Andrea Polizzi
Cybersecurity and Consultancy Manager at Npo Sistemi- Claim this Profile
Click to upgrade to our gold package
for the full feature experience.
Topline Score
Bio
Credentials
-
Third Party Risk Management
SecurityScorecardJul, 2022- Nov, 2024 -
Auditor / Lead Auditor ISO 22301 - Business Continuity Management Systems
AICQ SICEVApr, 2022- Nov, 2024 -
Auditor / Lead Auditor ISO 27001 - Information Security Management
AICQ SICEVFeb, 2022- Nov, 2024 -
CISSP - Certified Information Systems Security Professional
(ISC)²Nov, 2021- Nov, 2024 -
NCPSP - Netwrix Certified Partner Sales Professional
Netwrix CorporationJul, 2021- Nov, 2024 -
SC01 - Sales Fundamentals - Sales Consultant
SophosJul, 2021- Nov, 2024 -
Sales Foundation for IBM SaaS
IBMJul, 2021- Nov, 2024 -
IBM Certified Deployment Professional - IBM QRadar SIEM V7.3.2
IBMJun, 2021- Nov, 2024 -
CISM - Certified Information Security Manager
ISACAApr, 2021- Nov, 2024 -
MITRE ATT&CK Defender Fundamentals
CybraryApr, 2021- Nov, 2024 -
PCI Compliance
QualysMay, 2020- Nov, 2024 -
Utilizing Big Data
(ISC)²May, 2020- Nov, 2024 -
Vulnerability Management
QualysMay, 2020- Nov, 2024 -
ICS CyberSecurity Risk
U.S. Department of Homeland SecurityApr, 2020- Nov, 2024 -
ICS CyberSecurity landscape for Manager
U.S. Department of Homeland SecurityApr, 2020- Nov, 2024 -
Six Sigma Yellow Belt Professional
6SIGMAstudy - The global certification body for six sigma certificationsApr, 2020- Nov, 2024 -
GDPR - General Data Protection Regulation
Avvera s.r.l.Sep, 2019- Nov, 2024 -
CNSA - Certified Netwrix Sales Associate
Netwrix CorporationJun, 2019- Nov, 2024 -
ISO/IEC 27001 Foundation - Information Security Management
EXIN your ICT competence partnerApr, 2019- Nov, 2024 -
ITIL® v4 Foundation - IT Service Management
AXELOS Global Best PracticeMar, 2019- Nov, 2024 -
Ethical Hacking & Cyber Security
UdemyFeb, 2018- Nov, 2024 -
Essential Security
Certified SecureOct, 2017- Nov, 2024 -
Security Specialist
Certified SecureOct, 2017- Nov, 2024 -
TCP/IP
CybraryMar, 2017- Nov, 2024 -
Symantec Data Loss Prevent SSE+
SymantecDec, 2015- Nov, 2024 -
Symantec Data Center Security: Server & Server Advanced SSE+
SymantecNov, 2015- Nov, 2024 -
BCSP - BeyondTrust Certified Sales Professional
BeyondTrustMay, 2020- Nov, 2024 -
F-Secure Radar Commercial Training
F-Secure CorporationApr, 2020- Nov, 2024 -
F-Secure Radar Technical Training
F-Secure CorporationApr, 2020- Nov, 2024 -
F-Secure Radar Technical Training Advanced
F-Secure CorporationApr, 2020- Nov, 2024 -
Network Security Expert Associate - NSE 1
FortinetApr, 2020- Nov, 2024 -
Network Security Expert Associate - NSE 2
FortinetApr, 2020- Nov, 2024 -
NCSP - NIST CyberSecurity Professional
itSM Solutions LLCApr, 2020- Nov, 2024
Experience
-
Npo Sistemi
-
Italy
-
IT Services and IT Consulting
-
200 - 300 Employee
-
Cybersecurity and Consultancy Manager
-
Oct 2022 - Present
Responsible for the delivery and operations of Cybersecurity and Compliance Services, spanning from Cybersecurity Consultancy to Systems Integration and Managed Services.I support our customers in defining and maintaining a Security Program and implementing activities to increase the level of corporate security.Expert in Security Governance, Business Continuity, Offensive Security, Compliance, Risk Management, Third Party Risk Management, GDPR, and Incident Management.
-
-
Security Governance & Consulting Coordinator
-
Mar 2022 - Present
As Coordinator of the Security Governance and Consulting unit, I support our customers in areas such as:- Security Information Governance & Compliance- Security Risk Management, Controls, Audit Management- Security Program Management- Business Continuity & Disaster Recovery Management- Incident & Vulnerability Management
-
-
Security Governance and Compliance Specialist
-
Feb 2019 - Present
Security contact in the Delivery business line, I help companies to understand their security level according to international standards and frameworks (ISO/IEC 2700x, NIST, etc.) and to define and implement an Information Security Program.The topics that I deal with are more:- Information Security Governance and Compliance- Risk Management and Incident Handling- Business Continuity Management- Offensive Security Management- Data Privacy and GDPR- IT Security and Risk Assessment- Threat Analysis and Business Impact- Security by Design- Application Security and Secure SDLC- Security Awareness and Training- CyberSecurity Advisor Show less
-
-
-
Volkswagen Group Italia S.p.A.
-
Italy
-
Automotive
-
400 - 500 Employee
-
IT Security Governance - External Consultant
-
Apr 2018 - Feb 2019
Reporting directly to Chief Information Security Officer for the following activities: - Information Security - Information Classification - Secure Software Development LifeCycle (SDLC) - Software Analisys Security Testing (SAST) - Business Continuity Management - IT Security Audit - IT Risk Management - Vulnerability Assessment & Penetration Test Management - Business & IT Security Consulting - Security Infrastructure Analysis - Review of internal process Reporting directly to Chief Information Security Officer for the following activities: - Information Security - Information Classification - Secure Software Development LifeCycle (SDLC) - Software Analisys Security Testing (SAST) - Business Continuity Management - IT Security Audit - IT Risk Management - Vulnerability Assessment & Penetration Test Management - Business & IT Security Consulting - Security Infrastructure Analysis - Review of internal process
-
-
-
Horizon Security
-
Italy
-
Information Technology & Services
-
1 - 100 Employee
-
IT Security Consultant
-
Mar 2018 - Feb 2019
- Information Security - Information Classification, Protection & Monitoring - IT Security Governance - IT Risk Management - Security Technology Advisory - Security Solution Selection - Security Infrastructure Analysis & Design - Hardening and Cryptography Services - Information Security - Information Classification, Protection & Monitoring - IT Security Governance - IT Risk Management - Security Technology Advisory - Security Solution Selection - Security Infrastructure Analysis & Design - Hardening and Cryptography Services
-
-
-
Sisal
-
Italy
-
Entertainment Providers
-
700 & Above Employee
-
IT Security and Compliance PMO - External Consultant
-
Mar 2018 - Jul 2018
Reporting directly to Chief Information Security Officer for the following activities: - Remediation Plan Management - Vulnerability Assessment & Penetration Test Management - SAST Management - Information Security Standards (PCI DSS) Reporting directly to Chief Information Security Officer for the following activities: - Remediation Plan Management - Vulnerability Assessment & Penetration Test Management - SAST Management - Information Security Standards (PCI DSS)
-
-
-
d'Arco Italia
-
Italy
-
IT Services and IT Consulting
-
1 - 100 Employee
-
Systems Engineer
-
Feb 2015 - Mar 2018
- Systems and Network Administrator - Mail Security Solution - IT Monitoring Technology - IT Solution Selection Relevant Projects and Roles: - Systems Specialist Consultant at Aviva - Systems Monitoring Engineer Consultant at Eco-bat SpA. - Systems Monitoring Engineer Consultant at Azienda Ospedaliera Ospedale Civile di Legnano. - Systems and Network Administrator - Mail Security Solution - IT Monitoring Technology - IT Solution Selection Relevant Projects and Roles: - Systems Specialist Consultant at Aviva - Systems Monitoring Engineer Consultant at Eco-bat SpA. - Systems Monitoring Engineer Consultant at Azienda Ospedaliera Ospedale Civile di Legnano.
-
-
-
MediaWorld
-
Italy
-
Retail
-
700 & Above Employee
-
Systems Specialist e Monitoring Engineer - External Consultant
-
Feb 2015 - Mar 2018
Reporting directly to Support Service & Delivery Manager for the following activities: as Systems Specialist: - Business Continuity - Development of a Troubleshooting Tool for Client and Server Patching (Powershell) - Patching and Security Scan (Nmap, Nessus, Wsus) - Server Administrator (Windows, Unix-Like) - Database Administrator (MySql, Microsoft Sql Server) - Systems and Network Administrator (Active Directory, VMware, Veeam Backup, etc) as Monitoring Engineer: - Shell Scripting (Sh, cmd, Powershell) - Development of custom Dashboard for controls and Kpi (PHP, Cgi) - Programming Languages (Perl, Python, Java) - TCP/IP (HTTP/HTTPS, TCP, SMB, SNMP, SMTP, FTP, etc) - Management and Maintenance of Monitoring Environment (Custom OpenSource Stack) - Systems Integrator Relevant Projects: - 18000 unique controls for more than 50000 business process monitored (eCommerce, Security, Database, Dataflow, VisualStore, etc) - Implementation and Configuration of SIEM Solution (Splunk) Show less
-
-
-
BNP Paribas Cardif
-
France
-
Insurance
-
700 & Above Employee
-
Jr Project Manager - External Consultant
-
Jan 2016 - Dec 2016
Reporting directly to CTO for the activities about the Moving on Diamond Tower project:- Migration of the entire primary site to another site (Server, Storage, Firewall, Wiring, Wifi)- Operation Activities for Disaster Recovery and Secondary site- Planning and Management of Suppliers'activities
-
-
Systems Engineer - External Consultant
-
Feb 2015 - Jan 2016
Reporting directly to Systems and Support Technical Manager for the following activities:- Systems and Network Administrator (Active Directory, SCCM, DNS, DHCP, etc)- Server Administrator (Windows, Unix-Like)- Lotus Domino Administrator- Virtualization Technology & Virtual Machines Management (VMware)- Network Infrastructure (Cisco devices)- Help Desk 2/3 LevelRelevant Projects: Business Continuity and Disaster Recovery Site
-
-
-
University of Calabria
-
Italy
-
Higher Education
-
700 & Above Employee
-
Stagista
-
Sep 2013 - Jan 2014
Per la durata dello stage, ho avuto il compito di configurare da zero apparati Cisco (2960, 3360) con servizi di QoS, Access List e Redundancy con l'obiettivo di creare una nuova Sotto-Rete per l'Ateneo. Per la durata dello stage, ho avuto il compito di configurare da zero apparati Cisco (2960, 3360) con servizi di QoS, Access List e Redundancy con l'obiettivo di creare una nuova Sotto-Rete per l'Ateneo.
-
-
Education
-
University of Calabria
Laurea