alenkrga.

Security operations / Cyber risk / Resilience

Alen Krga.

Security & Resilience
Engineer.

I’m a Senior Security & Resilience Engineer based in Croatia. I connect security monitoring, incident investigation and cyber risk to help make informed decisions and improve operational resilience.

Find me on LinkedIn ↗
Based in Croatia · Previously in IrelandSecurity · Risk · Resilience

Security, in practice.

01

Security operations

Security operations, incident investigation and threat-informed analysis. Following evidence rather than jumping to the first explanation.

Detection & response
02

Cyber risk

Vulnerabilities, exposure and cyber risk. Connecting technical severity with the context that makes a finding matter.

Risk & perspective
03

Operational resilience

Control gaps, procedures and operational resilience. Learning from findings and improving the way things work.

Resilience & improvement

Writing about cybersecurity.

Visit my blog ↗

Recent writing from my cybersecurity blog.

From the blog

What is CyScan.io

CyScan.io, also known as Cyber URL Scanner, is a simple online tool to check websites before you interact with them. Built by cybersecurity professionals, it…

Read article ↗
From the blog

Asymmetric Encryption

Decrypt Everything: Understanding Asymmetric Encryption Introduction:In today’s digital world, protecting our data is crucial. Encryption plays a key role in keeping our…

Read article ↗
From the blog

What is Symmetric Encryption?

Symmetric encryption is a method of protecting data by using a private key to encrypt (lock) and decrypt (unlock) it. Both the sender and recipient…

Read article ↗

Technical context.
Business perspective.

My work sits where technical signals, people and decisions meet.

My background includes running a retail and e-commerce business, managing sales, webshop operations, website maintenance and administration, and digital marketing.

In Dublin, I moved into operations, auditing and policy work, then cyber risk. My path continued through security operations to security and resilience engineering in Croatia. Running a business gave me a practical perspective on technology, everyday operations and customer needs.

That mix shapes how I approach a problem: understand the evidence, put it in context, and work out what to do next. An alert is a starting point. The interesting part is figuring out what it means.

English & Croatian

My professional journey.

From running a business
to security & resilience.

Current role

Senior Security & Resilience Engineer

I work across monitoring, investigation, vulnerability priorities and resilience, bringing technical findings into conversations about risk and controls.

Security operationsCyber riskResilience

Security Operations

Hands-on monitoring and alert investigation, remediation follow-through and control reviews — working with engineering teams to make security part of everyday delivery.

InvestigationVulnerability management

Cyber Security & InfoSec — Second Line

A financial-services perspective on security: risk guidance, policy exceptions and control decisions, with threat intelligence providing additional context.

Second-line riskControls

Policy SME, Auditor & Operations Analyst

Operations, quality, root-cause analysis and training. This is where I built the analytical and people skills that I still bring to security work.

AnalysisPolicyPeople & process

Business Owner · Retail & E-commerce

I ran my own retail and e-commerce business, overseeing day-to-day operations, sales, the online store and digital marketing. This gave me practical experience of business ownership and the role technology plays in everyday operations.

Continuous learning.
Applied knowledge.

Certifications are one part of the journey. Applying the learning is the part that stays interesting.

CompTIA CSAP2025
CompTIA CySA+2025
CompTIA Security+2024
CompTIA Network+2024

Also in my learning toolkit: ATT&CK training, NIST control assessment, OWASP concepts, and a full-stack development foundation.

Explore. Investigate. Learn.

If you like exploring, I made an interactive terminal and a few small security challenges. There’s more here than first meets the eye.

Analyst Terminal

A different way to explore this page. Type help, or mission to try a challenge.

A little experiment
alen / analyst terminal
LOCAL SESSION · --:--:--
analyst@portfolio:~$

Four decisions. Your call.

A few small scenarios about evidence, judgement and trade-offs. There is something to discover if you finish all four.

XP 000
0/4
ALERT-01HIGH

Suspicious Authentication

Choose the strongest first investigative action before containment.

VULN-01MED

Vulnerability Priority

Balance technical severity with exposure and business context.

ATK-01HUNT

Threat-Informed Investigation

Use behavior and telemetry to validate a threat hypothesis.

RISK-01RISK

Control Exception

Choose a risk treatment that is explicit, owned and time-bound.

Following a signal

A lightweight interactive representation of the way I reason across signals, risk and response.

SECURITY OPSCORRELATE · DECIDE · RESPOND IDENTITYAUTHENTICATION SIGNALS ENDPOINTBEHAVIORAL ALERT CLOUDPOSTURE · EXPOSURE VULNERABILITYPRIORITIZED FINDING THREAT INTELCONTEXT · TTPs
Three starting points
HIGH
Suspicious authentication sequence
Identity · behavior anomaly
MED
Exposure requiring prioritization
Vulnerability · business context
MED
Control exception approaching review
Risk · governance workflow

An illustrative workflow: collect signals, validate evidence, understand impact, make a risk-based decision, and improve controls.

Let’s connect.

You can find me on LinkedIn for conversations about security, risk and resilience.

Connect on LinkedIn ↗
Cookies & local storage

The portfolio code does not set cookies or use persistent browser storage. Interface preferences, challenge progress and game scores are held only in memory while this page is open and reset when it is reloaded. This version does not read any game data saved by earlier versions; you can remove those old values using your browser’s site-data settings. Hosting services and the linked WordPress blog may process technical data separately.