«Breaches don't just affect systems; they impact revenue, operations, and trust. I help companies uncover real attack paths and fix what truly matters, based on real-world experience.»
Tailored advisory services to support regulatory compliance and strengthen cybersecurity posture, combined with technical expertise in penetration testing, vulnerability assessments, risk analysis, and secure development of management software.
ISO 27001NIS 2CompliancePenetration TestFileMaker
Software Security Consultant
IMQ Minded Security
Italy
Execution of security assessment projects, including web and mobile application penetration testing, source code review, and development of custom rules for SAST activities.
Involved in comprehensive security operations, including proactive monitoring and management of SIEM, endpoint, network, and cloud security systems. Experienced in advanced incident response, threat hunting, and red teaming, as well as conducting penetration tests, vulnerability assessments, phishing simulations, and OSINT analyses.
Conducting vulnerability assessments and penetration tests on applications, web services, and internal or external networks, following OWASP and OSSTMM methodologies, calculating risk using CVSS, and reporting identified vulnerabilities to support effective mitigation strategies.
Web Application SecurityAPI SecurityOWASPOSSTMMRisk Analysis
Scroll down
Studies and Certifications
B.S. in Computer Science
Università Degli Studi Dell'Insubria
Core CS foundations: data structures, algorithms, operating systems, networking, and databases; team capstone in web systems.
Core CS foundations: data structures, algorithms, operating systems, networking, and databases; team capstone in web systems.
Algorithms Data Structures Operating Systems Databases Networking
EWPT
eLearnSecurity
Certified in web application penetration testing, demonstrating expertise in identifying and exploiting security vulnerabilities in web applications.
Certified in web application penetration testing, demonstrating expertise in identifying and exploiting security vulnerabilities in web applications.
Web Application Penetration Test Certification OWASP
Lead Auditor ISO/IEC 27001:2022
Gerico Security Srl
Qualified to lead and conduct ISO 27001 audits on information security management systems.
Qualified to lead and conduct ISO 27001 audits on information security management systems.