Curriculum Vitæ
Complete Curriculum Vitæ
Download the English version of my complete Curriculum Vitæ [HERE].
Brief Curriculum Vitæ
Desired employment, occupational field: Security and network consultant
Work experience
From May 2007 – Consultant at Spike Reply. Main activities involve design and implementation of Identity and Access Management infrastructures in medium and big-size international companies.
From January 2003 to April 2007 – Freelance consultant. Main activities involve IT assistance and mantenance in small offices.
From August 2006 to March 2007 – Stageur at LaSeR lab working on analysis and development of malware containment systems.
From March 2004 to October 2004 – Stageur at CERT-IT Computer Emergency Response Team – Italy working on analysis and development of a semi-automated incident management system.
Education and training
From December 2004 to April 2007 – Master Degree in Information and Communication Technologies at the University of Milan with a final grade of 110/110 cum laude and a work on “Study and analysis of intrusion detection systems for polymorphic worms”.
From October 2002 to December 2004 – Bachelor Degree in Computer Science at the University of Milan with a final grade of 110/110 and a work on “Realization of semi-automatic incident report management system”.
December 2008 – Certification as Lead Auditor ISO/IEC 27001 Information Security Management.
October 2007 – Training course CA (Computer Associates) eTrust SiteMinder 6.0 Combo (ET775).
December 2004 – FSE (European Social Fund) course on Java Network Programming.
Personal skills and competences
Mother tongue: Italian
Other languages: English, French
Social skills and competences: I like working in dynamical environment and in multi-cultural teams where comunication is a key aspect.
During my stages at CERT-IT and in my current work I have acquired good skills on working in medium-sized team but holding however a fairly good working autonomy.
Organisational skills and competences: I think that organizational skills are required to arranging and keeping everything in order.
Organizational skills enable an individual to complete all tasks in the limited time available.
Technical skills and competences
Good knowledge and fairly good management expertise on Windows systems (of different versions) and good knowledge and good management expertise on Linux systems.
Good knowledge of Java and fairly good of Python, Perl, VB.net, C, PHP, pascal, HTML, assembly x86.
Good knowledge of SQL (T-SQL, P-SQL) and relational DMBS. Good analisys and design skills and base knowledge of object-oriented DBMS.
Good knowledge of the most important network infrastructures and protocols. Fairly good administration skills of networking devices and good knowledge of the most known IT security issues and theirs countermisures.
Good knowledge of Identity and Access Management issues in medium and big-size international companies and good analysis and development (Microsoft, CA, Novell tools) skills.
Awards
Second classified at “Premio tesi CLUSIT 2007″ award, for the best information security thesis.
Papers
LISABETH: Automated Content-Based Signatures Generator for Zero-day Polymorphic Worms, University of Milan, Milan, 03/2007.
LISABETH: Automated Content-Based Signatures Generator for Zero-day Polymorphic Worms, SESS08, Leipzig, 05/2008.
Security and network consultant
Work experience
Dates 20 of May 2007 ->
Occupation or position held
Junior consultant
Main activities and responsibilities
Design and implementation of IAM infrastructure in medium and big-size international companies
Name and address of employer
Spike Reply s.r.l.
via Brembo, 27
20139 Milano (MI)
Type of business or sector
ICT security
Dates 01 January 2003 – 30 April 2007
Main activities and responsibilities
IT assistance and mantenance in small offices
Name and address of employer
Freelance
Type of business or sector
IT assistance
Dates 01 August 2006 – 31 March 2007
Occupation or position held
Stageur
Main activities and responsibilities
Analysis and development of malware containment systems
Name and address of employer
CERT-IT Computer Emergency Response Team – Italy
Dipartimento di Informatica e Comunicazione
Università degli Studi di Milano
Via Comelico 39
20135, Milano
Type of business or sector
Research
Dates 01 March 2004 – 31 October 2004
Occupation or position held
Stageur
Main activities and responsibilities
Analysis and development of a semi-automated incident management system
Name and address of employer
CERT-IT Computer Emergency Response Team – Italy
Dipartimento di Informatica e Comunicazione
Università degli Studi di Milano
Via Comelico 39
20135, Milano
Type of business or sector
Research
Education and training
Dates 01 December 2004 – 16 April 2007
Title of qualification awarded
Master Degree in Information and Communication Technologies at the University of Milan with a final grade of 110/110 cum laude and a work on “Study and analysis of intrusion detection systems for polymorphic worms”
Name and type of organisation providing education and training
Università degli Studi di Milano
via Festa del Perdono 7
20122, Milano
Level in national or international classification
Master Degree (Laurea Magistrale)
Dates 01 October 2002 – 17 December 2004
Title of qualification awarded
Bachelor Degree in Computer Science at the University of Milan with a final grade of 110/110 and a work on “Realization of semi-automatic incident report management system”
Name and type of organisation providing education and training
Università degli Studi di Milano
via Festa del Perdono 7
20122, Milano
Level in national or international classification
Bachelor Degree (Laurea Triennale)
Dates 15 December 2008 – 19 December 2008
Title of qualification awarded
Lead Auditor – ISO/IEC 27001 Information Security Management
Principal subjects / occupational skills covered
Including the following topics:
- Information security
- The importance of information security
- ISO 27001
- Reviewing security threats and vulnerabilities
- Management of security risks
- Selecting security controls
- How to build an Information Security Management System (ISMS)
- ISO 27001 auditing techniques
- Managing and leading an ISO 27001 audit team
- Interview techniques
- Audit reporting
- Examination to prove competency
Name and type of organisation providing education and training
BSI Management Systems Italia s.r.l.
Corso Milano 21, 20052 Monza (Italy)
Level in national or international classification
IRCA certified course (A17287)
Dates 01 October 2007 – 05 October 2007
Title of qualification awarded
CA (Computer Associates) eTrust SiteMinder 6.0 Combo (ET775)
Principal subjects / occupational skills covered
eTrust SiteMinder Combo is a five day course that gives you intensive practical reinforcement of environmental conditions by performing the installation, configuration, tuning and troubleshooting of an eTrust SiteMinder implementation in a fail safe environment. All processes are taught from a best practices perspective. This is an experiential class focused on systems infrastructure.
Name and type of organisation providing education and training
COMPUTER ASSOCIATES
Palazzo uffici nuova sede di Milano 3 City
Via F. Sforza, 3. 20100 Milano
Italy
Level in national or international classification
Training course
Dates 01 December 2004 – 31 December 2004
Title of qualification awarded
FSE (European Social Fund) course on Java Network Programming
Principal subjects / occupational skills covered
The course provides a general background in network fundamentals, as well as detailed discussions of Java’s facilities for writing network programs. I learn how to write Java programs that share data across the Internet for games, collaboration, software updates, file transfer, and more.
Name and type of organisation providing education and training
Università degli Studi di Milano
via Festa del Perdono 7
20122, Milano
Level in national or international classification
Training course
Personal skills and competences
Mother tongue(s)
Italian
Other language(s)
Self-assessment European level (*)
English
Understanding Listening
B1 Independent user
Understanding Reading
C2 Proficient user
Speaking – Spoken interaction
B1 Independent user
Speaking – Spoken production
B2 Independent user
Writing
B2 Independent user
French
Understanding Listening
A2 Basic User
Understanding Reading
A2 Basic User
Speaking – Spoken interaction
A1 Basic User
Speaking – Spoken production
A1 Basic User
Writing
A1 Basic User
(*) Common European Framework of Reference (CEF) level
Social skills and competences
I like working in dynamical environment and in multi-cultural teams where comunication is a key aspect.
During my stages at CERT-IT and in my current work I have acquired good skills on working in medium-sized team but holding however a fairly good working autonomy.
Organisational skills and competences
I think that organizational skills are required to arranging and keeping everything in order.
Organizational skills enable an individual to complete all tasks in the limited time available.
Technical skills and competences
Operating systems:
Good knowledge and fairly good management expertise on Windows systems (of different versions).
Good knowledge and good management expertise on Linux systems;
Programming languages:
Good knowledge of Java.
Fairly good of Python, Perl, VB.net, C, PHP, pascal, HTML, assembly x86.
DBMS and DB:
Good knowledge of SQL (T-SQL, P-SQL) and relational DMBS. Good analisys and design skills.
Base knowledge of object-oriented DBMS.
Networking:
Good knowledge of the most important network infrastructures and protocols. Fairly good administration skills of networking devices.
ICT Security:
Good knowledge of the most known IT security issues and theirs countermisures.
Good knowledge of Identity and Access Management issues in medium and big-size international companies and good analysis and development (Microsoft, CA, Novell tools) skills.
Driving licence(s)
Driving licence of B category since December 2002
Additional information Awards:
Second classified at “Premio tesi CLUSIT 2007″ award, for the best information security thesis
Tecnical reports:
LISABETH: Automated Content-Based Signatures Generator for Zero-day Polymorphic Worms,
University of Milan, Milan, 03/2007
Papers:
LISABETH: Automated Content-Based Signatures Generator for Zero-day Polymorphic Worms,
SESS08, Leipzig, 05/2008