Lugano Metropolitan Area
As InformationSecurity Manager I'm responsible for protecting the confidentiality, integrity and availability of the entire Group's information through the planning, government and monitoring of the Information Security strategy. This includes the adoption of organizational, technical and procedural security measures aimed at protecting assets from both internal and external threats, as well as increasing resilience.
As the Group Information Security Manager I am responsible for: Governance & Control area * Develop and maintain the security policies, coordinate the governance and guarantee the security measures effectiveness. * Define the security strategy and assure compliance with cybersecurity requirements in new projects/changes. Cyber Risk Management & Compliance * Manage risks and regulatory compliance, identifying, evaluating and mitigating cyber risks. * Ensure the compliance with applicable laws, regulations and standards, implementing adequate procedures. Security Operations Detection & Response * Continuously monitor Security Operations to detect and respond to cybersecurity incidents. * Use tools and advanced technologies for network and system surveillance to identify potential threats.
▪ I’m accountable for the study and realization of the Security strategy and architecture that are driving IBSA in its transformation process to become a multinational corporate. ▪ Driving pillars of this activity are: - security governance - creation of internal security policies based on international frameworks, best practices and regulations compliances, - defence - evolutions, extensions and introductions of orchestrated technologies aimed to fortify overall defence, - unification of different realities deriving from diverse corporate functions and from branches acquisitions never integrated into a corporate strategy, - sustainability - rise awareness, develop training, spread and seep security into mindset and processes, - resiliency - creation of internal technologies and processes aimed to reduce the impact and time to recover in case of incidents; - suppliers consolidation.
I have been the first Cyber Security Team's member that have joined the fully digital and totally cloud "illimity Bank" before its born. Here I have designed from a clean sheet and built from scratch the IT security infrastructure of the enterprise both in cloud than on premises. I researched, selected and orchestrated the integration of the solutions to best protect the bank and its customer. I'm currently involved in the design, implementation and run of the Security Operation Center and Fraud Management of the bank.
I was selected as a member of SANS's team running the Munich event in November 2019 in the "Work Study Program". SANS's management assigned to my care "SEC560: Network Penetration Testing and Ethical Hacking" course that was the class with highest number of students and the room that hosted all the @night events.
▪ SIEM: alerts analysis and, eventually, engagement of incident response plan. ▪ Tuning recommendation for security devices (firewall, IDS, endpoint protection, etc.) ▪ First responder. Incident triage. Evidence collection and analysis. IoC list compilation. Short and long term containment. Recovery. ▪ Threat hunting: monitoring and analysis of low level logs produced by various protection devices. ▪ Enterprise delegated member at CERTFin. ▪ Implementation and management of products related to SOC activities like, for example, MISP platform for threat sharing, PassiveDNS probes, Sysmon logging and analysis. ▪ Evolution of incident response plan processes. ▪ Forensic analysis of clients and servers. ▪ On-call shifts on IT security related issues.
Design and evolution of security systems (firewall, IPS, antivirus, internet proxy, access manager suite, Microsoft PKI). ▪ IT Security architect for infrastructure. ▪ Management of projects aimed at data and network security. ▪ Consultancy (providing analysis and technical security recommendations) to internal clients on security issues concerning bank projects. ▪ On-call shifts on IT security related issues (infrastructure operation problems, security incidents, etc.). Recent projects/achievements: ▪ Design and implementation of: ▫ infrastructure security architecture for mobile devices deployment. ▫ Network Access Control (NAC) solution. ▫ Security infrastructure (IPS, anti DDoS, etc.) serving the internal SOC. ▫ User-based and application aware policies on firewalls. ▫ Mainframe placement into network to enable dynamic HA and DR ▫ Studies and activation of SSL inspection on proxy Internet.
▪ Management and maintenance of security systems (firewall, IPS, antivirus, internet proxy, access manager suite, Microsoft PKI). ▪ On-call shifts on IT security related issues (infrastructure operation problems, security incidents, etc.).