Cloud & application security

Hi, I'm Omar — I keep the internet's edges a little safer.

Cloud security consultant working with WAF, Zero Trust, and cloud platforms — with a calm, thoughtful approach to protecting the things that matter.

About

Precision by nature.

I'm a Cybersecurity Engineer delivering cloud network and application security solutions for enterprise customers — WAF, CDN, Anti-DDoS, Zero Trust and SASE, built on platforms like F5, Cloudflare, and Akamai, and wired into AWS and Azure environments via Terraform and CI/CD.

The technical design is half the job. The other half is the client and vendor relationship around it: running pre-sales demos and PoCs, writing RFP responses, and being the person a client calls when something in production needs an answer, not a ticket number.

I graduated 110/110 cum laude from Università degli Studi di Milano, with a thesis on Threat Hunting using MITRE Caldera and STIX-Shifter — including an open-source contribution to the project. I hold 20+ certifications across cloud, network, and application security.

Experience

Cloud Network & Security Consultant

Jul 2024 — Present

Communication Valley Reply

  • Primary technical point of contact for a portfolio of enterprise clients
  • Direct vendor collaboration with F5, Cloudflare, and Akamai on escalations and joint solution design
  • Pre-sales: technical demos, PoC design, RFP/RFI responses
  • Onboard and mentor junior consultants; review their work before client delivery

Thesis Intern — Threat Hunting Research

Feb 2024 — Jun 2024

CyberArmor CH

  • Built a Threat Hunting framework using MITRE Caldera for adversary emulation
  • Contributed merged fixes to the open-source STIX-Shifter library
Case studies

Selected work.

Client names are withheld under confidentiality agreements — architecture, approach, and outcomes are described accurately.

Banking, Italy

OpenShift Bare-Metal Migration with F5 Container Ingress Services

Designed and validated a dynamic BIG-IP/CIS integration for a bank's migration from virtualized OpenShift clusters to bare-metal OCP, then supported the live cutover.

F5 BIG-IPF5 CISOpenShift (OCP)Kubernetes
Luxury / fashion, EU

B2B/B2C Migration to F5 Distributed Cloud, Managed as Code

Migrated all B2B and B2C applications onto F5 Distributed Cloud and introduced WAF, rate limiting, anti-bot, L7 anti-DDoS, and automated web app scanning — entirely managed through Terraform.

F5 Distributed CloudTerraformWAFRate LimitingIaC
Transport / road infrastructure, Italy

L3/L4 Anti-DDoS via BGP Routing and Cloudflare Magic Transit

Protected network-layer infrastructure against L3/L4 DDoS using BGP-routed traffic through Cloudflare Magic Transit over GRE tunnels, then migrated B2B/B2C applications onto Cloudflare with caching, WAF, and anti-bot.

Cloudflare Magic TransitBGPGRE TunnelsWAF
Energy / oil, EU

Akamai Zero Trust Platform Modernization

Upgraded a legacy Akamai Zero Trust deployment to a modern architecture for lower latency and simpler operations, covering both infrastructure components and end-user clients.

Akamai Zero TrustEnterprise Application Access
Food & beverage, EU

F5 Distributed Cloud Migration with Behavioral Anti-Bot & API Security

Migrated B2B and B2C applications to F5 Distributed Cloud and activated advanced security capabilities, behavioral anti-bot and API security, managed entirely through Terraform.

F5 Distributed CloudTerraformAPI SecurityBehavioral Anti-BotIaC
Luxury / fashion, EU

Hub-and-Spoke Network Design on Azure with FortiGate & NGINX

Designed a hub-and-spoke network architecture on Azure for a fashion group, with FortiGate as the centralized next-gen firewall and NGINX handling WAF duties at the application layer.

Microsoft AzureFortiGate NGFWNGINXHub-and-Spoke
Research / open source

Threat Hunting Framework with MITRE Caldera & STIX-Shifter

Built a practical threat hunting framework using adversary emulation, and contributed fixes upstream to an open-source threat intel translation library.

MITRE CalderaPythonSTIX-ShifterMITRE ATT&CK
Multi-sector — MSSP engagement

Managed Security Services (MSSP): Change & Incident Management

Ongoing managed security services across multiple clients: Akamai CDN/WAF/DNS/Zero Trust, F5 Distributed Cloud, BIG-IP, and firewall platforms (Cisco, Palo Alto) — handling both change requests and incident response.

AkamaiF5 Distributed CloudF5 BIG-IPCiscoPalo Alto NetworksServiceNowJira
Skills

Security

WAFZero TrustSASEAnti-DDoSThreat HuntingMITRE ATT&CKAI Security

Platforms

F5 Distributed CloudCloudflareAkamaiPalo Alto NGFWCiscoAWSAzure

Engineering

TerraformCI/CDPythonLinuxGitDocker
Contact

Open to security engineering roles — internationally, or with vendors in Italy.