About Me

TL;DR

tldr I’m a Product Security Engineer with experience securing applications at scale. I currently work at PagoPa, where I lead Application Security for IO, Italy’s digital public services app with over 40 million users. My expertise spans Application Security, Cloud Security, and DevSecOps. I have strong experience designing and implementing secure architectures on AWS and Azure, as well as conducting threat modeling, security design reviews, and code reviews. I focus on software supply chain security, vulnerability management, and security assessments, with the goal of strengthening security posture across complex systems. I’m particularly interested in building scalable, secure-by-design architectures and embedding security throughout the development lifecycle.

Experience

Certifications

  • Burp Suite Certified Practitioner (BSCP) — PortSwigger
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500) — Microsoft
  • HashiCorp Certified: Terraform Associate — HashiCorp

Education

GitHub ← Home LinkedIn