Security Expert

Security Operations Engineer

Security Operations Engineer with 2.5+ years owning the full incident lifecycle — triage, troubleshooting, cross-team coordination and root cause analysis — Built a SOC from the ground up, cut critical-incident MTTD from days to ~2 hours through automation, and ran zero-downtime upgrades of production infrastructure. Calm and decisive under pressure, with strong technical and executive communication. Currently at Thales, embedded on a space programme.



Experience: 2 years

Yearly salary: $60,000

Hourly rate: $30

Nationality: 🇮🇹 Italy

Residency: 🇮🇹 Italy


Experience

Security Operations Center Analyst & Engineer
IT Centric
2024 - 2026
air-gapped environment. Designed and productionised a complete SOC for 2,000+ endpoints: structured incident response process, escalation matrices, on-call workflows and KPI/SLAs; introduced Agile/Scrum to SOC operations. Acted as technical first responder on critical incidents, owning end-to-end triage, troubleshooting, coordination across infrastructure and application teams, root cause analysis, and technical & executive reporting. Reduced MTTD for critical incidents from days to ~2 hours by automating triage and response with Palo Alto XSOAR playbooks and structured ticketing. Executed a zero-downtime, multi-hop upgrade of a production Splunk cluster (8.2.6 → 10.0.2); diagnosed and resolved a broken XSOAR integration caused by a deprecated library, restoring automation within hours. Built Python automation for proactive health checks across an 11-server estate; designed HA/DR architecture and offline patch management for an air-gapped SIEM infrastructure. Created a staging environment to validate rules, playbooks and changes before production deployment; engineered role-based telemetry (Sysmon, Windows Event Logging) across Domain Controllers, Exchange, IIS and SQL. Hardened and operated Trellix ePO endpoint protection (2,000+ endpoints), including VDI performance remediation and formal operating procedures and runbooks.
Network Security Engineer
IT Centric
2023 - 2024
Perimeter security operations (firewalls, IDS/IPS, VPN), email/web security on Cisco ESA/WSA, and traffic analysis in support of Blue Team activities.

Skills

agile
analyst
consulting
security
english
italian