Gianluca Caruso

I work in cybersecurity with a hands-on approach: security applied to code, infrastructure, DevSecOps automation and real processes, even when doing it right is the hard part.

Want the jargon-free version? What I do

Work experience

  1. ICT Security Specialist | DevSecOps Engineer | Full Stack Developer | AI Engineer @ Altrama Italia

    Jun 2023 - present

    ICT security, application hardening, full-stack development, DevSecOps automation and support for the company's ISO 27001 certification path.

Education

  1. CyberSecurity - continuous learning @ HackTheBox Academy, PortSwigger Academy and specialist platforms

    ongoing

    Hands-on training in offensive security (penetration testing, web application testing, vulnerability assessment, OSINT, bug bounty), blue team practices (hardening, WAF, IDS/IPS, EDR, XDR, SOAR) and governance (NIS2).

  2. BSc in Computer Science @ University of Calabria

    2018 - 2023

    University studies in computer science, software development and security fundamentals.

  3. Diploma in Business Information Systems @ ITAS ITC Rossano

    2013 - 2018

    Technical education in information systems, databases and business processes.

Skills

Full-stack development

Frontend, backend, APIs and databases for complete web applications.

  • TS/JS
  • React
  • Next.js
  • Node.js
  • Spring Boot
  • Django
  • FastAPI
  • Go
  • PostgreSQL
  • MongoDB
  • Redis
  • MySQL
  • SQLite
  • REST
  • GraphQL
  • WebSocket
  • tRPC
  • Test e2e
  • HTML
  • CSS
  • TailwindCSS
  • Bootstrap

DevSecOps

Pipelines, containers, infrastructure and automated checks close to the code.

  • Docker
  • Kubernetes
  • Terraform
  • Ansible
  • GitHub Actions
  • Vault
  • Helm
  • Nginx
  • Caddy
  • Prometheus
  • Grafana
  • ELK

AI engineering

Agents, RAG and automations that turn technical context into useful workflows.

  • Python
  • LLM
  • RAG
  • AI Agents
  • LangChain
  • Prompt Engineering
  • Red Teaming AI
  • Automation

Security

Offensive security, defense, hardening and analysis of exposed surfaces.

  • Penetration Testing
  • WPT
  • Vulnerability Assessment
  • Web Security
  • Bug Bounty
  • OSINT
  • Threat Intelligence
  • Hardening
  • WAF
  • IDS/IPS
  • EDR
  • XDR
  • SIEM
  • SOAR
  • Zero Trust
  • SAST
  • DAST
  • SCA
  • NIS2
  • ISO 27001

Certifications & achievements

Click to see all badges

HTB Certified Web Exploitation Specialist

Path completato

Hacking in the wild

Hacking WordPress

The eye that sees all

Network Enumeration with Nmap

Do things the traditional way

Introduction to Bash Scripting

Every road leads back to root

File Inclusion

Airborne delivery

File Transfers

DROP your weapon

SQL Injection Fundamentals

Your request is my demand

Web Requests

Combine the modules

Using the Metasploit Framework

Playing with the mess

JavaScript Deobfuscation

Stairway to Heaven

Linux Privilege Escalation

Fuzzing is power

Attacking Web Applications with Ffuf

Crude but effective

Login Brute Forcing

JOIN the adventure

SQLMap Essentials

Developer

Introduction to Web Applications

Your first battle

Getting Started

Just a small crack, and you're in

Broken Authentication

Start building your arsenal

Setting Up

Tactical

Penetration Testing Process

Included in every report

Cross-Site Scripting (XSS)

Light in the dark

Vulnerability Assessment

Inject with caution

Command Injections

Dive into requests

Using Web Proxies

You need to trace before you can hunt

Footprinting

Ghost in the shell

Shells & Payloads

Scan and execute

Attacking Common Services

Arachnoid

Web Attacks

Prepare your payload and up you go

File Upload Attacks

Information is not knowledge, or is it?

Information Gathering - Web Edition

Straight to the server

Server-side Attacks

Passwords are not the only way forward

Session Security

You shall not (by)pass

Web Service & API Attacks

Hunt the bug

Bug Bounty Hunting Process

Flaw finder

Intro to Whitebox Pentesting

Endpoint Explorer

API Attacks

Fuzzing guru

Web Fuzzing

Graph invader

Attacking GraphQL

Protocol Breaker

Attacking AI - Application and System

PenguinTracer

Introduction to Linux Forensics

Say hi!

Type at least two characters: the board answers live.