Summary
Overview
Work History
Education
Skills
Professional Role
Personal Information
Languages
Extra Notes
Timeline
06
Luca Morini

Luca Morini

Penetration Tester
Barcelona

Summary

With 12 years of experience in IT and 8 years specializing in cybersecurity, I have worked across various enterprise environments, developing strong expertise in both hardware and software. Passionate about computer science and ethical hacking, I am dedicated to continuous improvement and excellence, consistently striving to enhance my technical skills and deliver high-level cybersecurity solutions.

Overview

12
12
years of professional experience

Work History

Pentester - Sr. Offensive Security Consultant

Ingram Micro
02.2022 - Current
  • Web Application Penetration Testing
  • Mobile Application Penetration Testing
  • Infrastructural Penetration Testing
  • External Penetration Testing
  • Wi-Fi Penetration Testing
  • Cloud Penetration Testing
  • Open Source Information Gathering
  • Phishing Campaigns
  • Vulnerability Assessments
  • Web Application Scanning
  • System Administrator
  • Automation developer
  • Pentesters Trainer


Products knowledge:

  • Fortinet
  • PhisingBox

Pentester - Sr. Offensive Security Consultant

IThink UPC
01.2022 - 02.2023

Extern at:

Boehringer Ingelheim as SOC Operator LV2:

  • Ticket solving
  • Vulnerability Managements
  • Vulnerability Assessments
  • Automation development
  • Forensics analysis

Internal:

Penetration Tester

  • WiFi Assessments
  • Web Application Penetration Test
  • Vulnerability Analysis

Products Knowledge:

  • PaloAlto Firewall
  • QRadar
  • Microsoft ATP
  • F5 Load Balancer
  • ServiceNow
  • Qualys

Pentester - Sr. Offensive Security Consultant

Accenture Security
03.2020 - 06.2020
  • Vulnerability Assessment
  • Infrastructural Penetration Testing
  • Web Application Penetration Testing
  • Mobile Applications Penetration Testing (iOS / Android)
  • Static Code Analysis


Product Knowledge:

  • Fortify

Pentester – Sr. Offensive Security Consultant

Adora ICT
09.2019 - 03.2020
  • Vulnerability Assessment
  • Penetration testing
  • VAPT Trainer
  • Open Source Information Gathering


Products Knowledge:

  • Nessus
  • Spiderfoot
  • Maltego

Security Consultant

ESC2 srl
10.2018 - 09.2019

Intern as Pentester:


Vulnerability Assessment

Penetration testing

  • Infrastructural
  • Web Applications
  • Mobile (Android / iOS)
  • ATM and POS
  • WiFi Assessment
  • Phishing / USB baiting Campaigns
  • Social Engineering


Extern at:

Terna spa as Security Consultant:

  • Vulnerability Assessment
  • Penetration Tests
  • System engineer


Italian Minister of foreign affairs as SOC Operator LV2:

  • Firewall Manage
  • Antispam Manage
  • Load Balancer Manage
  • Forensics Analysis



Product knowledge:

  • Nessus
  • OpenVAS
  • Nexpose
  • kali
  • metasploit
  • Alfa Network cards
  • OWASP ZAP
  • BurpSuite
  • PaloAlto
  • CheckPoint
  • Fortinet
  • IronPort
  • F5 Load Balancer
  • Archsite
  • Celebrite
  • GoPhish


Security Consultant

Gsnet Srl
03.2018 - 10.2018

Extern at:


ACEA as Security operation center (SOC) LV1 - Blue Team:

  • Networking
  • Firewalling
  • Implementation of security policies
  • Automation development
  • Tickets solving
  • Creation of VPN IPsec tunnels
  • Network traffic analysis (log firewall / SIEM / log proxy)
  • Event correlation and analysis
  • Active Directory Manage
  • AntiSpam Manage
  • Proxy Manage
  • SSL VPN Manage


Sogei as pentester - Red team:

  • Penetration testing
  • WAF manage


Consip as Code Analyst:

  • Static code analysis


Products knowledge:

  • Remedy
  • SIEM RSA
  • Juniper Firewall
  • PaloAlto Firewall
  • CISCO ASA Firewall
  • Forcepoint Proxy
  • Symantec AntiSpam
  • Tufin
  • Pulse Secure SSL VPN
  • Cisco AnyConnect SSL VPN
  • Positive Technologies code analyzer
  • Positive Technologies WAF

Developer / Pentester

M&M Computers srl
05.2017 - 04.2018

Developing of web sites and web applications using:

  • HTML5, PHP, CSS3, JavaScript, jQuery, MySQL, Python, Java


Advanced competencies of:

  • GNU/Linux, UNIX, Windows, Mac OSX
  • Bash, batch, Python


  • Some penetration tests following the OSCP methodology

Helpdesk Lv 1

Var Group
11.2016 - 05.2017

Extern at:

Lamborghini spa as HelpDesk operator lv 1

  • Asset management
  • Ticket solving
  • Active Directory Manage
  • Security Policies Management
  • IMAC Rollout


CRIF spa as Document Writer

  • Drafting of technical documentation


Product knowledge:

  • Remedy
  • Active Directory
  • E-Policy Orchestrator (McAfee)
  • Office Suite

Junior System Integrator / Computer Technician

M&M Computers srl
01.2013 - 11.2016

System Integrator:

  • Manage of virtual machines over Amazon EC2
  • Installation and maintenance of LAMP (Linux Apache MySQL PHP) servers
  • Creation of websites using wordpress/Joomla CMS or HTML5, CSS3, PHP and JavaScript
  • Onsite assistance at the customer or at the datacenters
  • Creation of bash / python scripts in order to automate the productive process
  • Manage of Synology Backup Systems


Computer Technician:

  • Hardware and software repairs over PC, smartphone and Tablets
  • Specialized on iPhone hardware repairs
  • Virus cleaning from infected systems
  • HardDisk migration from SATA to SSD
  • Formatting of Windows or installing Linux
  • Analog to digital conversion

Education

OSCE -

Offensive Security
05.2019

OSCP -

Offensive Security
09.2017

SEC556 - IoT Penetration Testing -

SANS
09-2022

FCSS FortiSASE AD 23 -

Fortinet
09-2024

VoIP And SIP Pentesting -

VoIP School
06-2022

Fortinet Certified Associate in Cybersecurity -

Fortinet
09-2024

Firewall 9.0:Optimizing Firewall Threat Prevention -

PaloAlto
01-2021

Firewall 9.1 Essentials: Configuration And Manage -

PaloAlto
01-2021

Panorama 9.0: Manage Firewalls At Scale -

PaloAlto
01-2021

Vulnerability Management Self-Paced Training -

Qualys
01-2021

Web Application Scanning Self-Placed Training -

Qualys
01-2021

Sophos Synchronized Security Expert -

Sophos
02-2020

High School Diploma - Perito Informatico

ITIS Odone Belluzzi
05.2016

Skills

  • Penetration Testing
  • Social Engineering
  • Security Operation Center
  • Programming
  • System Administration
  • Security frameworks (OWASP, CVSS)
  • Open source intelligence
  • Mobile security
  • Code Analysis
  • IoT security
  • Exploit development
  • Reverse engineering
  • Forensic analysis

Professional Role

Senior Penetration Tester

Personal Information

  • Year of Birth: 1997
  • Gender: Male
  • Nationality: Italian

Languages

English
Advanced (C1)
Italian
Bilingual or Proficient (C2)
Spanish
Bilingual or Proficient (C2)

Extra Notes

I have a strong focus on data privacy and security, maintaining full control over my digital environment to ensure my information is stored, managed, and protected according to my own standards. To achieve this, I have built and maintained a self-hosted infrastructure, which includes:


  • FreeBSD as the base OS of my server
  • AdGuard as a DNS filtering solution
  • WireGuard for secure VPN access
  • iRedMail as a private mail server
  • Matrix/Synapse for secure messaging
  • Coturn as a VoIP relay server
  • Nextcloud as a self-hosted cloud platform
  • Substreamer for music streaming
  • Plex as a media server
  • Nginx (compiled with Naxsi WAF ) as a hardened reverse proxy
  • Fail2Ban for brute-force and DoS protection
  • Remotely for remote machine management
  • Spiderfoot my OSINT favorite tool
  • LocalAI platform for Local Language Models
  • Virtualbox Headless as Hypervisor
  • Graphene OS as mobile phone OS


While not the most extensive or complex tech stack, each component reflects my commitment to privacy, security, and self-reliance in an increasingly data-driven world.

Timeline

Pentester - Sr. Offensive Security Consultant

Ingram Micro
02.2022 - Current

Pentester - Sr. Offensive Security Consultant

IThink UPC
01.2022 - 02.2023

Pentester - Sr. Offensive Security Consultant

Accenture Security
03.2020 - 06.2020

Pentester – Sr. Offensive Security Consultant

Adora ICT
09.2019 - 03.2020

Security Consultant

ESC2 srl
10.2018 - 09.2019

Security Consultant

Gsnet Srl
03.2018 - 10.2018

Developer / Pentester

M&M Computers srl
05.2017 - 04.2018

Helpdesk Lv 1

Var Group
11.2016 - 05.2017

Junior System Integrator / Computer Technician

M&M Computers srl
01.2013 - 11.2016

OSCE -

Offensive Security

OSCP -

Offensive Security

SEC556 - IoT Penetration Testing -

SANS

FCSS FortiSASE AD 23 -

Fortinet

VoIP And SIP Pentesting -

VoIP School

Fortinet Certified Associate in Cybersecurity -

Fortinet

Firewall 9.0:Optimizing Firewall Threat Prevention -

PaloAlto

Firewall 9.1 Essentials: Configuration And Manage -

PaloAlto

Panorama 9.0: Manage Firewalls At Scale -

PaloAlto

Vulnerability Management Self-Paced Training -

Qualys

Web Application Scanning Self-Placed Training -

Qualys

Sophos Synchronized Security Expert -

Sophos

High School Diploma - Perito Informatico

ITIS Odone Belluzzi
Luca MoriniPenetration Tester