✦ Cloud & Application Security Consultant · Milan, Italy
Security that ships with the product, not after it.
I'm Omar. I design and operate WAF, Zero Trust, and cloud security for 5+ enterprise clients across F5, Cloudflare, Akamai, AWS, and Azure. The client-facing and pre-sales side of the job has sharpened how I translate security issues for people who don't speak security, and how I stay precise when several engagements run in parallel.
When a project involves a technology I haven't used before, I pick it up quickly and bring that same autonomy to ambiguous problems. I graduated 110/110 cum laude in Computer and Information Systems Security from Università degli Studi di Milano, with a thesis on Threat Hunting using MITRE Caldera, including a merged open-source contribution to STIX-Shifter. I hold 20+ certifications across cloud, network, and application security, including CCSK v5, AWS Certified Cloud Practitioner, and the Certified AI Security Specialist (CAISS).
Experience
Cloud Network & Security Consultant
Jul 2024 — PresentCommunication Valley Reply · Milan, Italy (Hybrid)
- Primary technical contact for 5+ enterprise clients, from requirements gathering through post-go-live support
- Designed, implemented and managed Multi-Cloud, WAF, Firewall, CDN, Anti-DDoS, DNS and Zero Trust architectures across F5, Cloudflare, Akamai, and Cisco integrated with AWS and Azure
- Applied AI Security frameworks to harden AI/ML workloads
- Automated infrastructure provisioning via Terraform/API and integrated security controls into CI/CD pipelines
- Ran pre-sales technical demos, and PoC design; managed vendor escalations and communications with F5, Cloudflare, and Akamai
- Mentored and onboarded junior consultants, reviewing their work before client delivery
Thesis Intern | Threat Hunting Research
Feb 2024 — Jun 2024CyberArmor CH · Switzerland, Remote
- Built a Threat Hunting framework using MITRE Caldera for adversary emulation, mapped to MITRE ATT&CK
- Automated manual hunting playbooks into repeatable Python scripts, cutting investigation effort
- Fixed bugs in the open-source STIX-Shifter library (Sumologic, Elastic, ReaQta modules); PR merged upstream
Selected work · (09) sector, problem, what changed
Client names are withheld under confidentiality agreements. Everything else is accurate.
BANKING, ITALY
OpenShift Bare-Metal Migration with F5 Container Ingress Services
Designed and validated a dynamic BIG-IP/CIS integration for a bank's migration from virtualized OpenShift clusters to bare-metal OCP, then supported the live cutover.
Read the case study →LUXURY / FASHION, EU
B2B/B2C Migration to F5 Distributed Cloud, Managed as Code
Migrated all B2B and B2C applications onto F5 Distributed Cloud, introduced WAF and anti-bot protection, and deployed dual Customer Edge clusters for private service exposure with fault tolerance.
Read the case study →TRANSPORT / ROAD INFRASTRUCTURE, ITALY
L3/L4 Anti-DDoS via BGP Routing and Cloudflare Magic Transit
Protected network-layer infrastructure against L3/L4 DDoS using BGP-routed traffic through Cloudflare Magic Transit over GRE tunnels, then migrated B2B/B2C applications onto Cloudflare with caching, WAF, and anti-bot.
Read the case study →ENERGY / OIL, EU
Akamai Zero Trust Platform Modernization
Upgraded a legacy Akamai Zero Trust deployment to a modern architecture for lower latency and simpler operations, covering both infrastructure components and end-user clients.
Read the case study →FOOD & BEVERAGE, EU
F5 Distributed Cloud Migration with Behavioral Anti-Bot & API Security
Migrated B2B and B2C applications to F5 Distributed Cloud and activated advanced security capabilities, behavioral anti-bot and API security, managed entirely through Terraform.
Read the case study →LUXURY / FASHION, EU
Hub-and-Spoke Network Design on Azure with FortiGate & NGINX
Designed a hub-and-spoke network architecture on Azure for a fashion group, with FortiGate as the centralized next-gen firewall and NGINX handling WAF duties at the application layer.
Read the case study →GAMBLING / BETTING, EU
Multi-Cloud Connectivity: Oracle OCI to AWS via VPN
Set up VPN connectivity between Oracle Cloud Infrastructure and AWS, and managed routing within a new AWS hub-and-spoke architecture, as part of the client's multi-cloud network design.
Read the case study →RESEARCH / OPEN SOURCE
Threat Hunting Framework with MITRE Caldera & STIX-Shifter
Built a practical threat hunting framework using adversary emulation, and contributed fixes upstream to an open-source threat intel translation library.
Read the case study →MULTI-SECTOR, MSSP ENGAGEMENT
Managed Security Services (MSSP): Change & Incident Management
Ongoing managed security services across multiple clients: Akamai CDN/WAF/DNS/Zero Trust, F5 Distributed Cloud, BIG-IP, and firewall platforms, handling both change requests and incident response.
Read the case study →Skills
Cloud & Security: AWS, Azure, Zero Trust, WAF, Firewall, CDN, AI Security
Automation & Scripting: Python, Bash, Terraform, Git, CI/CD, DevSecOps
Platforms: F5, Cloudflare, Akamai, Palo Alto Networks, Cisco
Let's talk.
Open to security engineering roles, internationally or with vendors in Italy. The fastest way to reach me is email.