SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsIreneusz Tarnowski | DFIR and CTI Professional Poland | 10 GIAC Certifications | GSP and GSE | 3 SANS Courses Completed

First and foremost, I see myself as an analyst. Over the years, I have gained extensive experience in cyber threat intelligence and incident response. At the same time, my experience has gradually taken me beyond purely analytical work, allowing me to lead security processes and teams.
There was no single moment when I decided, “I want to work in cybersecurity.” For me, it was a natural process. My professional journey has been quite long. I started as a programmer, then worked as a systems administrator and systems integrator. Eventually the systems we were building and operating also needed to be secured, and that was how I gradually became a cybersecurity professional. At the time, cybersecurity was still a relatively young discipline. I had the opportunity to grow together with the field, continuously moving into new areas as the technology and threats evolved.
At some point in my career, I felt that I needed to take my knowledge to the next level. In my area of specialization, SANS has always been widely recognized for the quality and technical depth of its training. I wanted to learn from the best, so I decided to experience it for myself.
My first SANS course was FOR508, and it confirmed that this was the kind of training I was looking for: practical, technically deep, and directly applicable to real-world investigations.
Interestingly, I did not start this journey with the GSE as my goal. The idea came later, after I passed my first GX exam — one of the GIAC Applied Knowledge Certifications. It made me realize that I genuinely enjoyed testing not only what I had learned, but also my practical experience and ability to apply that knowledge.
While reading more about the GX exams and the broader GIAC certification path, I discovered the GSP and eventually the GSE. That was the moment when achieving the GSE became something I dreamed about.
My biggest challenge was simply finding enough time.
Working professionally in cybersecurity already requires continuous learning. Threats, technologies, tools, and techniques evolve constantly, and staying current is a significant commitment on its own.
At the same time, my professional life extends beyond my day-to-day responsibilities. I am active in the cybersecurity community, sharing knowledge at conferences and in smaller professional communities, and I also teach cybersecurity at university. Combining all of this with systematic preparation for demanding exams was probably the most difficult part of the journey.
In the beginning, I was not even sure whether I could complete the entire path. But I remember passing my third exam, GREM, and thinking, “Maybe I really can do this.”
I enjoy new challenges, and I also have a strong need to finish what I start. So, I gave myself time. I did not try to rush the journey.
I also realized something very simple: If I want to remain good at what I do, I need to keep learning anyway. So why not make that learning systematic, challenge myself with exams, and use them to validate my progress? That mindset kept me moving forward.
Personally, earning the GSE feels like completing an important stage of my professional development. It is certainly something I am proud of.
Professionally, however, I see the GSE as part of a much broader approach to what it means to be a cybersecurity professional.
Knowledge is important. Experience is essential. You also need to prove yourself through your everyday work and through the problems you are able to solve. But experience alone is not enough. You have to continue learning, challenging your assumptions, and developing your skills. That is what this certification journey represents to me.
I also chose my courses and certifications deliberately. They were not a collection of unrelated certificates. GCFA, GCTI, GCIH, GREM, GEIR, GIME, and the other steps along the way complemented one another and reflected the areas in which I wanted to develop.
My goal has always been to become a more complete analyst on the defensive side of cybersecurity — someone who can understand a threat, investigate an incident, analyze malware, connect technical findings with threat intelligence, and see the bigger picture.
For me, the GSE is a recognition of that journey rather than its final destination.
I have always selected courses based on whether I could apply what I learned directly to my work.
FOR508 is a good example. I was able to bring both investigative methodology and specific techniques and tools from the course into my day-to-day incident response and forensic work. It helped me structure investigations more systematically and approach incidents with a clearer methodology.
The same happened with cyber threat intelligence training. I was able to use that knowledge not only for individual analyses, but also to structure CTI processes and align the way we work with established industry practices.
This is probably what I value most about SANS training: I always take something from a course and use it in my actual work.
I do not approach a course simply as something to complete or an exam to pass. My objective is to understand how professionals solve these problems, why a particular methodology works, and how I can incorporate it into my own way of working.
First, choose your courses carefully. Think about which course best fits your current professional needs, but also consider where you want your career to take you in the future. Ideally, each course should be another piece of a larger development plan.
Be patient as well. The journey does not have to be fast. Give yourself enough time to learn, practice, apply the knowledge in real situations, and then move to the next challenge.
Most importantly, I would not make the GSE itself the primary goal.
The goal should be knowledge. The goal should be becoming better at what you do and being able to apply that knowledge when a real problem appears in front of you.
If you approach the journey this way, the certifications become milestones that validate your progress.
And the GSE? I see it as the recognition and reward that comes at the end of that journey — not the reason for starting it.