Senior Security Architect · eu-LISA

Security architecture for systems that cannot stop.

I turn regulatory requirements, cloud, networks and industrial environments into concrete controls that engineering and operations teams can actually adopt.

  • Large-scale EU systems
  • Critical infrastructure
  • Security operations
Network Segmentation Cloud Controls Industrial Resilience SOC Response
Security Architecture Patterns · Guardrails

One architecture. Four operational domains.

Experience across
  • eu-LISA
  • Leonardo
  • Vodafone Group
  • ACEA

Operating model

Security that connects architecture to operations.

A consistent approach across infrastructure, workloads and response—designed around real constraints rather than shelf-ware.

NET

Network & perimeter

Segmentation, secure connectivity and hardened perimeters that support the business instead of becoming its weak link.

Outcome: controlled, observable connectivity.

CLD

Cloud & modern stack

IAM, network controls, workload protection and visibility aligned with how cloud services are actually operated.

Outcome: guardrails teams can use.

OT

Industrial & critical

OT/IT boundaries, monitoring and disciplined change for systems where resilience and continuity come first.

Outcome: resilience without operational blind spots.

SOC

Security operations

Monitoring, triage and escalation processes that help analysts act instead of adding more noise.

Outcome: response that scales.

Selected work

Architectural decisions in regulated environments.

Examples drawn from public professional experience. Details remain intentionally concise where environments are sensitive.

EU / Large-scale ITSecure connectivity Cross-border EU systemsArchitectures balancing availability, performance and regulation across large European environments.
Context
Large-scale systems operating across multiple European countries.
Constraints
Continuity, performance, regulatory requirements and alignment across stakeholders.
Decision
Consistent secure-connectivity patterns and guardrails that translate requirements into implementable controls.
Role
Security architecture and cross-functional alignment.
Outcome
A clearer implementation path for engineering and operations teams.
ACEA / UtilitiesPerimeter & SOC Hardening for a major utilityStronger perimeter and monitoring, with detection and escalation processes designed around how the organisation works.
Context
Network-security operations for a major Italian utility.
Constraints
Operational continuity, signal volume and disciplined escalation.
Decision
Strengthen perimeter monitoring, triage and escalation around the organisation's real operating model.
Role
Network security consulting and technical leadership of the SOC team.
Outcome
More consistent detection and response processes.
Vodafone GroupNetwork services Visible, reliable security servicesConnectivity and security services designed for operational reliability, visibility and compliance.
Context
Connectivity and security services supporting a global telecommunications environment.
Constraints
Reliability, operational scale and end-to-end visibility.
Decision
Design network and security services around observable, operable patterns.
Role
Senior network and security engineering.
Outcome
More robust and observable service platforms.

Career

From systems engineering to security architecture.

A path through operations, network security, defence and large-scale European systems.

  1. Senior Security Architect

    eu-LISA · Strasbourg

    Security architecture for large-scale EU systems and cross-functional alignment so controls are understood and adopted.

  2. Security Architect

    Leonardo · Rome

    Secure-by-design architectures and guardrails for mission-critical defence and aerospace platforms.

  3. Senior Network & Security Engineer

    Vodafone Group Services via RICOH · Düsseldorf

    Reliable, observable connectivity and security services supporting operations and response.

  4. IT Security Consultant

    GS-Net Italia / ACEA · Rome

    Network security consulting and technical leadership for the Security Operation Center of a major Italian utility.

  5. Systems Engineer

    Gf Com · Rome

Credentials

Certifications and technical grounding.

Active · through Jun 2028

GIAC GICSP

Global Industrial Cyber Security Professional

GIAC · 2024

Previous credentials

Expired · Oct 2025

Professional Cloud Security Engineer

Google Cloud

Google · 2023

Expired · Dec 2018

CCP–N

Citrix Certified Professional — Networking

Citrix · 2015

Beyond the role

Open infrastructure and technical community.

Community involvement with Ninux.org since 2011, alongside published slides and a Netkit lab on the OLSR routing protocol.

Explore the local AI lab