Marco Bonino

CSIRT analyst

Paris, Île-de-France, France

About

15 years of experience working in various fields of IT, mainly Ops. Currently, my area of interest is IT security, leveraging DevOps tools and methodology to make applications and infrastructures more secure. Competencies: IT security, hardening, Linux, DevSecOps, cloud computing, Docker, Ansible, Python, network protocols.

Experience

  • Confidentiel at Ministère de l’Économie, des Finances et de la Souveraineté industrielle et numérique
    Nov 2024 - Present · 1 yr 8 mos

  • SysOps / SecOps at Société Générale
    Apr 2020 - Jan 2025 · 4 yrs 10 mos

  • Cloud Security Architect at D2SI
    Apr 2019 - Apr 2020 · 1 yr 1 mo

    • RFP requirements analysis, solutions definition and associated cost estimates • DevSecOps attached to the network perimeter security team at AirLiquide: - Extranet security policy definition - API security policy definition - Cloud misconfiguration or compliance violations detection, reporting and remediation - Security dashboard (Splunk)

  • Cloud and DevOps Security (Internship) at Orange
    Jul 2018 - Dec 2018 · 6 mos

    • Linux server hardening automation via Ansible playbooks • Development of an OWASP ZAP’s plugin for access control testing • Automation of RESTful APIs’ security scan in a CI/CD pipeline • Automation of security groups’ audit in cloud environment • Static Application Security Testing (SAST) Skills and tools : Git, Jenkins, Docker, Vagrant, Ansible, Cloud-init, ZAP, Pentest, Python, Postman, VMware, Openstack, SonarQube, Java

  • Linux System Administrator at Gutenberg
    Sep 2016 - Jul 2017 · 11 mos

    • Installation and administration of CentOS / RHEL and SUSE Linux servers • Administration of FTP servers • Migration of Xinet's Fullpress DAM from SGI Altix 450 to SGI UV 3000 Skills and tool: RHEL, Suse Linux, Sysadmin