Skip to content
profix::sec
HU

SECURITY ENGINEERING · OFFENSIVE SECURITY

One major implementation at a time

We help companies identify security weaknesses and actually fix them.

I'm Levente Lajkó, a security engineer in Budapest. By day I run security operations for a national telecom: SIEM engineering, detection tuning, log pipelines. PROFIX is where I do the same work for companies that need it done once and done properly. I find what an attacker would find, then I build the thing that closes it.

See what I do

30 minutes, no charge. Or email hello@profixsec.com

My risk, not yours

On the first engagement: if your auditor rejects the remediation plan I write, I don't invoice it.

Fixed price, 2–3 day turnaroundNDA as standardHackTheBox Global Top 1000

SAMPLE · WHAT A TUNED FEED SURFACES

What I do

Find it, then fix it.

Most providers sell one side of this. Here the finding and the repair are the same engagement, run by the same person.

Identify

Diagnostics
Security Assessment
A structured review of where you actually stand: architecture, access paths, exposure, and what an attacker reaches first.
Vulnerability Assessment
Authenticated scanning across servers, endpoints and network gear, with the false positives stripped out and the rest ranked by what it would cost you.
Web / API Security Testing
Manual testing of your own applications and APIs: authentication, authorisation, injection, business logic. The things a scanner reports as clean.
Adversary Simulation
Goal-based testing against a named objective, from an agreed starting point. I scope it down to what is genuinely useful rather than selling it as a full-scope red team, and I say so in writing before you buy.

Fix

Hardening & code
Linux & Infrastructure Hardening
Baseline configuration, patch discipline, service exposure, and logging that survives a reboot. Debian, RHEL, Ubuntu, containers.
IAM & Access Control
SSO, MFA, least privilege, and access reviews that run on a schedule instead of when someone remembers.
Security Automation
Alert triage, enrichment and evidence collection that runs without you. 500 alerts in, three that need a person.
Network Segmentation
Separating what should not talk to what, in real networks with real production constraints, including OT/IT converged sites.
DevSecOps
Secrets management, pipeline security, dependency and image scanning wired into the build instead of bolted on afterwards.

Who I work with

Companies with real infrastructure and real risk, usually between 50 and 500 people.

  • SMEs
  • Technology companies
  • Manufacturing
  • SaaS
  • Enterprise suppliers

Where to start

What are you up against?

Pick whichever stings most. You get back what I look at first, what lands on your desk at the end, and how long it takes.

Pick a focus

The first engagement

Turnaround

2–3 working days

Price

From €1,200, fixed

What I look at
Architecture, access management, logging, backup and network separation, against whichever framework applies to you.
What you get
A prioritised remediation plan with a concrete step next to every finding.

Whatever follows from the assessment is quoted separately. You are under no obligation to continue, and I will say so on the call if I am not the right person for it.

How it works

Four steps, no obligation past the first one.

01

Intro call

30 minutes, no charge. We figure out if it's a fit and I learn enough about your environment to scope the assessment.

02

Gap assessment

2–3 days, fixed price, delivered as a prioritised written report plus a walkthrough call.

03

You decide

No obligation to continue. If you want implementation support, it's scoped as a separate, clearly-priced engagement.

04

Implementation

Scoped, milestone-based delivery, direct communication throughout. No account-manager layer.

The practice

PROFIX Security Engineering

Founded and run by a practising security engineer. You deal with the person who does the work, not an account team with a junior behind it.

Lajkó Levente

Lajkó Levente

Founder & CEO

Budapest, HU

HackTheBoxGlobal Top 1000
In progressOSCP · AZ-500 · CISSP

I run security operations for a national telecom by day: SIEM engineering, detection tuning, log pipelines, and the automation that keeps them useful. Before that I took a multinational manufacturing site through NIS2, and built the security layer around production AI systems handling confidential records.

PROFIX is where I do that same work for companies that need it done once, properly, rather than staffed permanently. The practice is new. The work is not, and it is all verifiable below and on LinkedIn.

You get the person who does the work

No account manager, no handover to a junior after the kickoff call.

Everything I build, you own

Configuration, scripts and evidence pipelines, documented so your team can run them without me.

Selected work

The work behind the claims.

BYD

BYD

Automotive manufacturing · multinational

Cyber Security Engineer, site-level

Taking a converged OT/IT manufacturing site through NIS2

A manufacturing site fell under EU NIS2 with production systems and corporate IT sharing the same network reality. Compliance ownership was split across IT, overseas InfoSec, EHS, HR and production, with external compliance partners involved, and no single technical strategy tying it together.

  • Defined and executed the site-level cybersecurity strategy against NIS2 requirements
  • Implemented network segmentation, Zero Trust architecture and vulnerability management across OT/IT converged systems
  • Ran cross-functional security governance across five departments, including vendor and third-party risk management
  • Coordinated secure network architecture with the telecom provider and managed external compliance partners
  • Identified and remediated vulnerabilities on ICS/SCADA-adjacent systems using Wireshark and Nmap, reducing attack surface
NIS2OT / IT convergenceSegmentationZero TrustGRC
ONE Hungary

ONE Hungary

Telecommunications · national carrier

Cyber Operations Expert

Detection engineering across a multi-vendor SIEM estate

A national telecom runs security operations across five SIEM and log platforms at once, plus an in-house platform. At carrier volume, the hard problems are not tooling but detection quality, log integrity and the manual effort of keeping both correct.

  • Operate and tune a multi-vendor stack: Splunk, Microsoft Sentinel, Wazuh, Elastic/ELK and IBM QRadar
  • Write and tune detection alerts in KQL and SPL, aligned to the MITRE ATT&CK framework
  • Troubleshoot log transport pipelines (syslog-ng, nxlog) and LDAP/Active Directory authentication across enterprise Linux and Docker
  • Build internal security automation in Python and Bash, with Ansible for configuration management and runbook automation
  • Apply AI-assisted log analysis to log quality and throughput, feeding anomaly and threat detection
SIEMDetection engineeringMITRE ATT&CKLog pipelinesAutomation
Kibit Solutions

Kibit Solutions

AI systems · document automation

Machine Learning Engineer

Securing an AI pipeline that handles confidential records

Production AI agents processed CVs, candidate data and financial documents, which meant sensitive personal and financial data flowing through LLM infrastructure at volume. The security questions were not theoretical: prompt injection, data leakage, and who can retrieve what.

  • Built vector retrieval pipelines across 10,000+ documents with data minimization and access control for confidential records
  • Implemented input validation and sanitization to mitigate prompt injection and data-leakage risk
  • Deployed hardened LLM inference backends (FastAPI/Uvicorn) in Docker, shipped via GitHub Actions CI/CD on GCP
  • Set up API authentication and secrets management for the inference layer
  • Automated end-to-end document processing with NER and entity linking across PDF, DOCX, image and CSV inputs
AI securityPII handlingPrompt injectionSecrets managementGCP

Same controls, different label

NIS2ISO 27001DORASOC 2PCI DSSPentest findingsYour own risk framework

The gap

A finding on a page changes nothing on its own.

Without implementation

  • Nobody has physically walked your network segmentation.
  • Your incident response plan has never met a real incident.
  • IT and security still argue about who owns a finding.
  • Backups exist on paper, but nobody has ever restored from one.
  • Evidence for the next audit gets scrambled together the week before.

With it

  • Every login, access change, and config edit logged, retained, and queryable, not buried in a SIEM nobody reads.
  • Access reviews run on a schedule, not when someone remembers. Dormant privileged accounts get flagged automatically.
  • One person owns the fix end to end. No handoff between the report and the person who configures the firewall.
  • Backups restore because the restore was tested. The test log is the audit evidence.
  • Audit evidence exports itself. The next assessment is a formality, not a fire drill.

That gap, the one between the paperwork and the actual risk, is where I work.

Why not the alternatives

Two things you've probably already tried.

A compliance platform

Tools built for NIS2, ISO 27001, SOC 2, or DORA are good at generating policy documents and tracking a risk register. They aren't built to walk your production floor, segment your network, or tune your SIEM. That's a different skill, and it's the one I bring.

A big consultancy

Big firms are built for engagements with matching minimums and timelines. You get a senior partner in the kickoff and a junior analyst doing the work for the next six months. I do the work myself, starting faster because there's no approval chain between you and me.

  • Framework-agnostic: led NIS2 site-level security strategy and cross-department alignment (IT, overseas InfoSec, EHS, HR, production) at a multinational manufacturing site. The same governance approach applies under ISO 27001, DORA, or SOC 2.
  • OT/IT convergence: hands-on network segmentation, Zero Trust, and vulnerability management in live manufacturing environments.
  • AI-driven SecOps: building log-anomaly detection and security automation in a large-scale telco SecOps environment.
  • Offensive-side literacy: I build and publish my own red-team tooling, with documented limitations. I know what a real attacker path looks like, not just what a checklist says.

Engagement ladder

What I do, in the order it usually happens.

01

Security & Compliance Gap Assessment

A concrete, prioritised report against whatever applies to you: NIS2, ISO 27001, DORA, SOC 2, or your own risk framework. No vague findings, a remediation step for each one.

From €1,200 · fixed price · 2–3 days

02

Focused Build

One control area taken to a working state: backup with tested recovery, automated access reviews, or central logging with tuned alerts. Fixed price, delivered within two weeks, handed over documented.

From €2,500 · fixed price · 2 weeks

03

Security Systems, Built

Access management with SSO, MFA and scheduled access reviews. Logging and detection that someone actually reads. Backups that restore: 3-2-1-1-0, immutable copy, tested recovery. Network segmentation. Built on proven open-source components, so you pay for engineering, not licences. Everything documented, everything yours.

From €6,000 · milestone-based

04

SecOps Automation

Alert triage, enrichment and evidence collection that runs itself. The outcome: 500 alerts in, three that need a human. Built the same way I build it for a national telecom.

Scoped per environment

05

Continuous Controls Monitoring

The systems stay compliant after I leave: scheduled access reviews, configuration drift detection, quarterly restore tests, and audit evidence that exports itself before every assessment. Not a 24/7 hotline, but an automated control loop with an engineer behind it.

From €700 / month

My risk, not yours

On the first engagement: if your auditor or the authority doesn't accept the remediation plan I produce, I don't invoice it. I can offer that because the work is technical, and technical work either holds up under inspection or it doesn't.

FAQ

Questions worth answering up front.

Get started

Let's look at your gap.

30 minutes, no charge, no obligation. Bring whatever you've got: an audit report, a pentest finding, or just a hunch.

  • I tell you on the call if I am not the right person for it.
  • You leave with a direction or a number, not a follow-up deck.
  • Confidential. NDA as standard.