preloader

ABOUT

Rzec AB is an IT-security consulting business founded and led by Tomas Rzepka, based in Stockholm, Sweden. Specializing in a range of security services, the company offers assessments, architecture, red/purple teaming, and training, with over 20 years’ experience in the industry. I provide personalized and high-quality services to clients of all sizes, aiding with vulnerability identification and overall security improvements. Contact for me more information on protecting against cyber threats.

about-me

EXPERIENCE

  • Founder of Rzec AB; Senior IT Security Consultant

    Rzec AB | 2023-current

    IT-security consulting with focus on security assessments, security architecture, red / purple teaming and cyber security training.

  • Senior IT Security Consultant

    F-Secure / WithSecure | 2019-2023

    Security assessments of applications and infrastructure penetrations tests (Attack Path Mapping and red teaming) as well as hardware hacking and reverse engineering. I also led workshops for threat modeling and current state analysis, as well as architecting implementation according to security requirement specifications. Discovered high severity CVE-2021-3057 in Palo Alto Network GlobalProtect VPN client.

  • IT-security specialist

    Swedish Security Service | 2017-2019

    Reviewing security designs and penetration testing IT-systems related to companies and government agencies of importance to Swedish national security. Member of the Swedish team for NATO CCDCOE Locked Shields 2019.

  • IT-security specialist

    Swedish Police Authority | 2015-2017

    Worked in the Computer Emergency Response Team with focus on penetration testing internal systems and as part of the internal red team, training the blue team on detecting intrusions.

  • IT Security Consultant

    Certezza | 2010-2015

    Initially worked with implementation and design of network security solutions as well as generic information security. Joined the penetration testing team and earned a GIAC Web Application Penetration Tester (GWAPT) certification. Eventually, I became the team lead and focused solely on pentest assignments.

  • Network Security Engineer

    2000-2010

    Presales, support and training; firewalls, VPN, MFA, and other security products. Acquired CISSP certification (2009).

  • IT Consultant

    1998-2000

    Generic IT, web development and network security consulting.

SERVICES

  • Security assessment image
  • Security Architecture image
  • Red and Purple team resource image
  • Training and workshops image