
Security roadmaps, target operating models and program planning that align cybersecurity with business strategy and risk appetite.
-
Security Architecture
Secure-by-design architecture and reference models - from network and cloud to identity and Zero Trust - that scale with the organization.
// career
Experience
A track record of building and leading security programs.
-
May 2025 - Present
Senior Cybersecurity Consultant
KP Consulting · Ljubljana, Slovenia
Advising organizations on information security strategy, ISMS, GRC and certification pathways - helping SMEs and enterprises strengthen their security posture and achieve ISO 27001, TISAX and NIS2 compliance.
-
Sep 2022 - May 2025
Information Security Manager
Led information security end to end - heading both technical cybersecurity (threat detection & response, vulnerability management, endpoint and email security) and the ISMS & GRC program (governance, risk, compliance and security awareness) across the organization.
-
Jul 2019 - Sep 2022
System Security Specialist
Hardened systems and infrastructure, ran vulnerability assessments and implemented security controls across Windows Server environments.
-
Jul 2015 - Jul 2019
IT Business System Analyst & Support
Bridged business and IT - analyzing requirements, supporting core systems and Office 365, and keeping operations running smoothly.
-
Oct 2013 - Jul 2015
IT Support
Delivered front-line IT support and administration, building the technical foundation that underpins a security-first career.
-
Oct 2010 - Apr 2014
Sales & IT Support
Combined customer-facing sales with hands-on IT support - where it all started.
// credentials
Certifications & education
Credentials and a working toolkit spanning cyber defense, governance and compliance.
Certifications
- Certified SME Cyber Security Officer
- Certified Ransomware Protection Officer
- ITIL® Foundation Certificate in IT Service Management
- More certifications currently in the works
Education
-
University of Ljubljana
Faculty of Computer and Information Science
Languages
- Slovene - Native
- English - Professional
Cyber Defense & Operations
- EDR / XDR
- SIEM / SOC
- Threat Detection & Response
- Threat Hunting
- Incident Response
- Security Architecture
Governance, Risk & Compliance
- ISMS
- ISO 27001
- NIS2
- TISAX
- Risk Management
- Internal Auditing
Security Platforms
- Microsoft Defender
- Microsoft Sentinel
- CrowdStrike
- SentinelOne
- Proofpoint
- Microsoft 365
// get in touch
Let's secure what matters.
Need cybersecurity, information security, GRC or certification support for your organization? Reach out and I'll connect you with the right consulting engagement through KP Consulting.
connect@erikcvetek.comBased in Ljubljana, Slovenia · Consulting inquiries welcome via KP Consulting.